# Information Security Policy

| Version | Effective | Approved | Last reviewed | Owner |
|---|---|---|---|---|
| 1.4 | October 2, 2026 | October 2, 2026 | October 2, 2026 | Brian Johnson, President |

!!!info About This Document
This policy establishes the overarching information security commitments of 7 Minute Security LLC. It is the parent document for all security sub-policies and is published in our Trust Center for customer and partner review.
!!!

## 1. Purpose

7 Minute Security LLC ("7MinSec") is a cybersecurity services company. We help small and mid-sized organizations improve their security posture, and we hold ourselves to the same high standards we recommend to our clients. This Information Security Policy defines our core security commitments and serves as the governing document for all security-related practices within our organization.

This policy applies to all 7MinSec personnel, contractors, and systems that create, process, store, or transmit information on behalf of 7MinSec or its clients.

## 2. Scope

This policy applies to:

- All full-time and part-time employees of 7 Minute Security LLC
- Contractors, consultants, and third-party vendors with access to 7MinSec systems or client data
- All 7MinSec-owned or 7MinSec-managed systems, networks, and cloud services
- Any personal devices used to access 7MinSec resources (BYOD)

## 3. Policy Statement

7 Minute Security is committed to protecting the confidentiality, integrity, and availability of all information assets entrusted to us, our own and our clients'. We accomplish this through:

### 3.1 Governance and Accountability

Security is a shared responsibility at 7MinSec. The President (Brian Johnson) holds ultimate accountability for information security. All personnel are responsible for complying with this policy and immediately reporting potential security incidents.

### 3.2 Risk Management

We take a risk-based approach to security. We periodically assess threats and vulnerabilities, prioritize controls based on risk, and make security decisions that are proportionate and practical for our business context.

### 3.3 Access Control

Access to systems and data is granted on a least-privilege, need-to-know basis. All accounts require strong, unique passwords managed in an enterprise password manager. Multi-factor authentication (MFA) is required for all cloud services, remote access, and administrative accounts. Access is reviewed regularly and revoked promptly when no longer needed.

### 3.4 Data Protection

We classify data based on sensitivity and handle it accordingly. Client data is treated as confidential at all times. Data is encrypted in transit and at rest wherever technically feasible. We maintain an inventory of the data we hold and where it lives.

### 3.5 Logging, Monitoring, and Vulnerability Management

Security-relevant events on 7MinSec-managed systems are centrally collected, correlated, and retained for a minimum of one year through a self-hosted security monitoring platform. Collected events include authentication attempts, privileged actions, account and credential changes, file integrity events, and access to audit data. Alerts are reviewed and triaged by the President. The same platform provides continuous visibility into missing security updates and configuration drift across monitored systems. 7MinSec additionally performs authenticated vulnerability scanning against its own systems at least quarterly, and following any security incident.

7MinSec triages vulnerabilities identified through authenticated scanning and through continuous monitoring, and remediates them according to severity, using the CVSS base score as the severity rubric. Remediation timeframes match the patch timeframes set out in Access Management Policy Section 7.1: Critical within 7 days, High within 30 days, Medium within 60 days, and Low within 90 days, measured from the date the vulnerability is identified.

### 3.6 Incident Response

7MinSec maintains an [Incident Response Policy](https://kb.7minsec.com/trust/incident-response-policy) that defines how we detect, respond to, and recover from security incidents. All personnel understand their obligation to report potential incidents without delay. Affected clients will be notified of confirmed incidents in a timely manner consistent with applicable law and contractual obligations.

### 3.7 Vendor and Third-Party Management

Before engaging vendors or tools that will access client or sensitive data, 7MinSec evaluates their security practices. We prioritize vendors who maintain recognized security certifications or who can demonstrate strong security controls.

7MinSec maintains an inventory of the service providers that store, process, or transmit 7MinSec or client data. For each provider the inventory records the service supplied, the classification of data involved, the business impact should that provider fail or be compromised, and a security contact. The inventory is reviewed at least annually, and whenever a provider is added, removed, or materially changed. This inventory is established by January 1, 2027.

All subcontractors are required to sign a 7MinSec Partnership Agreement prior to engagement. The agreement sets out confidentiality and data handling obligations, including the requirement to hold client data only on encrypted devices and to destroy sensitive client information within 60 days.

Compliance with this policy suite is established and maintained through the 7MinSec Subcontractor Security Acknowledgment form, which each subcontractor signs before engagement and re-signs annually. On that form the subcontractor attests, policy by policy and control by control, to having read and agreed to our policies and to having the required security controls active on every device used for 7MinSec or client work.

### 3.8 Physical Security

Work is conducted in controlled environments. Sensitive conversations and work involving client data are not conducted in public spaces. Devices are locked when unattended. Portable media is encrypted.

