Table of Contents
- 1. Purpose
- 2. Scope
- 3. Policy Statement
- 4. Roles and Responsibilities
- 5. Policy Requirements
- 6. Implementation Guidance
- 7. Monitoring, Evidence, and Compliance
- 8. Exceptions
- 9. Review and Maintenance
- 10. Related Standards
1. Purpose
Ligala Tech Pte Information Security Management Policy establishes the company’s foundational governance for protecting information assets, client data, systems, and supporting services. As a small legal technology firm operating in Singapore, Ligala Tech Pte handles information that may include confidential client materials, legal workflow data, account credentials, and internal business records. This policy sets the minimum management expectations for how security is directed, monitored, and improved across the organization.
The policy is designed to reduce ad hoc security decisions and ensure that risk ownership, accountability, and control objectives are defined at the management level. It provides a consistent framework for selecting and operating security controls in cloud services, endpoints, communications tools, and business processes. It also supports the company’s ability to demonstrate responsible handling of personal data and confidential information, which is essential in a legal technology environment.
This policy is aligned with ISO 27001 principles for an information security management system and supports Singapore PDPA accountability expectations by requiring oversight, documentation, periodic review, and enforceable responsibilities. It is intended to be practical for a small organization: concise enough to operate effectively, but strong enough to support trust with customers, partners, and regulators.
2. Scope
This policy applies to all Ligala Tech Pte personnel, including employees, directors, contractors, consultants, interns, and any third parties who access company information or systems. It covers all information in any form, whether stored, processed, transmitted, or disposed of by the company. This includes information hosted in cloud services, information on company-managed devices, and information handled through approved business applications.
The scope includes systems used to build, support, administer, secure, and deliver the company’s products and services, including collaboration tools, identity systems, code repositories, customer support systems, infrastructure services, and data storage platforms. It also applies to information received from customers, prospects, vendors, and service providers, especially where such information may include personal data or legally sensitive material.
This policy applies regardless of location. Because Ligala Tech Pte may support remote work and cloud-first operations, security responsibilities continue when personnel access company resources from home, public networks, client sites, or travel locations. Any business process that creates, stores, transmits, or destroys information within the company’s control is included in scope.
3. Policy Statement
Ligala Tech Pte shall protect the confidentiality, integrity, and availability of information in a manner proportionate to the company’s size, risk exposure, legal obligations, and customer commitments. Security shall be managed as a business responsibility, not only a technical function. Management shall define expectations, assign accountable owners, approve risk decisions, and ensure that security controls are implemented, monitored, and improved over time.
The company shall maintain an information security management approach that is risk-based and documented. Security controls shall be selected according to the sensitivity of information, the criticality of services, the company’s operational model, and applicable legal and contractual obligations. For a legal technology firm, this includes particular attention to client confidentiality, access control, encryption, auditability, and secure handling of personal data under Singapore PDPA requirements.
Ligala Tech Pte shall establish a culture of accountability. Personnel are expected to understand their security responsibilities, follow approved procedures, report incidents and weaknesses promptly, and participate in training and review activities. Failure to comply with this policy may result in access restrictions, disciplinary action, contract remedies, or termination of engagement, depending on the person’s relationship with the company and the severity of the issue.
4. Roles and Responsibilities
- Executive Director: Approves this policy, sets the tone for security governance, accepts residual risk above defined thresholds, and ensures that sufficient resources are allocated for security, privacy, and resilience.
- Information Security Owner or designated Security Lead: Maintains the security program, coordinates risk assessments, tracks control implementation, manages exceptions, and reports security status, incidents, and improvement items to management.
- Data Protection Officer or privacy-designated lead: Oversees personal data handling practices, advises on PDPA obligations, supports privacy impact reviews, and coordinates responses to data subject requests and privacy-related incidents.
- System Administrators or Technology Operations staff: Implement technical controls, manage identity and access, maintain logging, patching, backups, and configuration standards, and provide evidence of operational compliance.
- Product and Engineering Lead: Ensures security requirements are built into product design, code review, deployment practices, and vendor integrations; owns remediation of product-related vulnerabilities and secure development controls.
- All Personnel: Protect company information, use approved tools, complete required training, report incidents or suspicious activity, follow access and data handling rules, and return or delete information when no longer authorized.
- Human Resources or People Operations: Ensures onboarding and offboarding security steps are completed, including confidentiality acknowledgments, access requests, and return of company assets.
- Vendor or Procurement Owner: Ensures third-party services are reviewed for security and privacy risks, contractual safeguards are in place, and vendor access is limited and reviewed.
