Policies for information security

Information Security Policies

Policy:

Neon Ideas is committed to meet the Information Security requirements of its customers, employees and business partners. It shall do so through effective implementation and continual improvement of its Information Security Management System (ISMS) by identifying, evaluating and controlling risks to ensure the confidentiality, integrity and availability of its Critical and sensitive information assets, and meet legal and statutory requirements.

Objectives:

  • • Confidentiality of information by protecting it from deliberate or unintentional unauthorized access and acquisition.
  • • Integrity of information by protecting it from unauthorized modification
  • • Ensure the availability of information to authorized users whenever required.
  • • Availability of information to authorized users when needed
  • • Classification of information according to its sensitivity
  • • Compliance to regulatory, legislative and contractual requirements
  • • Adopting a formal and sustainable Risk Assessment and Risk Management approach for effective ISMS.
  • • Preparing a Business Continuity and Disaster Recovery Plan
  • • Training of employees to achieve high compliance of information security awareness.
  •  

Responsibility:

  • • The Information Security Officer has direct responsibility for maintaining and implementing the Policies.
  • • All employees are responsible to adhere to this Information Security Policy.
  •  

Review of the Policy:

  • • The Information Security Policy shall be reviewed at least once in a year.

Human Resource Security

Policy:

“Security roles and responsibilities of employees, contractors and third party users shall be aligned with Organization’s information security policy. Adequate level of awareness, education and training in security procedures and correct use of information processing facilities shall be provided to them to minimize possible security risks. The change in responsibilities and their exit from the Organization shall be managed. “In case of any breach company will initiate internal investigation through a formal committee, which will be formulated by HR. The same may have one or more committee members. This is a confidential process, HR Head who is the Chief Officer for Neon Ideas, will take appropriate decisions (decide penalties) based on the merits of the case.”

Objectives:

  • • To ensure that employees, contractors and third party users understand their responsibilities, and are suitable for the roles they are considered for, and to reduce the risk of theft, fraud or misuse of facilities.
  • • Reduce the risks of human error, theft, fraud or misuse of facilities.
  • • Ensure that users are aware of information security threats and concerns, and are equipped to support organizational security policy in the course of their normal work.
  •  

Related processes:

  • • Human Resource Security Policy

Asset Management

Policy:

“All assets shall be accounted for and have a nominated owner. Acceptable use of assets shall be established. Information shall be classified to indicate the need, priorities and expected degree of protection.”

Objectives:

  • ▪ To achieve and maintain appropriate protection of Organizational assets.
  • ▪ Ensure that information assets receive an appropriate level of protection.
  • ▪ Maintain classification of the information based on the sensitivity and criticality to the business.
  • ▪ Nominate owners for all major information assets.
  • ▪ Maintain accountability for all information assets.
  • ▪ Proper and Secure disposal of Asset when no longer required.

 

Responsibility:

  • ▪ Asset Management Policy
  • ▪ Secure Disposable Policy

Access Control

Policy:

“Allocation of access rights to information systems, network and services shall be controlled. User shall be made aware of the responsibilities for maintaining effective access controls.”

Objective:

  • ▪ Control access to information according to business requirements.
  • ▪ Prevent unauthorized access to information systems.
  • ▪ Detect unauthorized activities.
  •  

Related Process:

▪ Access Control Management Policy.

Physical and Environmental Security

Policy:

“Organization’s sensitive information processing facilities shall be housed in secure areas. Physical protection shall be provided against natural and man-made disasters. Access to premises shall be controlled”.

Objective:

  • ▪ Prevent unauthorized physical access, damage and interference to organizational premises
    and information;
  • ▪ Prevent loss or damage to information assets and interruption to business activities; and
  • ▪ Prevent compromise or theft of the information and information assets.
  •  

Related processes:

▪ Physical & Environment Security Policy.

Operations Security

Policy:

“Management and operations of all information processing facilities shall be controlled to reduce the risk of negligent or deliberate misuse. Services delivered by third parties shall be managed according to Organization’s information security requirements.”

Objective:

  • ▪ To ensure the correct and secure operation of information processing facilities.
  • ▪ Have an appropriate backup strategy and monitoring plan for protecting integrity and availability of information processing facilities.
  • ▪ Ensure protection of information in networks and supporting infrastructure.
  • ▪ Have appropriate controls over storage media to prevent its damage and/or theft
  •  

Related Process:

  • ▪ Communication Security Policy.
  • ▪ Access Control Policy.
  • ▪ IT Acceptable Use Policy.
  • ▪ Operation Security Policy.
  • ▪ Physical and Environmental Policy

Communications Security

Policy:

“Management and operations of all information processing facilities shall be controlled to reduce the risk of negligent or deliberate misuse. Services delivered by third parties shall be managed according to Organization’s information security requirements.”

