Cyber Security Policy

Introduction

Elev8 Training holds the cyber essentials kitemark for cyber security. As part of our ongoing commitment to maintaining a safe and secure work and learning environment for all.  We have adopted key security principles that help to mitigate the threats relating to cyber security. 


Aims & Objectives

The cyber security policy provides key information on the procedures to ensure that the risk of cyberthreats are minimised. This also links to the safeguarding & Prevent policy and procedures, to help protect learners and staff from risk relating to cyber security


Removable media policy 

1. Where possible no sensitive information should be stored on a removable device.

2. Where this is not possible the removable media must be used with caution and approved by a senior manager prior to use.

3. All removable media must be scanned for viruses prior to use. encrypted and password protected. It must be used in a secure manner and must be stored in a secure location when not in use,  labelled with the user's name, date of use and purpose of use.

4. All removable media must be securely destroyed when no longer needed.

5. All removable media must be used in accordance with the company's acceptable use policy.


Information Incident Management Process


Objectives

Incident Management process objectives are to ensure that standardised methods and procedures are used for the efficient and prompt response, analysis, documentation, ongoing management and reporting of incidents


Scope

Incident management includes any event which disrupts, or which could disrupt service. This includes events which are communicated directly by users, either through google workspace or any other stakeholder or other authority.

This includes any incident that relates to information that is or was held within the IT systems relating to the organisation - including those outside the scope of GDPR.  

Staff should use the cyber security reporting process to identify any incidents. 


Timescales

Timescales must be agreed for all incidents by the leadership team according to their priority; this includes response and resolution targets. These should be stated within the incident action plan. 


Major Incidents

A separate procedure, with shorter timescales and greater urgency, must be used for 'major' incidents. A definition of what constitutes a major incident must be agreed upon and ideally mapped onto the overall incident prioritisation scheme. 

When necessary, a specialist can be used by the Management to ensure that adequate resources and focus are provided to find a swift solution.

All affected stakeholders should be informed of the incident through management communication channels along with the response plan.  


Incident Status Tracking

During the lifecycle of an incident, different status occurs; here are some examples :

New - an incident is submitted but is not assigned for resolution

Assigned - an incident is assigned for resolution

In process - the incident is in the process of being investigated for resolution

Resolved - a resolution has been put in place



Employer Responsibilities: 


 

Employee Responsibilities: 














This policy has been reviewed and authorised by

Kieran England  on 20/3/2022