Information Security and IT Policy

Organization: Ghida Alsultan Co  •  Effective: 2025-01-01  •  Version: 1.0

Scope & Purpose

General

Purpose

Set minimum security expectations for people, systems, and data used by Ghida Alsultan Co, across cloud and SaaS systems, to preserve confidentiality, integrity, and availability.

Policy

  • Applies to all employees, contractors, and vendors accessing organizational data or systems (Internal, Confidential, or Restricted).
  • Covers SaaS platforms (e.g., Odoo cloud), networks, and endpoints.
  • Purpose: protect confidentiality, integrity, and availability of organizational information assets.
  • Standards & references: ISO/IEC 27001/27002, NIST CSF, and applicable laws (e.g., GDPR, KSA PDPL, PCI DSS, local labor/finance records).

Note: See the “Top 50” and “Follow‑ups” source questionnaires for the detailed prompts this policy is based on.

Governance & Ownership

General

Purpose

Define ownership, approval, and review responsibilities so policy stays current and enforceable.

Policy

  • Maintain a current list of covered systems, owners, and periods in the Systems table.
  • Keep security and privacy commitments aligned with vendor contracts and local laws.

Roles

  • Policy Owner: Ghida Alsultan IT Department.
  • Approvers: IT, COO, CEO.
  • Reviewers: IT (annual cadence).

Systems (2026 coverage)

Name Hosted Type Period
Odoo SaaS ERP 01/01/2026 – 31/12/2026
Dgtera POS SaaS POS 01/01/2026 – 31/12/2026

Types inferred (ERP/POS). Adjust if you use different categories.

Regulatory applicability

  • Current stance: no specific regulatory obligations identified by the department at this time.
  • Contracts are reviewed at signing; include security/privacy clauses where provided by vendors.

Based on your answers: Department = IT Department of Ghida Alsultan Co; Owner = Ghida Alsultan IT Department; Approvers = IT/COO/CEO.

Change Management

Process

Policy & Procedure

  1. The person who needs a change submits an email request to the IT Manager.
  2. The IT Manager reviews the request, studies its feasibility and cost.
  3. If the change is viable, the IT Manager raises the request to the Chief Operating Officer (COO) for approval.
  4. If the COO approves, the change is implemented by the IT team or outsourced if needed.

Risk Assessment Management

Risk

Purpose

Establish a structured approach to identifying, evaluating, and mitigating risks to information systems and data.

Policy

  • Risk assessments are performed annually and after major system updates or changes.
  • The IT Department leads risk assessments using recognized methodologies (ISO 27001).
  • Assessments include asset identification, threat and vulnerability analysis, risk evaluation, and mitigation planning.
  • Findings are documented in a risk register and reported to management; high risks require mitigation plans and follow-up.
  • Risk assessment results inform updates to policies, controls, and incident response plans.

Risk assessments are scheduled once a year or after major updates, ensuring ongoing risk management and compliance.

Acceptable Use

Workforce

Purpose

Describe acceptable use of company IT resources to reduce misuse, data loss, and operational risk.

Policy

  • Use company systems for business; limited personal use is permitted when it does not interfere with duties, consume excessive resources, or violate policy or law.
  • Do: use approved systems, protect credentials, report incidents promptly (Incident Report form), and follow data handling rules.
  • Don’t: share passwords, install unapproved software, disable or bypass security controls, or misuse company data/systems.
  • Monitoring: company may monitor usage consistent with local laws and contracts.

Adapted from policy_full.html: Acceptable Use statement.

Identity & Access Management

Identity

Purpose

Ensure people get appropriate access for their role and lose it when no longer needed.

Policy

  • Unique identities are used across systems (email ID where supported; employee ID for POS). Accounts are created on join and terminated when HR notifies IT.
  • Onboarding/offboarding: currently manual via IT form; no automation with HR. Deprovisioning occurs upon HR notification.
  • User identities are local to each application and created manually.
  • Access reviews: conducted every 6 months by the relevant owners; last period had new joiners only, no privilege changes.
  • Shared accounts (e.g., Finance): must be documented with owners and usage scope (currently 4 users share 2 accounts, in pairs).

Based on your answers: local/manual accounts; 6‑monthly reviews; shared accounts in Finance.

Passwords & Secrets

Auth

Purpose

Rely on platform password settings that balance usability and security.

Policy

  • Use platform defaults for password complexity; Odoo enforces "3 of 4" character classes — at least three of uppercase A‑Z, lowercase a‑z, digits 0‑9, and symbols (e.g., ! @ # $ %).
  • We rely on platform enforcement; no additional overlay (e.g., custom password filter) is applied today.
  • System‑to‑system secrets are managed per application; no centralized secrets manager at present.

Based on your answers: accept platform defaults; Odoo enforces 3‑of‑4 (upper, lower, number, symbol).

Assets & Endpoint Management

Devices

Purpose

Maintain awareness of devices and handle lost/stolen cases to reduce data exposure risk.

