Information Security Policy¶
| Distribution | Employees and Contractors; Clients upon request |
| Version | 2.1 |
| Approved | 2026-04-21 |
| Approved by | Ben Smith |
Overview¶
The purpose of this policy is to support the confidentiality, integrity, and availability of client content being stored and processed by FooEngine Ltd., hereafter known as 'the company'.
This top level document outlines the company's commitment to information security and the approach it will take to achieve this goal. The information security management system has been developed in alignment with the MPA Content Security Best Practice Guidelines version 5.3.1.
Scope¶
This policy applies to all employees, contractors, and third-parties such as clients or users who are responsible for, and who make use of the company's systems, including digital and physical media, software, hardware, cloud and network infrastructure and applications.
Governance¶
This policy document contains the governance framework of policies and references to related documents which work to support the confidentiality, integrity and availability of information under the company's care, and the implementation of measures in compliance with contractual and legal security requirements. This policy and related documents will be reviewed regularly to ensure they remain relevant and effective.
Security Organisation¶
The business owners are responsible for information security, developing and implementing policies and procedures to mitigate threats and risks.
Acceptable Use¶
Overview¶
This policy addresses MPA Content Security Best Practice Control OR-1.1 (v5.3).
As part of normal operations, the company receives and processes information of various classifications, through various facilities, systems and interfaces.
To protect the information the company processes, those who have access to company systems and information must be made aware of what usage is acceptable to the company (and what is unacceptable).
Unacceptable use of company systems or information exposes the company to risks including financial damage, virus attacks, compromise of systems and services, and potential legal issues.
Acceptable Use Policy - Baseline¶
The below baseline framework is the basis of acceptable use policies provided for sign-off by the different identified user types. Bold text is used in the table below to indicate critical points.
Table 1.3.1
| Topic | Policy |
|---|---|
| Confidentiality | For the avoidance of doubt, any information made available to users concerning the company, its clients or operations is explicitly confidential. |
| Social media | Personnel must not share any company or client information in any form on any social media platform, forum, blog post or website without expressed written consent from an officer of the company who has the authority to give such approval. |
| General use and ownership | Company owned/managed computing assets should be used only for the company business-related purposes - incidental personal use is permitted on a limited basis. For security and network maintenance purposes, authorised individuals within the company may monitor equipment, systems and network traffic at any time in a manner consistent with applicable regional and local legal requirements. |
| Internet use | Employees and contractors are expected to use the Internet responsibly and productively. Internet access is limited to job-related activities and incidental personal use. All Internet data that is composed, transmitted and/or received by company systems is considered to belong to the company and is recognised as part of its official data. It is therefore subject to disclosure for legal reasons and/or to other third parties as required. The equipment, services and technology used to access the Internet are the property of the company, and the company reserves the right to monitor Internet traffic and monitor and access data that is composed, sent, or received through its networks. Emails sent via the company email system must not contain content that is deemed to be offensive. This includes, though is not restricted to, the use of vulgar or harassing language or images. Illegal, violent, pornographic, hateful or terrorist material is strictly forbidden. All sites and downloads may be monitored and/or blocked by the company if they are deemed to be harmful and/or not productive to business. Where the content of client material in the platform may be potentially in violation of this acceptable use policy, the company must be notified as soon as possible as per incident management procedure which is provided as part of personnel training. The installation or use of unapproved software or web based services is strictly prohibited. |
| Artificial Intelligence / Machine Learning (AI/ML) | Artificial Intelligence / Machine Learning tools are only to be used with prior authorisation; Usage is subject to company policy, according to the classification of data processed. |
| Incident reporting | If a user identifies a potential or actual security incident, then they must use the current incident management procedure to notify management as appropriate. |
| Mobile devices / recording equipment | The company prohibits camera, video or audio capture of any confidential information or locations under its care, without prior authorisation. Personally owned mobile devices (phones, tablets, laptops) are subject to restrictions and facility specific policies. |
Business Continuity and Disaster Recovery¶
Overview¶
This policy addresses MPA Content Security Best Practice Controls OR-1.2 and OR-1.3.
Business Continuity (BC) Planning is the process of creating systems of prevention and recovery to mitigate the impact of potential threats to a company. This includes preventative controls and management of personnel to preserve continuity of operations.
Disaster Recovery (DR) Planning is the process of maintaining vital infrastructure and systems following a disruptive event, such as a fire, storm or attack. DR is a subset of BC whose primary objective is to minimise business downtime and reclaim normal operations as soon as possible.
