Goldline I.T Information Security Policy
Effective Date: 01/06/2026
1. Purpose
The purpose of this Information Security Policy is to protect the confidentiality, integrity, and availability of information entrusted to Goldline I.T P/L by clients, suppliers, and business partners.
2. Scope
This policy applies to all employees, contractors, consultants, and third parties who access company systems, client systems, or company data.
3. Access Control
- Access to systems and information is granted on a need-to-know basis.
- User accounts are unique and must not be shared.
- Access rights are reviewed periodically and removed when no longer required.
- Administrative access is restricted to authorised personnel only.
4. Password and Authentication
- Strong passwords must be used for all systems.
- Multi-factor authentication (MFA) is enabled wherever available.
- Passwords must not be shared or stored in unsecured locations.
5. Device Security
- Company-managed devices must be protected by passwords or biometric authentication.
- Antivirus and endpoint protection software must be installed and maintained.
- Operating systems and applications must be regularly updated with security patches.
- Lost or stolen devices must be reported immediately.
6. Data Protection
- Client information must be handled confidentially.
- Sensitive data should be encrypted where appropriate.
- Information must only be accessed, used, or disclosed for authorised business purposes.
- Client data is not shared with third parties except where required to deliver services or comply with legal obligations.
7. Backup and Recovery
- Critical business and client data is backed up regularly.
- Backup systems are monitored and tested periodically.
- Recovery procedures are maintained to support business continuity.
8. Incident Management
- Security incidents, suspected breaches, malware infections, or unauthorised access attempts must be reported promptly.
- Incidents will be investigated and appropriate corrective actions taken.
- Clients will be notified of significant incidents affecting their information where required.
9. Security Awareness
- Personnel are expected to follow security best practices.
- Awareness of phishing, social engineering, and cybersecurity threats is encouraged.
- Security responsibilities form part of normal business operations.
10. Vendor and Cloud Services
- Reasonable care is taken when selecting technology vendors and cloud service providers.
- Service providers are expected to maintain appropriate security controls to protect information.
11. Compliance
Goldline I.T P/L is committed to complying with applicable laws, regulations, contractual obligations, and industry best practices relating to information security and privacy.
12. Policy Review
This policy will be reviewed annually or whenever significant changes occur to business operations, technology systems, or regulatory requirements.