Purpose
Set minimum security expectations for people, systems, and data used by Ghida Alsultan Co, across SaaS and local systems, to preserve confidentiality, integrity, and availability.
Policy
- Applies to all employees, contractors, and vendors who access organizational data or systems.
- Covers SaaS platforms (e.g., Odoo), on‑premises services (e.g., POS), networks, and endpoints.
- References good practices (ISO 27001, NIST CSF) and applicable legal/contractual terms.
This policy establishes minimum security requirements for all information systems, data, users, contractors, and third parties engaged by [Your Organization Name]. It applies to on‑premises, cloud, and SaaS environments, covering endpoints, network, applications, and data.
- Purpose: protect confidentiality, integrity, and availability of organizational information assets.
- Scope: all employees, contractors, and vendors accessing Internal, Confidential, or Restricted data.
- Standards & references: ISO/IEC 27001/27002, NIST CSF, and applicable laws (e.g., GDPR, KSA PDPL, PCI DSS, local labor/finance records).
Note: See the “Top 50” and “Follow‑ups” source questionnaires for the detailed prompts this policy is based on.