Policy¶
The company must establish and regularly review formal plans for Business Continuity and Disaster Recovery, which may differ according to facility and/or business unit.
The business owners are responsible for business continuity and disaster recovery strategy and planning.
Threats to critical assets, locations, infrastructure and business operations must be defined and documented in the business continuity plans. Some examples of possible threats are:
- Loss of power or communications
- Systems failure
- Natural disasters
- Pandemics
- Cyber attack (e.g. 'ransomware')
Business Continuity and Disaster Recovery plans must include appropriate notification to internal stakeholders, business partners, clients and other third parties as applicable. These plans may include 'Crisis Management' considerations, and will also reference the company's Incident Response Plan.
Any business functions performed remotely must be considered within the scope of the Business Continuity and Disaster Recovery plans.
As a smaller cloud based, 'remote-first' organisation without a physical facility, BCP and DR plans may be combined, as our risk profile does not require 'bricks and mortar' considerations for company managed facilities.
Business Continuity and Disaster Recovery Plan Testing¶
Plans relating to business continuity should be tested regularly, making use of 'tabletop exercises', if applicable.
Recovery Point Objective (RPO) and Recovery Time Objective (RTO) should be defined for critical business functions, and considered when forming continuity plans. Where a 'Shared Security Responsibility Model' is in place with service providers and users, this should be addressed in the continuity planning process.
Workarounds and alternate solutions for operational processes should be identified for maintaining continuity of operations.
For disaster preparedness, prioritised recovery procedures should be defined which should include steps to restore systems.
Adequate cyber security insurance must be scoped, organised and maintained, and any technical or other organisational stipulations by the insurers must be implemented to ensure effective response in the event of a claim.
Data Classification¶
This policy addresses MPA Content Security Best Practice Control OR-1.4.
The company must establish and regularly review a process for classifying, protecting and handling data and assets throughout their respective lifecycles.
The company should classify according to sensitivity and define data retention periods for the various classes identified, with accommodation/exceptions according to client contractual terms. Data must be destroyed according to the current state-of-the-art methods when the retention period ends.
Information assets such as computers, virtual machines, software defined networking components inherit the classification level of the most restricted data passing through them.
If data is shared with/on third-party service providers, responsibilities must be identified, confirmed and documented using appropriate contract clauses and using a shared security responsibility model (SSRM).
Data Classification Table¶
| Classification | Description |
|---|---|
| Client Top Secret | As per Client Confidential, but when Client or Senior Management has determined that a project is at their most restricted classification level. Examples: Unreleased features from major studios e.g. 'TIER 0'; projects otherwise classified as highly sensitive by senior management (e.g. due to sensitivity of content). |
| Client Confidential | Data provided initially by client and/or generated by the company as part of production services. Examples: This is the default classification for client projects and assets. Handling procedures to be aligned with MPA Content Security Best Practices. |
| Internal | Any non-production data generated internally is classified Internal as soon as it is created. Examples: Financial and budgetary information; penetration test results; risk registers; company strategy; data concerning internal know-how; customer lists; code; system designs; contact information; personally identifiable information; company policies. |
| Public | Data and information approved by the business owners for public release. Examples: Press releases; white papers; marketing materials; website content. |
Risk Management¶
Policy¶
This policy addresses MPA Content Security Best Practice Control OR-2.0.
The company must undertake an annual content security risk assessment process, using the current version of MPA Content Security Best Practices to review the security status of applications, workflows, assets and operations.
Risks to confidentiality, integrity of information and availability of services must be considered within the risk management program.
The business owners will meet quarterly to review risk, and involve other personnel / third parties as appropriate.
Any risks to integrity or availability of services must be factored into the business continuity plan / disaster recovery plan as applicable.
The output of any assessments performed must be documented and prioritised, with any remediation statuses communicated where appropriate with stakeholders such as clients or potential clients.
Note: Risk assessments relating to matters other than content security may also be performed.
Background Screening of Personnel¶
This policy addresses MPA Content Security Best Practice Control OR-3.0.
The company must perform appropriate background screening on any personnel having access to information classified as Internal or higher.
These checks will be performed as appropriate to the local legal and privacy regulations, and will include:
- Identity verification
- Reference checks
- Social media checks
- Criminal / financial background checks may be requested
On-Boarding and Off-Boarding of Personnel¶
This policy addresses MPA Content Security Best Practice Controls OR-3.1 and OR-3.2.
