SECURITY POLICY
Scope & Objectives
This policy applies to all employees, contractors, partners and Interns working in Odotobri Rural Bank. Third party service providers providing hosting services or wherein data is held outside Odotobri Rural Bank premises shall also comply with this policy. The objective of the Information Security Policy is to provide the Bank with an approach to managing information risks and directives for the protection of information assets to all units, and those contracted to provide services.
Data Classification: We classify information based on its sensitivity and criticality, ensuring appropriate levels of protection and access controls are implemented. Classification levels may include public, internal, confidential, and restricted data.
Access Control: This security mechanism regulates who can view or use resources in our environment, and its purpose is to protect sensitive information and systems by ensuring only authorized individuals or processes gain access. User accounts are provisioned with appropriate access privileges, and access rights are systematically reviewed and updated to maintain compliance and security.
Physical Security: This practice safeguard people, property, and information systems from physical threats. To achieve this, we have implemented physical security measures designed to guard against unauthorized entry, theft, or harm to information assets. These measures include secure access controls for facilities, equipment, and storage areas, ensuring that critical resources remain protected at all times.
Network Security: Our network infrastructure is secured through firewalls, encryption, intrusion detection systems, and regular monitoring to prevent unauthorized access, data breaches, and network attacks.
Data Protection: We employ encryption, access controls, and backup procedures to safeguard data integrity and prevent data loss or corruption. Personal and sensitive information is handled in accordance with applicable privacy regulations.
Incident Response: There are protocols in place to quickly identify, evaluate, and address security problems, such as system vulnerabilities, illegal access, or data breaches. To coordinate response activities and reduce risks, incident response teams are assigned.
Training and Awareness: Regular information security awareness training and education are being provided to ORB employees, clarifying their responsibilities relating to ORB’s information security policies and procedures and all relevant obligations defined in their job description.
Compliance and Auditing: This addresses the legal and compliance requirements pertaining to relevant statutory legislation, and contractual and regulatory obligations. This is to protect its documents, records, and assets, thereby preventing the misuse of information. Therefore, we are committed to and conducts our business activities lawfully and in a manner that is consistent with our compliance obligations.
Policy Review and Updates: This policy is periodically reviewed and updated to address emerging threats, technological advancements, and changes in business operations. Employees are notified of any policy changes and are expected to adhere to the updated guidelines.
We show our dedication to safeguarding the availability, confidentiality, and integrity of information assets and upholding the confidence of our stakeholders by abiding by this information security policy.