Security Awareness & Training Policy¶
| Field | Value |
|---|---|
| Owner | Puneet Gupta (Co-Founder) |
| Classification | Internal (shareable under NDA) |
| Version | 1.0 |
| Effective date | 2026-06-11 |
| Next review | 2027-06-11 |
1. Purpose¶
Ensure personnel understand their security responsibilities and can recognize and respond to threats.
2. Training program¶
- All personnel complete security awareness training on onboarding and at least annually.
- Training covers: phishing and social engineering, password and authentication hygiene, data handling and classification, device security (BYOD), safe use of integrations/credentials, and incident reporting.
- Personnel handling sensitive/customer data receive role-relevant guidance.
- Contractors complete equivalent training before being granted access.
3. Tracking¶
Training completion is tracked and recorded (sign-off or LMS), and records are retained for review during customer/audit assessments. (Tracking mechanism being established.)
4. Reinforcement¶
Security reminders and updates are shared with personnel as threats and practices evolve.
Revision history¶
| Version | Date | Author | Change | Approved by |
|---|---|---|---|---|
| 1.0 | 2026-06-11 | Puneet Gupta | Initial draft | Puneet Gupta (Co-Founder) |