Onboarding and offboarding procedures for personnel and users of in scope systems will be defined and implemented, aligned with current MPA Content Security Best Practice.
Security of Third-Parties¶
This policy addresses MPA Content Security Best Practice Control OR-3.4.
Third party service providers used by the company should undergo risk assessments commensurate with the classification of the information they process, and have appropriate confidentiality and information security stipulations in contracts / service level agreements.
MPA Content Security Best Practice version 5.3.1 control OR-3.4 (or the most current release) should be used as a benchmark for the approach to subcontractors and their responsibilities.
Incident Response¶
Overview and Definitions¶
This policy addresses MPA Content Security Best Practice Control OR-4.0.
Incidents are unplanned events which have an adverse effect on the organisation. These require investigation and remediation by an appropriate combination of IT, operations and security personnel.
Examples of incidents can include:
- Unexpected restart of a system
- Ransomware preventing systems from normal function
- Unauthorised access to classified information
- Unauthorised sharing of confidential company or client information (e.g. on social media)
- Loss or theft of a device with access to company information
- Exceptional event preventing access to buildings or systems (e.g. fire, flood, earthquake, etc.)
It is important to note that what may appear as insignificant events to an individual may be symptoms of a larger problem, and remain undetected without detection or notification processes in place. For example a 'phishing' attack may be delivered to multiple personnel concurrently, and not be identified as a coordinated attack without users submitting reports.
The company must establish a formal incident management process covering unplanned events which impact confidentiality, integrity and availability of company data and systems.
The company should make best efforts to define different incident types such as operational incidents, security incidents or emergency incidents which require first responders.
The incident response team is the business owners, with the addition of appropriate resources for the impacted (or potentially impacted) business unit.
Incidents should be addressed within 48 hours (e.g. identified and triaged, and a plan developed within that timeframe).
Remote Working, Remote Sites & Mobile Devices¶
Overview¶
This policy addresses MPA Content Security Best Practice Controls OP-2.0, OP-2.1, TS-1.4, TS-2.9 and 2.11.
All policies and procedures relating to security and acceptable conduct apply to personnel, regardless of working location.
Remote working can introduce certain threats and risks to confidential company and client information and property.
The measures in this policy section are designed to control risks associated with remote working methods and practices by introducing controls relating to location, equipment, mobile devices and methods of remote access.
Note: This policy section relates to company personnel, not client users of any company hosted platforms.
Cloud or data centre providers used will have their security posture evaluated by review of their SOC 2 type 2 and related audit reports.
By making use of company systems, company personnel and users of company hosted platforms incur shared responsibilities for content security, as detailed in the acceptable use and shared responsibility sections of this document, and related materials.
Remote Access Policy - Personnel¶
Classified material accessed, processed and/or stored at remote sites and locations, or accessed remotely must be secured using the following measures:
- Multi-factor authentication must be used for remote access connections
- Remote workers must be trained on this section of the company policies and procedures as part of their security awareness training
- Remote work is only permitted within a location where a worker has control of their environment and network
- Remote workers must acknowledge remote working policies and procedures by signing (wet ink or digitally)
- Remote access methods utilised must be company approved
Warning
Remote work on confidential information is only permitted where unauthorised people are unable to possibly view or hear it. For example - Home is OK, a coffee shop is not OK.
Company Owned Mobile Devices - Requirements¶
Company owned portable computing devices must be secured according to these minimum requirements:
- Full disk encryption enabled (e.g. Windows BitLocker, Apple Mac OS FileVault, Mobile device equivalents)
- Anti-virus/anti-malware protection installed
- Password complexity and age controls as per company password standards
- Auto-lock after 10 minutes of inactivity for a computer, sooner for portable devices (phone, tablet)
- Devices and accounts must not be shared with family members or friends
- Mobile device management implemented
- Ability to perform remote wipe of mobile devices in case of theft, loss or compromise (e.g. use of MDM)
- Entrances and exits of remote working locations be kept secure (e.g. front doors locked)
Danger
Lost or stolen devices must be reported immediately via the incident response procedure.
Company Owned Devices – Guidelines for Remote Working Locations¶
If feasible, or determined as required in relation to a specific project, the following requirements should be implemented at remote working locations:
- Using a wired network and disabling wireless networking on devices performing company business
- Isolating devices performing company business with a segmented network (subnet) at the remote location
- When a wired network is not available, configuring wireless networks with WPA2-PSK (AES) and/or WPA3-SAE rather than WEP/WPA, and follow details in MPA Content Security Best Practice TS-2.11
- Restricting unauthorised access to the screen and audio by others at the remote location (e.g. spouse, children) - use a separate workspace with closed door, headphones etc.
