Cyber Security Policy

1. Roles and Responsibility

Applies to all SPC employees, contractors, volunteers, whether working remotely or on site.

2. Password

Any password used must be secure and kept secret. Using double security is advisable. Do not use common information such as birth dates or simple sequences like abc12345.

3. Data Transferring

Data must ONLY be shared over the company network/system and treated as CONFIDENTIAL. Store data in a shared drive that is accessible only by authorized personnel.

4. Unidentified Source

Do not attempt to open any unidentified link from an unknown source. Always conduct a preliminary investigation first.

5. Physical Device

All devices in the company must be protected with authorized firewalls and anti-malware software. DO NOT download unauthorized or illegal software, or access suspicious websites.

6. Communication

Awareness training must be provided to all employees. Regularly inform employees of new scam emails, viruses, and ways to combat them.

7. Incident Response

Any incident must be reported directly to ADMIN. Do not switch off the workstation. IMMEDIATELY unplug the internet cable or disconnect WiFi.