Objective:

  • ▪ To ensure the correct and secure operation of information processing facilities.
  • ▪ Prevent spread of malicious codes so as to protect integrity of software and information. Have an appropriate backup strategy and monitoring plan for protecting integrity and availability of information processing facilities and communication services.
  • ▪ Ensure protection of information in networks and supporting infrastructure.
  • ▪ Have appropriate controls over storage media to prevent its damage and/or theft
  • ▪ Maintain security during information exchange.
  • ▪ Ensure addressing of the information security risks associated with information and communications technology services and product supply chain.
  •  

Related Process:

  • ▪ Communication Security Policy.
  • ▪ Access Control Policy.
  • ▪ IT Acceptable Use Policy.
  • ▪ Operation Security Policy.

Network Security Management Policy

Policy:

“Controls shall be established to safeguard the confidentiality and integrity of data passing over public and internal networks, and the users are provided access to the network services that have been specifically authorized.

Objective:

▪ To ensure the security of data in networks as well as the infrastructure that supports them.

Related Process:

  • ▪ Network Security Policy.
  • ▪ Communication Security Policy.

IT Acceptable Security Policy

Policy:

Controls shall be established to safeguard the confidentiality and integrity of data passing over different channels such as Email, Internet and Internet

Objective:

▪ To safeguard information transmitted through the Internet

Related Process:

▪ IT Acceptable Use Policy
▪ Network Security Policy
▪ Communication Security Policy

System Acquisition, Development and Maintenance

Policy:

“Security requirements shall be identified and agreed prior to the development and / or implementation of information systems”

Objective:

  • ▪ Ensure that security is built into information systems during development.
  • ▪ Restrict access to the source code to authorized personnel only.
  • ▪ Maintain the security of application system software and information.
  • ▪ Ensure that secure system testing is carried out in test environment (UAT)
  •  

Related Process

  • ▪ System Acquisition, Development and Maintenance Policy.
  • ▪ Vulnerability Management Policy

Supplier Relationship

Policy:

“Information security requirements for mitigating the risks associated with supplier’s access to the Organization’s assets shall be agreed with the supplier and documented.”

Objective:

  • ▪ To ensure protection of the organization’s assets that is accessible by suppliers.
  • ▪ To maintain an agreed level of information security and service delivery.
  •  

Related Process

▪ Supplier Relationship Policy.

Information Security Incident Management

Policy:

“Appropriate controls shall be established to ensure a quick, effective, and orderly management of information security incidents”

Objective:

  • ▪ To ensure that Information Security events are assessed properly so that classification of information security incident is done. The learning from incidents should be captured by analyzing and resolving information security incidents to reduce the likelihood or impact of future incidents.
  • ▪ To ensure the proper procedures for the identification, collection of information, which can serve as evidence.
  •  

Related Procedures:

  • ▪ Information Security Incident Management Policy.
  • ▪ Change Management Policy.

Business Continuity Management

Policy:

“A business continuity management process shall be implemented to minimize the impact on the Organization and recover from the loss of information assets to an acceptable level. Business Continuity plan shall be developed and implemented to ensure the timely resumption of critical
functions. The plan shall be periodically tested and kept updated.”

Objective:

  • ▪ Develop a business continuity plan and implement the controls to mitigate the impact of disaster and timely resumption of business activities to minimize losses.
  • ▪ To verify the established and implemented information security continuity.
  • ▪ To ensure availability of information processing facilities in case of any disaster.
  •  

Related Process:

  • ▪ Business Continuity Management Policy
  • ▪ Business Continuity plan policy

Compliance

Policy:

“Compliance with legislative, regulatory and contractual security requirements for the design, operation, use, and management of information systems shall be ensured”

Objective:

  • ▪ Mitigate the risk of breaches of any criminal or civil law, and statutory, regulatory or contractual obligations, and of any security policies.
  • ▪ Ensure compliance of information processing systems with the information security policy and standards.
  • ▪ Minimize interference to business operations from system audit process by appropriate planning.
  •  

Related Process:

  • ▪ Compliance Policy
  • ▪ IS Audit Procedure

Cryptography & Key Management

Policy:

“To outline the procedures for cryptography used in company environment, company shall support the encryption algorithms suitable for its business needs. Use of a particular encryption algorithm to ensure confidentiality and integrity of information”

Objective:

  • ▪ A policy on the use and protection of cryptographic keys shall be implemented throughout their whole lifecycle which includes key generation, ownership, distribution, archival, storage and revocation.
  • ▪ The cryptographic keys shall be protected against unauthorized modification, substitution, unintended destruction and loss.
  •  

Related Process:

▪ Cryptographic Control Policy.

Change Management Policy

Policy:

“Unauthorized changes and unstructured implementation of information assets can lead to system downtime and cause denial of service to users who need access to the system. Major or minor changes to any information asset should be carried out such that proper analysis is done,
approvals are taken prior to implementation and the entire process is documented and maintained post implementation.”