Asset Tracking¶
This policy addresses MPA Content Security Best Practice Control OP-3.0.
The company must make use of a tracking system to catalogue and keep track of client production assets and their derivatives.
- Unique identifiers must be created per asset, with associated relevant metadata (including timestamps, location, accesses etc.)
- Tracking logs must be retained for a year at minimum
- Tracking logs should be regularly reviewed for anomalies
- Watermarking must be implemented if required by client contract
High Security Projects¶
This policy addresses MPA Content Security Best Practice Control OP-3.1.
All production related data and content submitted by clients is classified as Client Confidential by default. Clients or company management may determine a more restricted classification level for a given project.
In cases where extra handling controls are required, if requested the following measures could be used:
- Physical access in specific high-security zones
- Logical access limited to a smaller subset of users
- Additional control over where the content can be viewed, specific IP addresses using specific DRM requirements, etc.
- Additional NDAs for personnel involved in projects
Physical Security¶
This policy addresses the 'Physical Security' domain controls from the MPA Content Security Best Practices.
The company must implement appropriate physical security controls for premises in scope according to the current MPA Content Security Best Practices and designated client specific requirements.
For public cloud, data centre or similar services where physical security is managed by a third party, the third party's security posture should be evaluated as per MPA Content Security Best Practices v5.3.1, control numbers PS-3.2 and PS-3.3.
Technical Security¶
Secure Transfer of Sensitive Content¶
This policy addresses MPA Content Security Best Practice Controls TS-1.0 and TS-1.15.
The company must put in place and maintain measures to protect content being transferred in and out of its systems.
Documentation regarding the content transfer workflow and applied security controls must be created and maintained.
Content must be encrypted in transit and at rest with an encryption cipher of AES 256 at minimum.
Secure Configuration and Patching¶
This policy addresses MPA Content Security Best Practice Controls TS-1.1 and TS-4.2.
Security baseline definitions as per MPA Best Practice TS-1.1 must be created and maintained for the following systems:
- Systems at company managed facilities
- Components of any hosted platforms
- Computing devices for those with access to company/client data
Adherence to the baseline configurations must be regularly monitored, with any deviations resolved as applicable.
Applicable devices must be monitored for patching status, with notification when patch installation is required. Systems performing patch monitoring must receive regular updates.
A plan for patching issues flagged as CRITICAL should be assembled within 48 hours, and a two week deployment deadline should be established for these.
Every effort should be made to deploy patches into a testing environment before deployment to production.
Any unsupported systems must be decommissioned.
Where patching is not feasible, compensating controls should be implemented and recorded.
Baseline Definition for Company Systems¶
- Endpoint protection must be installed
- Default local users (such as guest) must be disabled or removed, with any default or shared usernames changed
- Default network shares must be removed
- Unnecessary and unauthorised software, protocols and services must be uninstalled or disabled
- Users must not be administrators of their own workstations, unless required for production reasons
- I/O, mass storage, external storage and mobile storage devices must be disabled on systems handling production data (except nominated Data I/O machines)
- Secure configuration standards must be applied before system is connected to production
- Wireless transfer applications must be prohibited on production systems (examples: Bluetooth, AirDrop)
- Local firewalls should be enabled
- All systems should be protected with password-protected screensavers
- Group Policy / MDM systems should be used to standardise and enforce baselines for systems
Default Accounts¶
This policy addresses MPA Content Security Best Practice Control TS-1.2.
Default administrator accounts of systems in scope must be identified and the following measures applied:
- Default password changed
- Default username changed
- Such accounts only to be used when 'elevation' is required
Endpoint Protection¶
This policy addresses MPA Content Security Best Practice Control TS-1.3.
Endpoint protection is monitoring and protecting system endpoints against cyber threats.
'Endpoints' within the scope of this policy include:
- Workstations (e.g. desktop/laptop computers)
- Servers
- SAN/NAS devices
- Virtual machines
- Containers
The company must implement an endpoint protection process for endpoints in scope, which must include the following:
- Endpoint protection, anti-virus and anti-malware software managed by a central administrative console
- Updating anti-virus and anti-malware definitions regularly and performing regular scans on systems
- Delivering logs to a central logging repository
- Agreed endpoint protection responsibilities with any third-parties who host endpoints on the company's behalf
Security Information and Event Management¶
This policy addresses MPA Content Security Best Practice Control TS-1.5.