Policy

  • Asset inventory is recorded in the Assets module within the ERP.
  • BYOD allowed for top management for report viewing; device use must follow Acceptable Use.
  • FDE/EDR are not required at this time; most systems are SaaS and devices are used primarily for access.
  • Lost/stolen devices are reported using the Lost/Stolen Device Report form in the Forms section.

Based on your answers: ERP asset module; no EDR/FDE requirement; limited BYOD; lost/stolen reported via form.

Network & Infrastructure

Infra

Purpose

Define baseline controls for network access and connectivity.

Policy

  • Internet access is via Fortinet firewall and switches; no static public IPs; used primarily for cloud/SaaS access and browsing.
  • No VPN or remote admin is required; business systems are cloud/SaaS and accessed over the internet.
  • No inbound database or service ports are exposed to the internet; all business systems are vendor‑hosted SaaS.
  • Firewall settings are the platform defaults and rarely changed.
  • Wireless uses WPA2 security; guest devices share the same NAT (no separate guest VLAN).
  • Firewall is configured to immediately block the source after a single failed connection/authentication attempt.

Based on your answers: Fortinet edge; no VPN; defaults active; WPA2; guests on same NAT; no inbound service ports exposed (cloud/SaaS only); block on first failed attempt.

Data Classification & Protection

Data

Purpose

State the current approach to protecting data at rest and in transit, and how long backups are kept.

Policy

  • Encryption: rely on SaaS provider defaults for data at rest and in transit.
  • Retention & secure deletion: business data retention is managed within the SaaS platforms per vendor capabilities and contract terms.
  • For departing employees, a backup of the assigned device is taken and retained under IT custody.

Based on your answers: provider‑managed encryption; SaaS‑managed data retention; leaver device backups under IT custody.

Backups & Disaster Recovery

Resilience

Purpose

Ensure the ability to recover critical services and data within acceptable timeframes.

Policy

  • SaaS/cloud products (Odoo, Dgtera POS): the provider is responsible for platform backups and availability.
  • Access to any locally held backups (e.g., leaver device images): IT Manager only.
  • Restore/recovery testing occurs during day‑to‑day maintenance as needed; DR Quick Action and Backup Test forms are available.

Based on your answers: SaaS/cloud provider responsibility for backups and availability; RTO 4h/RPO 24h; IT Manager access to local backups; tests ad‑hoc.

DR/BC runbook (summary): Business systems are vendor‑hosted SaaS (Odoo, Dgtera POS); recovery and availability are the vendor’s responsibility. IT coordinates with vendors during outages and restores any locally held data (e.g., device backups) as needed.

Incident Response & Logging

IR

Purpose

Provide a simple path to report and respond to incidents to reduce impact.

Policy

  • Incidents are raised via the ticketing system and handled by the IT team; in emergencies, users may call an IT member to expedite resolution.
  • IR plan: a full IR playbook is desired and not yet documented; until then, use the Incident Report form and team coordination.

Based on your answers: full playbook requested; ticket/phone support.

Ticket Priority & SLA

Service Desk

Purpose

Explain how IT Support tickets are prioritised, so requesters know what priority to expect for a given issue and what response time comes with it.

How Priority Is Determined

  • Covers tickets raised through the IT Support form at ticket.ghidas.com, across all brands (main concept, TNDR, Pizza), branches, factory, warehouse, and office locations.
  • Priority reflects three things: category (which system), status (how broken it is), and scope (how much of the branch’s ability to sell or operate is affected right now).
  • Urgent describes live service — selling, ordering, kitchen operations — stopped for a whole branch. A single device with a backup, a slow app, or a personal inconvenience falls into a lower band.
  • Tickets are easiest to place correctly when the description states the actual impact, for example “2 of 5 tills down” rather than “urgent, please help”.

Priority Matrix

Category System Status Business Scope Priority
POS SystemsCompletely downWhole branch cannot sellUrgent
POS SystemsIntermittent / partialSome tills affected, branch still sellingHigh
POS SystemsSlow performanceAll tills working but slowNormal
Network & InternetCompletely downWhole branch offline (POS, orders, cameras)Urgent
Network & InternetIntermittentBranch online but degradedHigh
WiFi ConnectivityCompletely downStaff/guest WiFi only, POS unaffectedNormal
WiFi ConnectivitySlow performanceWiFi usable, just slowLow
Kitchen DisplaysCompletely downKitchen cannot see any ordersUrgent
Kitchen DisplaysPartial / slowOne screen affected, others workingNormal
Mobile AppsCompletely downCannot receive online ordersHigh
Mobile AppsWorking with errorsSome orders affected, not allNormal
Security CamerasCompletely downFull branch coverage lostHigh
Security CamerasPartial functionalityOne or two cameras downNormal
Phone SystemsCompletely downBranch cannot be reached / call outHigh
Printers & ScannersCompletely downKitchen/receipt printing stopped, no workaroundHigh
Printers & ScannersWorking with errorsSlow or occasional misprintsNormal
Computers & TabletsCompletely downSingle device, backup availableNormal
Email SystemsCompletely downCompany-wide email outageHigh
Email SystemsIntermittentIndividual mailbox issueLow
Inventory SystemsAny statusNot affecting today’s live serviceNormal
Backup SystemsAny statusNo immediate operational impactLow

Issues that are not listed sit at the priority of the closest equivalent row; where that is unclear, IT makes the judgment call.