Objective:

  • ▪ All proposed changes made with respect to IT infrastructure and application should initiate through Change Requisition Form.
  • ▪ Impact of proposed change should be calculated to check feasibility of change.
  • ▪ Proposed change should be reviewed and approved By It infra head/ IT Dev head.
  • ▪ Changes should be planned
  • ▪ Stakeholders should be aware of approved changes.
  • ▪ Proper rollback and backup should be taken before any change.
  •  

Related Process:

▪ Change Management Policy

Secure Media Disposable

Policy:

“Information can be compromised through careless disposal or re-use of media. Storage devices containing sensitive information which is no longer required should be physically destroyed or securely overwritten rather than using the standard delete function. All storage media should be checked prior to disposal to ensure that any sensitive data and licensed software is not remained or can be overwritten in any way.”

Objective:

  • ▪ Secure dispose of paper media.
  • ▪ Secure dispose of electronic based media.
  • ▪ Secure dispose of IT Assets.
  • ▪ Sale of assets that are no longer required.
  •  

Related Process:

• Secure Media Disposable Policy

Cyber Security Policy

Policy:

“The cyber security policy at NEON IDEAS provides a set of directives that will enable NEON IDEAS to identify, detect and treat Cyber-attacks in a timely manner such that attacks do not impact the confidentiality, integrity and availability of data at NEON IDEAS. Sufficient technological and process controls will be implemented to ensure customers’ personally identifiable information (PII) and organizational data is protected from potential cyber-attacks. This cyber security policy is in line with the leading cyber security standards, guidelines and RBI mandate on cyber security framework.”

Objective:

  • ▪ To protect information and information infrastructure in cyber space, build capabilities to
    prevent and respond to cyber threats, reduce vulnerabilities and minimize damage from cyber
    incidents.
  • ▪ Identify and prioritize opportunities for improvement within the context of risk management;
  • ▪ Assess progress towards cyber security risks; and
  • ▪ Foster communications among internal and external stakeholders.
  •  

Related Process:

• Cyber Security Policy

Cyber Crisis Management

Policy:

“Cyber Crisis Management Plan is the ability and readiness to manage business interruptions in order to provide continuity of services at a minimum acceptable level and to safeguard NEON IDEAS (NEON IDEAS)’s financial and reputational position.”

Objective:

• Develop and implement a strategy for managing the cyber incident and crisis communication

Related Process:

• Cyber Crisis Management Plan

Application Security Policy

Policy:

“Application Security Policy states the application security architecture.”

Objective:

The objective of this policy is to define specifications for Information security and Quality related controls of an application system to encourage in application development. This will ensure that adequate security, quality and service continuity controls are identified, defined, developed and
implemented while developing or acquiring applications to be used by NEON IDEAS (NI ).

Related Process:

• Application Security Policy

Data Backup & Recovery Plan

Policy:

“IT Infrastructure Head shall ensure that adequate data backup mechanism is in place to ensure that the data is not lost and can be recovered or restored in the event of an equipment failure, intentional destruction of data, or disaster. Adequate backup mechanism must be in place and monitored regularly to ensure the IT Service Continuity, Quality of NEON IDEAS IT facilities is maintained.”

Objective:

  • • Backup process
  • • Security of backup media
  • • Offsite Backup security
  • • Recovery Testing
  • • Backup Frequency
  •  

Related Process:

• Data Backup & Recovery Plan

Vulnerability Management Policy

Policy:

“The purpose of this policy is to prevent exploitation of technical vulnerabilities by external threats and ensure quality and continuity of the IT Services which are dependent on the IT assets of NEON IDEAS (NI).”

Objective:

• Objective of this policy is to define technical vulnerability management procedure and testing
timeframe for the application, network devices, and servers.

Related Process:

• Vulnerability Management Policy

IS Audit Framework

Policy:

“The purpose of the IS Audit framework is to set out the structure within which Internal Audit provides objective and independent assurance to the Audit team and the senior management of NEON IDEAS over the processes in NEON IDEAS.”

Objective:

1. Confirm to the requirements of the International Standards and relevant legislation or regulations

Related Process:

• IS Audit Framework

Neon Ideas logo – Full-Stack Design & Development Agency in Pune, India specializing in branding, UI/UX, web development, digital marketing, and creative solutions

NEON IDEAS

Data Privacy & Protection Policy

Document No: NI/ISMS/ Pol-24

Date of Issue: 02-02-2026

Revision No: 1.0

Date of Revision :00/00/00

Page No: 2 of 9

1. Approval and Authorisation

Completion of the following signature blocks signifies the review and approval of this Procedure

Name Job Title Signature Date
Authored by:-
Pravin Phule
02-02-2026
Reviewed by:-
Dipti Pathak
02-02-2026
Approved by:-
Dipti Pathak
02-02-2026

2. Change History

Version Author Reason Date
00
Initial Document
02-02-2026

Distribution

1. File server
2. Intranet

Documentation status

This is a controlled document. This document may be printed; however, any printed copies of the document are not controlled. The electronic version maintained in the file server and
Commune are the controlled copy.