The company must establish a security information and event management (SIEM) process, with the following components:
- Centrally logging firewalls, authentication servers, network operating systems, content transfer systems, remote access mechanisms, virtual machines/servers, storage services, databases, container-based application services, API gateway connections, key generation/management, and any relevant system data
- Retaining logs for a year at minimum, where local laws permit
- Limiting access to the logging infrastructure to only authorised personnel
- Notifying automatically when security events are detected
- MPA TS-1.5 must be referred to when creating SIEM configurations, and procedures must be documented
Authentication, Authorisation, Identity and Access Management (IAM)¶
This policy addresses MPA Content Security Best Practice Controls TS-1.6 and TS-1.7.
All systems accessible by personnel and client users must be organised as follows:
-
Authentication
- Unique username per individual
- Shared account use avoided unless required for production reasons
- Password controls applied as per separately maintained standard
- Multi-factor authentication on internet facing systems (e.g. webmail / web portals) and code repositories
-
Authorisation
- Permissions assigned using the 'principle of least privilege' - e.g. 'on a need to know basis'
- Monitoring of user authorisation events (successful and unsuccessful) in an appropriate logging system
Authentication and authorisation standards with required configuration details will be maintained and distributed to business units as appropriate.
Service accounts should have successful logons, failed logons, and lockouts monitored and centrally logged.
Application Configuration (Licensed Applications)¶
This policy addresses MPA Content Security Best Practice Control TS-1.16.
For licensed applications, application configuration guidelines must be sourced and implemented as provided by the application provider:
- Configuration guidelines must be applied to host and guest OSes (as applicable)
- Ensure that applications are licensed by an authorised source, and not expired
- Default and/or unused identities/principles/roles, functions and services must be changed, disabled or removed
- Tests must be performed before deployments into production environment
- Hardening guidelines must be reviewed annually and/or when system components are changed
- Count of administrative accounts must be minimised
- Applications must be logged off after a defined period of inactivity (for systems with user interfaces)
- Appropriate antivirus/anti-malware must be installed on systems in scope
- Packages should be verified for being up to date and authentic (e.g. using official sources and validating checksums)
Application Configuration (In-House Developed)¶
This policy addresses MPA Content Security Best Practice Control TS-1.17.
For in-house developed applications, secure configuration guidelines must be documented.
- General requirements as per licensed applications
- Follow testing procedures before deployment into production environments
- Designs must be reviewed annually
- Components and modules used in development should be documented
- Cybersecurity professionals should be used to identify security vulnerabilities in source code, repositories, API integrations and so on
Externally Accessible Services¶
This policy addresses aspects of MPA Content Security Best Practice Control TS-2.0.
Externally accessible servers and services must be made available using a 'DMZ' VLAN or 'public subnet'.
Access to any internal networks from the external network must be restricted using network controls such as firewall policies, ACLs, 'security groups' and similar technologies.
An inventory of externally exposed endpoints (IP addresses, hostnames) must be kept.
Email Filtering¶
This policy addresses MPA Content Security Best Practice Control TS-1.8.
To mitigate the risks associated with email, the company must implement configurations and procedures to detect, report and block the following:
- Phishing emails
- Malware/ransomware
- Transmission of sensitive material / client content (e.g. Data Loss Prevention)
-
Executable attachments
-
Email phishing or email related incidents should be factored into incident management procedures for reporting.
- SPF, DKIM and DMARC records must be configured on company domains.
- DMARC policy must be adequately configured - REJECT or QUARANTINE.
Web Portal Security¶
This policy addresses MPA Content Security Best Practice Control TS-1.9.
The company must implement a process for securing its web portals according to MPA Best Practice TS-1.9.
Internally accessible web portals vs. portals open to the public internet may have different control considerations.
Shared Responsibility¶
Overview¶
This policy addresses MPA Content Security Best Practice Control TS-1.10.
The company may make internet accessible 'cloud' platforms available to users.
Company employees and contractors, clients and other users may have access to cloud platforms granted as required.
'Public cloud providers' may be used to host aspects of the company's infrastructure.
Each party described has responsibilities for certain aspects of their interaction with the systems, and a shared responsibility model must be established to make these responsibilities explicit.
