Effective Date: February 27, 2025
1. Purpose
At GemBox Ltd., we are committed to ensuring the security of our software development processes and the protection of our customers' sensitive data. We have established a Workforce Device Security Policy to maintain a high standard of security across all work-related activities.
This document outlines our security requirements for all employees and contractors who use devices (whether owned by GemBox or the individual) when working for GemBox, providing services to GemBox, or providing services on behalf of GemBox.
2. Scope
This policy applies to all employees and contractors who use their personal or company-issued devices to execute tasks for GemBox.
3. Security Requirements
3.1. Access Control & Authentication
- Passwords must be at least 8 characters long and include uppercase, lowercase, numbers, and symbols.
- Multi-Factor Authentication (MFA) is mandatory for all work-related accounts.
- Passwords, API keys, or other credentials must not be written down or stored insecurely. Instead, all credentials must be managed using 1Password password manager.
- Automatic screen locking must be enabled after 10 minutes of inactivity to prevent unauthorized access.
3.2. Device Security
- All devices used for work must run a stable, actively maintained version of Windows, macOS, or Linux that is currently supported by the respective OS vendor.
- Antivirus and endpoint protection (e.g., Microsoft Defender, SentinelOne, CrowdStrike) must be active and up to date.
- Firewall must be enabled to protect against unauthorized access.
3.3. Data Security & Privacy
- Use only approved applications for work-related tasks.
- AI tools used at work must have data collection disabled to prevent leakage of sensitive information.
- External storage solutions such as USB drives, personal cloud storage (Google Drive, Dropbox), or external email services must not be used for work-related data.
- Customer documents must be permanently deleted (Shift+Del on Windows) once they are no longer needed.
- The PC recycle bin should be emptied regularly to prevent data leaks.
4. Compliance
To ensure continued compliance with this policy, we have implemented a yearly self-assessment checklist that all employees and contractors must complete. Responses will be stored at least for five years for auditing purposes.
5. Enforcement
Failure to comply with this policy may result in restricted access to company systems, security reviews, or contract termination.
6. Review & Updates
This policy is subject to annual review and updates based on emerging security threats and evolving best practices. Employees and contractors will be notified of any changes accordingly.