- Business Process Owners: Define data handling needs for their processes, identify risks, approve access requests for their areas, and ensure control requirements are followed in day-to-day operations.
5. Policy Requirements
- Information security risks shall be identified and documented for material systems, business processes, and data flows. Owner: Information Security Owner and relevant process owner. Frequency: At onboarding of new systems and at least annually. Evidence: Risk register, assessment records, and tracked remediation actions.
- Access to systems and data shall be granted on least privilege and based on approved business need. Owner: System Administrators and process owners. Frequency: At onboarding, role change, and quarterly review. Evidence: Access approval records, access review logs, and account listings.
- Multi-factor authentication shall be enabled for all remote access, administrative access, and critical cloud services. Owner: System Administrators. Frequency: Continuous with quarterly verification. Evidence: Configuration screenshots, identity provider settings, and audit logs.
- Company devices and approved endpoints shall be protected by device encryption, screen locking, malware protection, and supported operating systems. Owner: Technology Operations. Frequency: Continuous with monthly checks. Evidence: Endpoint management reports and compliance dashboards.
- Sensitive information, including client-confidential material and personal data, shall be encrypted in transit and at rest where technically feasible. Owner: Technology Operations and Product/Engineering Lead. Frequency: Continuous with annual verification. Evidence: Cloud configuration records, architecture diagrams, and encryption settings.
- Security logging shall be enabled for identity, administrative, and key application events, and retained according to business and legal needs. Owner: System Administrators. Frequency: Continuous with monthly review. Evidence: Log retention settings, monitoring alerts, and review records.
- Security patches and critical updates shall be applied within defined remediation timelines based on risk. Owner: Technology Operations. Frequency: Ongoing with weekly tracking. Evidence: Patch reports, vulnerability tickets, and closure records.
- Backups for critical systems and data shall be performed, protected from unauthorized alteration, and tested for restore success. Owner: Technology Operations. Frequency: Scheduled backups with quarterly restore tests. Evidence: Backup job logs, test restoration records, and incident notes.
- Security awareness and confidentiality training shall be completed by all personnel before access is fully enabled and refreshed annually. Owner: Human Resources and Information Security Owner. Frequency: Onboarding and annual refresh. Evidence: Training completion records and acknowledgments.
- Third-party service providers that process company or client information shall be assessed for security and privacy risk before onboarding and periodically thereafter. Owner: Vendor or Procurement Owner. Frequency: Before contract execution and annually. Evidence: Vendor assessments, contract clauses, and review notes.
- Security incidents, suspected breaches, and privacy events shall be reported immediately to the Information Security Owner and Data Protection Officer, where applicable. Owner: All Personnel, with response coordination by Security and Privacy leads. Frequency: Immediate reporting and documented closure. Evidence: Incident tickets, investigation records, and post-incident actions.
- Secure development practices shall be followed for any software or configuration changes affecting customer-facing or internal services. Owner: Product and Engineering Lead. Frequency: For each release cycle and major change. Evidence: Code review records, testing results, and deployment approvals.
- Information shall be classified and handled according to sensitivity, with restrictions on sharing, storage, and disposal. Owner: All Personnel, with oversight by the Security Lead. Frequency: Continuous with periodic spot checks. Evidence: Classification labels, handling guidance, and disposal records.
- Records containing personal data or confidential information shall be retained and disposed of according to approved retention rules. Owner: Business Process Owners and Data Protection Officer. Frequency: Ongoing with annual review. Evidence: Retention schedule, deletion logs, and archival controls.
6. Implementation Guidance
Ligala Tech Pte should implement this policy through a small, centralized security operating model. The Executive Director should formally appoint the Information Security Owner and Data Protection Officer function, even if the same person holds both responsibilities in a small team. Responsibilities should be documented in role descriptions, onboarding materials, and management meeting agendas so security is clearly owned and not assumed. A lightweight security committee or monthly management review can be used to track risk, incidents, exceptions, and remediation actions.
Operationally, the company should start with the highest-risk assets: identity systems, cloud storage, source code repositories, customer databases, and communication platforms. Each system should have an identified owner, approved access list, logging enabled, backup coverage, and a documented recovery method. For a legal technology company, special attention should be given to how client materials are uploaded, shared internally, exported, and deleted. Processes should be written in plain language so personnel can follow them consistently without extensive supervision.