Policy¶
- Shared responsibility models will be determined by the company as required
- The shared responsibility models (or appropriate sections thereof) will be shared with relevant parties
- Relevant parties must provide sign-off according to contractual terms before making use of any in scope systems (which will include acceptance of shared responsibilities)
Cloud Misconfiguration Detection¶
The company must implement a procedure for detecting cloud misconfigurations as per MPA Content Security Best Practice TS-1.12.
Security and Privacy by Design¶
This policy addresses MPA Content Security Best Practice Control TS-1.13.
The company must establish a process to develop systems and applications based on principles of Security by Design (SbD) and Privacy by Design (PbD).
The development process must include the following:
- Data protection and privacy requirements included by default at the design state and throughout the system and application development lifecycle
- Following applicable regional/local privacy laws e.g. GDPR
Change and Software Development Management¶
Background¶
This policy addresses MPA Content Security Best Practice Controls TS-5.0, TS-1.13, TS-1.14 and 1.15.
System and network configuration changes made to company systems, data and applications can introduce risks to confidentiality, integrity and availability of data and services.
Software development and/or configuration changes without consideration of various security aspects can add risk to an organisation.
Secrets such as system credentials or cloud access keys can be mistakenly put into source code repositories.
Some exploitable vulnerabilities can be included in a software project by developers using open source modules or frameworks which have not been security tested.
Non-sanitised inputs to applications, and omitting consideration of common threats such as the 'OWASP TOP 10' can also introduce threats to networks and inner database systems.
This policy is written to integrate security controls into the company's change management procedure and software development lifecycle, to mitigate risks associated with changes to software and networked systems.
Change Management Policy¶
- A procedure for managing changes to data, applications, networks and system components must be in place.
- A system inventory must be maintained
- Risks relating to identified system components must be catalogued
- Changes, test results and approvals must be logged
- Backup and roll-back procedures must be implemented and documented where applicable
Software Development and Code Management Policy¶
The company must establish and regularly review a process for source code management, secure software development for application design, development and deployment.
The source code management software development process must include a testing strategy, be agnostic of system or developer location, and include the following controls:
- Source code must be stored in private repositories, protected by multi-factor authentication
- Access to code must be based on the principle of least privilege
- Credentials and secrets must not be embedded in code or committed to repositories - rather a 'secrets management' service must be used to rotate, manage and retrieve credentials or secrets
- Credentials and sensitive data must be encrypted and stored inside a dedicated secret manager
- Performing a code security review for each build
- Performing application and code repository security testing
- Including scanning in continuous integration/continuous delivery automated pipelines and deployments
- Including scanning open source libraries
- Investigating any software issues found and putting them on a remediation plan
Network Topology Diagram¶
This policy addresses MPA Content Security Best Practice Control TS-2.2.
Network topology diagrams of in scope networks must be maintained and updated when configurations change. The network topology diagrams must include WAN, DMZ, LAN, Wireless, VLAN/subnets, Firewalls, Switches, Endpoints, etc.
Network and Firewall Management¶
These policy components address MPA Content Security Best Practices TS-2.3 and TS-2.4.
Ports and SNMP¶
For devices under physical and logical management:
- Layer 3 of the OSI model must be used to manage networks in scope
- If Layer 2 devices are in use then upstream Layer 3 devices should be used for traffic management and isolation
- Port security should be enabled
- Unused ports should be disabled
- SNMP should be disabled if not in use; if used then SNMPv3 or higher should be used, with strong community strings
Also, the following aspects should be considered:
- Administrator credentials should be strong
- Physical ethernet locks should be used where required to prevent unauthorised access to restricted networks
- Network-based access control (802.1x)
- Hubs and repeaters should not be used
Firewall Configuration Requirements¶
- Direct network access from the WAN (Internet) to internal networks must be prohibited
- WAN traffic must only be permitted to explicit hosts in a DMZ (or DMZ equivalent), and only on explicit ports
- Firewall policies must be reviewed regularly
- Logs for all network traffic and configuration changes must be generated and retained
- A Web Application Firewall (WAF) must be deployed between the internet and web applications
- Incoming and outgoing requests must be denied by default
- Incoming and outgoing requests must be enabled only for explicitly defined requests
- Unencrypted communication protocols (e.g. Telnet, FTP) must be replaced with encrypted equivalents
- Core services should be managed from a dedicated service or management network, if applicable (e.g. network switches, firewall management interfaces, server management interfaces)
- Egress filtering should be used to restrict unauthorized/unknown outbound transfers
- The following must be blocked: non-routable IP addresses, UDP and ICMP echo requests, unused ports and services, unauthorised DNS zone transfers
Separation of Production Networks¶
This policy addresses MPA Content Security Best Practice Control TS-2.5, and database security aspects of OR-1.4.
