Introduction
The employees, consultants, and partners of My Awesome Technology Tools (M.A.T.T.) are committed to maintaining the
highest standards of security to protect our clients’ data and ensure the integrity of our services. This
security policy outlines the measures we take to safeguard information and the responsibilities of our
employees and clients.
Scope
The details of this policy are expected to be understood and followed by all employees, contractors, consultants and
partners of M.A.T.T.. The policy is applicable to all systems and services related to M.A.T.T.'s business practices
and technical administration of company resources.
Data Protection
-
Data Encryption: When possible, all data is encrypted both in transit and at rest using
industry-standard encryption protocols. All private or sensitive data must be encrypted in transit and
at rest.
-
Access Control: Access to data is restricted based on the principle of least privilege necessary.
Data is only accessible to employees, partners and clients when the party is working in a role that necessitates
access to the data.
-
Data Backup: Regular backups are performed to ensure data integrity and availability. Backup
data is stored securely and tested periodically for restoration.
Network Security
-
Firewall Protection: Firewalls are implemented to protect our network from unauthorized access
and cyber threats.
-
Intrusion Detection and Prevention: Intrusion detection and prevention systems (IDPS) are
deployed to monitor and respond to suspicious activities.
-
Secure Communication: All communications, including emails and data transfers, are secured
using SSL/TLS protocols.
Application Security
-
Secure Development Practices: Our development team follows secure coding practices to minimize
vulnerabilities in our applications.
-
Regular Security Assessments: We conduct regular security assessments, including vulnerability
scans and penetration testing, to identify and address potential security risks.
-
Patch Management: All software and systems are kept up-to-date with the latest security patches
and updates.
Employee Responsibilities
-
Security Training: All employees receive regular security training to stay informed about the
latest security threats and best practices.
-
Incident Reporting: Employees are required to report any security incidents or suspicious
activities immediately to the IT security team.
-
Confidentiality Agreements: Employees must sign confidentiality agreements to protect client
information and company data.
Client Responsibilities
-
Strong Passwords: Clients are encouraged to use strong, unique passwords for their accounts and
change them regularly.
-
Access Management: Clients should manage access to their accounts and systems, ensuring only
authorized personnel have access.
-
Incident Reporting: Clients should report any security incidents or suspicious activities to
M.A.T.T. immediately.