Practical tooling may include a cloud identity provider with multi-factor authentication, an endpoint management platform for enforcing encryption and patch status, a ticketing system for access and incident records, and a secure password manager for credential sharing avoidance. A simple risk register and vendor review template can support repeatable governance. Where possible, security controls should be embedded in existing workflows, such as onboarding checklists, release approvals, and procurement steps, so compliance becomes part of normal operations rather than an extra burden.
7. Monitoring, Evidence, and Compliance
Ligala Tech Pte shall monitor security governance through recurring management reviews and operational checks. The Information Security Owner should report at least quarterly on risk posture, open remediation items, access review results, incident trends, training completion, and vendor issues. The Executive Director should review significant risks, approve major exceptions, and confirm that critical actions are being addressed in a timely manner. If the company handles regulated or highly sensitive client matters, review frequency may be increased to reflect risk.
Evidence of compliance shall be retained in forms that are practical for a small organization but sufficiently reliable to demonstrate due care. Expected artifacts include risk assessments, asset inventories, access approvals, access review outputs, training completion reports, incident tickets, backup test results, vulnerability reports, vendor assessments, and exception approvals. Records should be stored in a controlled repository with defined retention periods and limited edit rights. Evidence must be sufficient to show both that controls exist and that they are operating as intended.
Monitoring shall include simple metrics that support decision-making, such as percentage of personnel trained on time, number of overdue access reviews, patching timeliness for critical vulnerabilities, backup restore success rate, number of open security exceptions, and time to acknowledge incidents. Escalation shall occur when a critical control fails, when remediation deadlines are missed, when personal data may have been exposed, or when repeated noncompliance is identified. Significant matters shall be escalated to management promptly, with documented corrective action.
8. Exceptions
Exceptions to this policy are permitted only when a business need is documented and the risk is understood. Any exception request shall state the control being bypassed, the reason, the affected systems or data, compensating controls, the expected duration, and the risk owner. The Information Security Owner shall review the request, and the Executive Director shall approve exceptions that create material risk, affect client data, or last longer than a short operational window.
All exceptions shall be recorded in an exception register with an expiry date. Temporary exceptions should normally expire within 90 days unless a shorter period is required by the risk assessment or a longer period is expressly approved. Before expiration, the owner must either close the underlying issue or submit a renewal request with updated justification and mitigation status. Expired exceptions remain invalid even if remediation is incomplete.
Exception approvals shall be reviewed at least monthly by the Information Security Owner and at quarterly management review. Repeated requests for the same exception shall trigger a control redesign or corrective action plan. Exceptions related to personal data handling, client confidentiality, or administrative access must receive heightened scrutiny and cannot be treated as routine.
9. Review and Maintenance
This policy shall be reviewed at least annually and also whenever there is a major change in business operations, technology architecture, legal obligations, security incidents, or regulatory expectations. The Information Security Owner is responsible for initiating the review, coordinating input from relevant business and technical owners, and presenting recommended updates to management. The Executive Director is responsible for approving revised versions.
Policy maintenance should be practical and version-controlled. Updates should reflect changes in tooling, customer commitments, threat environment, and lessons learned from incidents or audits. Where review findings reveal that a requirement is no longer workable for a small legal technology firm, the company should revise the process or provide an approved compensating control rather than leaving the requirement unenforced. Superseded versions should be retained for reference and audit traceability.
The review process should also consider whether related documents remain aligned, including acceptable use rules, access management procedures, incident response steps, vendor review practices, data retention guidance, and secure development standards. If a change in this policy affects other procedures, the owners of those documents must update them promptly so operational guidance remains consistent. Review completion should be evidenced by meeting minutes, approval records, and published policy version history.
10. Related Standards
ISO 27001 is the primary management framework supporting this policy. This policy establishes the governance foundation that ISO 27001 expects: leadership commitment, risk-based control selection, documented responsibilities, internal review, corrective action, and continual improvement. The policy does not attempt to reproduce the full standard, but it provides the organizational rules needed to operate an information security management system in a way that can be audited and improved.
Singapore PDPA is relevant because Ligala Tech Pte may collect, use, disclose, and store personal data in the course of serving clients and operating the business. This policy supports PDPA accountability by requiring clear ownership, vendor oversight, incident reporting, retention discipline, and demonstrable safeguards for personal data. It also helps the company show that security and privacy are managed proactively rather than reactively.
This policy should also be read alongside internal procedures and operational standards that give it practical effect, including access management, incident response, device management, backup and recovery, vendor management, secure development, and records retention procedures. Together, these documents form the operational control environment that supports confidentiality, integrity, availability, and lawful handling of information across Ligala Tech Pte.
Comments
0 comments
Please sign in to leave a comment.