Internal networks containing classified material must be separated from less secure networks by making use of separate, more restricted subnets to contain classified material. Restrictions are to be imposed on classified subnets making use of stateful firewall policies, and 'air-gapping' as appropriate.
Databases containing classified material shall be stored in inner, more restricted network segments. Dual-homing (e.g. connection of a host to two networks) should be prohibited.
Firewall Management¶
This policy addresses MPA Content Security Best Practice Control TS-2.6.
Changes to aspects of firewall and network configurations in scope must be logged using the approved change management procedure.
Firewalls must be configured to log and notify on appropriate security events.
Intrusion Detection and Prevention¶
This policy addresses MPA Content Security Best Practice Control TS-2.7.
On-Premises Systems¶
Firewalls must be correctly licensed and configured with intrusion detection and prevention systems, including the following:
- Suspicious activity must be blocked and alerted on
- Gateway anti-virus, URL filtering must be enabled
- Attack signature definitions must be updated regularly
- Activity and configuration changes must be logged
Cloud-Hosted Environments¶
The cloud provider's web application firewall (WAF) (or similar) must be used.
The cloud provider's system configuration / vulnerability management tool must be activated and configured to notify on issues identified.
User Workstations¶
A suitable enterprise host-based endpoint protection solution must be used to identify vulnerabilities and threats on user workstations.
The solution in place must have a centrally administered dashboard for coverage and vulnerability review by management.
Note: Network based intrusion detection is not currently required locally for the company's remote users - as no content is processed locally - compensating controls are in place.
Wireless Networks¶
This policy addresses MPA Content Security Best Practice Control TS-2.11.
The following considerations apply to environments where sensitive data is accessed via wireless networks.
- Wireless environment must be configured with WPA2-EAP (AES) and/or WPA3-SAE
- Default administrator credentials for wireless management devices must be changed
- Default SSID must be changed and use non-company, non-production identifiable names
- Wireless passphrase must be complex and change regularly
- RADIUS or equivalent must be used for authentication (not applicable to Guest networks)
- Wireless cards on production computers must be disabled/disconnected
- Guest networks must be segregated from non-Guest networks (and only be able to access the Internet)
The following aspects can be considered regarding wireless networks:
- WPA-2 Enterprise
- MAC address filtering; disabling wireless interface MAC addresses of production devices
- Physical broadcast range limitation to only required area
- 802.1X implementation
- User accounts for wireless access managed via LDAP/AD
- Public Key Infrastructure being used to generate and manage client and server certificates
- WPA2/WPA3 configured with CCMP (AES) encryption
- Identify rogue wireless access points with suitable scanning mechanisms
Internet Access¶
This policy addresses MPA Content Security Best Practice Control TS-2.8.
Direct internet access from production networks or networks which process content must be prohibited.
Email system access from such networks must also be prohibited (email protocols such as SMTP/IMAP, or email web clients).
Outbound traffic must be denied by default, to prevent data loss.
For any systems requiring internet access, limited access must be configured according to MPA Content Security Best Practice TS-2.8.
Web Filtering¶
This policy addresses MPA Content Security Best Practice Control TS-2.10.
Web filtering for personnel laptops/computers must be implemented - preventing peer-to-peer file sharing, malware/ransomware, and malicious sites.
Web filtering of traffic inside cloud application infrastructure which does not have any human users accessing operating system or container components may not be required, though outbound restrictions should be applied on unnecessary traffic.
Cloud User Access and Intra-Tenant Segregation¶
This policy addresses MPA Content Security Best Practice Control TS-2.12.
Background¶
The company is both a consumer and provider of 'cloud' services.
The company is a consumer of public cloud services for their own infrastructure, and also application development, deployment and maintenance.
The company is also a provider of cloud services for its clients, who may authenticate themselves and are then subsequently authorised to perform certain activities.
Policy¶
A process must be established and maintained to configure cloud systems in scope so that cloud service provider and cloud service consumer user access and intra-tenant access is logically segregated between tenants.
The company must make use of available SOC 2 type 2 reports to validate inter-client segregation from their chosen infrastructure provider(s).