Response & Resolution SLA

Priority What it describes Response Target Resolution Updates
UrgentLive service stopped for a full branch, right now15 minutes1 hourEvery 30 minutes
HighSignificant impact on sales/service, but branch can partially operate or has a workaround1 hour4 hoursEvery 2 hours
NormalInconvenience or degraded performance; branch operations are not blocked4 business hours1 business dayDaily
LowNo operational impact; cosmetic, preventive, or convenience request1 business day3–5 business daysOn change

Response and resolution times are targets, measured from the point a ticket is confirmed at its priority.

Source: IT Ticket Priority Policy (IT Operations). The matrix and SLA targets are reviewed quarterly, or sooner when a new system category is added to the IT Support form.

Cloud & Vendor Risk

Third‑party

Purpose

Capture minimal expectations for vendor due diligence aligned with current practices.

Policy

  • Vendor due diligence: no formal assessment performed today; rely primarily on contract review at signing for security/privacy clauses.
  • Use the Vendor Security Checklist in Forms for future onboarding.
  • API keys are stored in databases as implemented by applications.

Based on your answers: no formal vendor assessment; contracts reviewed; API keys in DB.

Physical Security & Training

Facilities

Purpose

Define basic physical safeguards and training expectations.

Policy

  • Access controls: fingerprint device and cameras in use; camera footage retained ~30 days; biometric logs sync to BioTime server continuously.
  • Removable media are not restricted at this time.
  • Training is delivered 1:1 by IT using a checklist with employee sign‑off; annual policy review by IT Manager and upper management.

Based on your answers: fingerprint/camera in place; removable media open; training is 1:1 with sign‑off; annual governance review.

Forms

Interactive

Purpose

Provide simple checklists and templates to operationalize the policy and collect evidence for audits.

Policy

  • Use the embedded forms for incidents, access requests, shared accounts, DR checks, backup tests, vendor checklist, and lost/stolen device reporting.
  • Forms may be exported as JSON or printed for signatures.

Use these forms to operationalize the policy. Submit digitally (export) or print for signatures. Required fields are marked.

1) Incident Report Form IR
Severity *
2) Access Request / Deprovision Form IAM
Request type *
Systems requested *
3) Policy Exception Request Governance
Risk level *
4) Privileged Account Review Sign‑off PAM
Action *
5) Onboarding / Offboarding Checklist HR+IT
Tasks
6) Shared Account Request Identity
Controls
7) DR — Quick Action Checklist DR
  1. Confirm scope and impact; open DR ticket.
  2. Notify IT Manager and executives.
  3. Isolate affected systems as needed.
  4. Attempt recovery or restore from latest backup.
  5. Validate service and notify business owner.
8) Backup & Restore Test Script Backups
  1. Create test ticket and identify backup file used.
  2. Restore backup to test environment (do not overwrite production).
  3. Verify data and run smoke tests.
  4. Record restore duration and results.
  5. Document issues and remediation steps.
Test Type *
Result
9) Vendor Security Checklist Vendor
Security features
10) Lost/Stolen Device Report Devices
Immediate actions taken
Systems potentially at risk
11) Asset Handover Form Devices

Items

# Item / Description Asset Tag / Serial Accessories Condition
1
2
3
4
5
Note :
The listed assets remain the exclusive property of the Company. The Employee acknowledges receipt and assumes responsibility for reasonable care and safeguarding. The Employee further acknowledges that the IT Department reserves the right, at its discretion, to recall any asset for preventive or corrective maintenance, inventory verification, or compliance review, and agrees to return such asset promptly upon request.
ملاحظه:
تظل الأصول المدرجة ملكاً حصرياً للشركة. ويقر الموظف باستلامها ويتحمل مسؤولية العناية المناسبة والحفاظ عليها. كما يقر بأن قسم تقنية المعلومات يحتفظ بالحق، وفقاً لتقديره، في استرجاع أي أصل لأغراض الصيانة الوقائية أو التصحيحية أو التحقق من الجرد أو الامتثال، ويلتزم الموظف بإعادته فور طلبه.
12) Device Maintenance Request Devices
Urgency

Turnover and Return

Handover to IT Return to Employee
Date / Time
Person
Accessories / Work
Signatures
13) Change Request & Development Form Change
Priority *

Development & Deployment Checklist

Phase 1: Request & Approval
Phase 2: Design & Development
Phase 3: Testing & Deployment
Final Status *
14) Bug Fix & Maintenance Form Maintenance
Issue Type *
Severity *

Development & Deployment Checklist

Steps
Status *
15) Security Training & Awareness Form Training
Topics Covered *
Employee Acknowledgment *