Human Resources Security Policy¶
| Field | Value |
|---|---|
| Owner | Puneet Gupta (Co-Founder) |
| Classification | Internal (shareable under NDA) |
| Version | 1.0 |
| Effective date | 2026-06-11 |
| Next review | 2027-06-11 |
1. Purpose¶
Define security requirements for personnel across the engagement lifecycle — before, during, and after engagement.
2. Roles & responsibilities¶
Security roles and responsibilities for personnel handling scoped systems and data are defined and documented, consistent with the Information Security Policy.
3. Before engagement¶
- Background verification — ID, criminal, and employment checks are performed for personnel with access to scoped systems and data. (Being introduced as a standard pre-engagement step; retroactive checks for current personnel are in progress.)
- Agreements — all personnel sign written agreements including confidentiality / non- disclosure obligations, acceptable-use, and security responsibilities before access is granted.
4. During engagement¶
- Personnel complete security awareness training (see Security Awareness & Training Policy).
- Access is granted on least-privilege and reviewed periodically.
5. Disciplinary process¶
Security violations, breaches, or misuse of information processing facilities are subject to a disciplinary process, which may include suspension or revocation of access and termination, as set out in personnel agreements and this policy.
6. Offboarding¶
On termination of engagement, access is revoked promptly, and any company/customer data on the person's devices is removed (see BYOD & Endpoint Security Policy).
Revision history¶
| Version | Date | Author | Change | Approved by |
|---|---|---|---|---|
| 1.0 | 2026-06-11 | Puneet Gupta | Initial draft | Puneet Gupta (Co-Founder) |