The company must implement designs and processes to segment their own client users - e.g. Client A must not be able to access Client B's data; and where necessary, Client A data must be ring-fenced from Client B's data.
Encryption¶
This policy addresses MPA Content Security Best Practice Control TS-3.0.
Data requiring encryption according to its classification must be encrypted according to the following measures:
- Minimum of AES 256 for content at rest and in motion
- Access to keys only to be granted to authorised users
- File based / drive based encryption to be used according to requirement
- Decryption keys to be transmitted 'out of band'
- Backups of sensitive material must be encrypted
- Cloud provider key management systems must be used in cloud environments
- Key transactions and activity must be logged
Hard drives of portable computers must use disk encryption (e.g. using FileVault on Mac / BitLocker on Windows).
Exceptions to this encryption policy must be registered according to the security exception procedure.
Encryption Key Management¶
This policy addresses MPA Content Security Best Practice Control TS-3.2.
- Decryption keys, keypad PINs, and/or passwords must be communicated using an out-of-band protocol (i.e., not on the same storage media as the content itself)
- Keys must be changed/rotated at a defined cadence
- Grant key access only to authorised personnel
- Segregate key management duties from key usage
Recommendations from the MPA Best Practice TS-3.2 should be reviewed when assembling key management procedures.
Vulnerability Management¶
This policy addresses MPA Content Security Best Practice Control TS-4.0.
Vulnerability scanning shall be performed on the following targets:
- Production networks
- Non-production networks
- APIs
Vulnerability scanning will be performed at the following frequencies:
- On external IP ranges and hosts - monthly
- On internal IP ranges and hosts - quarterly
After scanning, remediation plans will be created for all vulnerabilities detected.
Vulnerability scans shall be performed after any major application or infrastructure change.
Scan tools and configurations shall be determined according to the properties of the targets; use of OWASP definitions and techniques can be considered.
Critical vulnerabilities discovered should be investigated and a remediation plan created within 48 hours.
Penetration Testing¶
This policy addresses MPA Content Security Best Practice Control TS-4.1.
Penetration testing shall be performed annually on external IP ranges, hosts, web applications, APIs and content transfer tools, with the following requirements:
- Issues discovered shall be investigated and have remediation plans developed
- Tests performed by suitably qualified independent personnel
- Tests performed after any major application or infrastructure change
The following can be considered in test scope depending on the systems being tested:
- Application and Network Architecture Review
- Encryption at rest and in transit
- Private storage review
- Authenticated and unauthenticated testing
- Network segmentation testing
- OWASP definitions and techniques
Backup¶
Discovery and Determination¶
- Each department must identify the information assets / system components required to recover their operational processes in the case of a disruptive incident
- 'Mission Critical' information assets must be labelled. These are the services, systems, and components necessary to ensure immediate survival during outages and other incidents
- 'Business Critical' information assets must be labelled. These are services, systems and processes required for normal operations, though not necessary for immediate survival during continuity incidents
- Each identified critical information asset must have the following values determined and documented:
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO)
- Backup retention period
- Required restore testing frequency
Note: Some classes of information assets may be ephemeral (e.g., only required for a short time), or can be regenerated rapidly.
Public cloud platform database and storage services can make use of multi-availability zone or multi-region capabilities to support data availability resilience.
If system owners determine that an asset is ephemeral, or that the resilience of configured cloud platform services is adequate, then backup of the ephemeral asset is not required. In cases where the asset can be rebuilt, the assets required to rebuild it must be backed up.
Backup Configuration¶
- Each identified information asset must have a defined backup procedure, with a matching restoration procedure.
- Restore procedures must be stored separately from the sites or assets they support.
- Local backups can be used on-premises and between facilities to leverage local network bandwidth efficiencies.
- Backups must be encrypted according to the company encryption policy.
- Backup systems must be configured to send success and/or failure alert notifications to the system owner's support team.
- Backup status notifications must be sent to a system which would remain accessible during primary system unavailability.
- Restore tests must be performed and logged according to the required restore frequency.
- Backup information must be assigned an appropriate level of physical and environmental protection requirement consistent with the standards applied at the primary application.
Privacy¶
Privacy matters are governed by FooEngine Ltd.'s dedicated Data Protection & Privacy Policy.
Exceptions¶
Any exceptions (e.g. approved breaches of clauses within this policy) which have been determined acceptable by the business owners must be recorded in the company risk register as an authorised exception, and reviewed regularly.