Purpose
Blink AI Payments's Information Security Policy has been developed to establish a general approach to information security and the minimization of information misuse, compromise or loss; document security processes and measures; uphold ethical standards and meet the company's regulatory, legal, contractual, and other obligations; control business risk; and ensure that the appropriate company image and reputation is presented.
Scope
- Information in any form, regardless of the media on which it is stored, as well as any facility, system, or network used to store, process, and/or transfer information.
- All Blink AI Payments employees, temporary staff, partners, contractors, vendors, suppliers, and any other person or entity that accesses the company's networks or any other public or private network through company networks or systems.
- All activity while using or accessing the company's information or information processing, storage, or transmission equipment, while on the company premises (owned, rented, leased, or borrowed) or remotely.
- Information resources that have been entrusted to the company by any entity external to the company (i.e. Customers, Staff, and others).
- Documents, messages, and other communications created on or communicated via company systems are considered company business records and may be reviewed by third parties in relation to audits, litigation, process improvement, and compliance.
Background
This policy is the overarching policy over the rest of the security policies, which make up the company's information security program (ISP).
- Acceptable Use Policy
- Asset Management Policy
- Backup Policy
- Business Continuity/Disaster Recovery Plans
- Code of Conduct
- Data Classification, Retention, and Protection Policies
- Encryption and Password Policies
- Incident Response Plan
- Physical Security Policy
- Responsible Disclosure Policy
- Risk Assessment Policy
- Software Development Life Cycle Policy
- System Access Management Policy
- Vendor Management Policy
- Vulnerability Management Policy
Information Security Objectives
It is the policy of Blink AI Payments that information in all forms will be protected from accidental or intentional unauthorized modification, destruction or disclosure throughout its lifecycle. This includes an appropriate level of security over the equipment and software used to process, store, and transmit that information.
The information security goal is to maintain confidentiality, integrity, and availability.
- Confidentiality: data and information are protected from unauthorized access.
- Integrity: data is intact, complete and accurate.
- Availability: IT systems are available when needed.
- Protect information from internal, external, deliberate, or accidental threats.
- Enable secure information sharing.
- Encourage consistent and professional use of information.
- Ensure clarity about roles and responsibilities associated with protecting information.
- Ensure business continuity and minimize business damage.
- Protect the company from legal liability and the inappropriate use of information.
Roles and Responsibilities
The SECURITY OFFICER is responsible for the design, development, maintenance, dissemination, and enforcement of this policy and other ISP policies.
Policy Review, Accessibility, and Exceptions
At minimum on an annual basis, senior management and key personnel discuss, evaluate and document the information security policy to ensure strategic goals and objectives continue to be developed.
At minimum on an annual basis, all security policies are reviewed, modified and/or edited to meet necessary security standards, and signed/approved by authorized personnel.
Policies and procedures are made accessible to employees for review at all times via compliance automation.
Requests for exceptions to policies included within the ISP must be approved by Executive Management after review, and approved exceptions are reviewed annually.
Personnel Security
All personnel are required to acknowledge in writing their understanding of the Information Security Policy, Code of Conduct, and topic-specific policies based on job function during onboarding and annually thereafter. New hire onboarding is completed within 90 days of hire.
Background checks are conducted prior to hire using a third-party service provider and in accordance with relevant laws, regulations, ethics, and business requirements. The HR/People team retains records of background checks.
Management evaluates candidates through a formal interview process that may include verification of academic/professional qualifications, identity verification, reference validation, technical interviews, or other applicable steps.
Training
Management ensures employees, contractors, and third-party users are properly briefed on security roles and responsibilities before access is granted, are provided security expectation guidelines, are regularly notified of security changes, comply with security policies, and maintain role-appropriate security awareness.
All new hires complete information security awareness training during onboarding and annually thereafter. Ongoing training includes security and privacy requirements and correct use of information assets and facilities. Records of completion are retained.
Awareness is supplemented through methods such as newsletters, web-based training, in-person training, and periodic phishing simulations.
Security updates, changes, and incidents are communicated as needed via email or appropriate Slack channels, with annual reminders included in security awareness training.
Incident response and contingency training is provided within 90 days of assuming an incident response role, as required by system/policy changes, and annually.
Periodic security awareness training includes identification and reporting of insider threats, and all employees are responsible for promptly reporting potential insider threats through proper channels.
Intellectual Property Rights
Blink AI Payments takes handling and safeguarding of intellectual property seriously. Intellectual property rights include software or document copyright, design rights, trademarks, patents, and source code licenses.
- Software is acquired only through known and reputable sources to avoid copyright violations.
- Asset inventory identifies all assets with requirements to protect intellectual property rights.
- Proof/evidence of ownership of licenses, master disks, manuals, etc. is maintained.
- Asset inventory review confirms only licensed software and products are installed.
- Compliance with software and information terms and conditions from public networks is ensured.
Information Security Requirements Analysis and Specifications
Blink AI Payments identifies information security requirements using multiple methods, documents the results, reviews them with stakeholders, and integrates requirements/processes in early project stages.
- Methods: policies and regulations, threat modeling, incident reviews, use of vulnerability thresholds.
- Factors include identity confidence for user authentication requirements.
- Access provisioning and authorization processes for business and privileged/technical users.
- User and operator duties and responsibilities communication.
- Protection needs of assets in terms of availability, confidentiality, and integrity.
- Business processes such as transaction logging, monitoring, and non-repudiation requirements.
- Other security controls such as interfaces to logging/monitoring and data leakage detection systems.
Employment Terms and Conditions
- Signing a confidentiality or non-disclosure agreement (NDA) prior to access to confidential information and processing facilities.
- Legal responsibilities and rights, particularly concerning intellectual property.
- Responsibilities for information classification and management of organizational assets associated with information and services handled by employees or contractors.
- Responsibilities for handling information received from third parties.
- Review and agreement with company security policies.
- Duration of responsibilities beyond end of employment.
- Actions for non-compliance with employment terms, conditions, and security policies.
Disciplinary Process
Blink AI Payments's disciplinary policy is designed to provide a structured corrective action process to improve and prevent recurrence of undesirable behavior and performance issues, consistent with company values, HR best practices, and employment laws.
The company reserves the right to combine or skip steps depending on the facts and nature of the offense. The level of intervention may vary based on recurrence, work record, and organizational impact.
- Step 1: Verbal Warning and Counseling.
- Step 2: Formal Written Warning, including acknowledgement, consequences review, and potential performance improvement plan (PIP).
- Step 3: Suspension and Final Written Warning, including immediate suspension when required for safety pending investigation.
- Step 4: Recommendation for Termination of Employment, with required management/HR approvals.
- Illegal behavior is not subject to progressive discipline and may be reported to law enforcement.
- Theft, substance abuse, intoxication, fighting, and other workplace violence are grounds for immediate termination.
Enforcement
Blink AI Payments Management, under authority granted by the CEO, retains the authority and responsibility to monitor and enforce compliance with this policy and other policies, standards, procedures, and guidelines.
Monitoring may be ongoing or random and may include investigation of use of company information resources. The company reserves the right to review communications and activities without notice.
Monitoring activities are limited to what is necessary to determine whether communications/activities violate company policies or align with normal business processing, performance, or quality activities.
Violation of controls established in this policy is prohibited and will be appropriately addressed. Disciplinary actions may include verbal and/or written warnings, suspension, termination, and/or other legal remedies consistent with HR standards and practices.