This Information Security Policy establishes Marklo’s approach to protecting the confidentiality, integrity, and availability of the information we process on behalf of our customers and within our own business. It sets out the roles, controls, and expectations that all Marklo personnel must follow.
1. Scope and Applicability
2. Roles and Responsibilities
3. Internal Policies and Supporting Documents
4. Risk Management
5. Access Control
6. Encryption
7. Pseudonymization
8. Asset Management
9. Secure Development and Change Management
10. Security Training and Awareness
11. Third Parties and Subprocessors
12. Incident Response
13. Internal and External Audits
14. Policy Exceptions
15. Policy Review and Revision
16. Version History