### 3.9 Professional Development and Threat Currency

7MinSec is a team of experienced security practitioners, and we maintain currency through continuous professional development rather than generic awareness training. Each practitioner pursues at least one industry certification or recertification per year (for example CISSP or OSCP), and the nature of our work keeps us engaged with emerging threats and techniques daily.

Should 7MinSec engage personnel whose role does not involve hands-on security work, those personnel will complete security awareness training on hire and at least annually thereafter, covering phishing and social engineering, data handling and classification, acceptable use, and incident reporting. No such personnel are engaged at the date of this revision.

### 3.10 Business Continuity

7MinSec maintains backup procedures (cloud and local) and business continuity plans to ensure we can continue serving clients during disruptions. Backups are tested periodically to confirm they are recoverable. Backup copies are protected by logical and physical controls equivalent to those applied to the primary copy, including encryption at rest, access restricted to the President, and storage in locations consistent with the classification of the data they contain.

### 3.11 Asset Inventory

7MinSec maintains inventories of the hardware and software it owns or operates. The hardware inventory covers endpoints, servers, virtual machines, and network devices. The software inventory covers operating systems, applications, and cloud services in use. Each record identifies the owner, the purpose of the asset, and the highest classification of data it may hold.

Both inventories are reviewed at least annually, and updated when an asset is added or retired. Assets no longer required are decommissioned, with their access paths and credentials revoked and their monitoring enrolment removed.

Both inventories are established by January 1, 2027.

### 3.12 Network Infrastructure Management

Network devices under 7MinSec control run vendor-supported firmware and are patched on the timeframes set out in Access Management Policy Section 7.1. Management interfaces are reachable only over encrypted protocols, HTTPS or SSH, are never exposed to the public internet, and authenticate against accounts distinct from those used for routine work. Default credentials are replaced before a device is placed in service.

Systems are placed on separate network segments according to function, and traffic between segments is denied by default at the perimeter firewall. Exceptions are explicit, individually justified, and limited to what a documented function requires. Assessment and laboratory systems therefore have no network path to systems holding client deliverables.

### 3.13 Penetration Testing Authorization

All penetration testing, whether performed for a client or against 7MinSec's own systems, requires written authorization from the President before testing begins. Client engagements are authorized through a signed scoping and authorization form recording the agreed scope, the testing window, the permitted techniques, and the named point of contact. Testing conducted outside an authorized scope is a violation of this policy and of the Access Management Policy.

### 3.14 Secure Development

Where 7MinSec writes scripts, tooling, or automation used in service delivery or in the operation of its own systems, that code holds no embedded credentials, is reviewed before it is put into use, and is stored with access restricted to authorized personnel. Third-party dependencies are kept current with security updates, and are avoided entirely where the standard library will serve.

## 4. Related Policies

This master policy is supported by the following sub-policies:

| Policy | Purpose |
|---|---|
| [Privacy Management Policy](https://kb.7minsec.com/trust/privacy-management-policy) | How we collect, use, and protect personal information |
| [Access Management Policy](https://kb.7minsec.com/trust/access-management-policy) | Rules governing system and data access |
| [Incident Response Policy](https://kb.7minsec.com/trust/incident-response-policy) | How we detect, manage, and report security incidents |
| [Data Inventory & Classification Policy](https://kb.7minsec.com/trust/data-inventory-classification-policy) | How we categorize and handle data based on sensitivity |
| [Vulnerability Disclosure Policy](https://kb.7minsec.com/trust/vulnerability-disclosure) | How to report a security issue in our own systems, and what we commit to in return |

## 5. Compliance and Enforcement

Compliance with this policy is mandatory. Violations may result in disciplinary action up to and including termination of employment or contract. Suspected violations should be reported to the President. 7MinSec will cooperate fully with law enforcement investigations when appropriate.

!!!warning Security Concerns or Incidents?
Contact us at: [security@7minsec.com](mailto:security@7minsec.com)
For vulnerability disclosures, please see our [Vulnerability Disclosure Policy](https://kb.7minsec.com/trust/vulnerability-disclosure)
!!!

## 6. Policy Review and Maintenance

This policy is reviewed at least annually or following any significant organizational change, security incident, or change in applicable law. The most current version is published in the [7MinSec Trust Center](https://kb.7minsec.com/trust).

## 7. Exceptions

Requests for exceptions to this policy must be submitted in writing to the President and include a description of the business justification and proposed compensating controls. Approved exceptions are documented and time-limited.

## 8. Key Definitions

| Term | Definition |
|---|---|
| Confidentiality | Ensuring information is accessible only to those authorized to have access. |
| Integrity | Safeguarding the accuracy and completeness of information and processing methods. |
| Availability | Ensuring authorized users have access to information when needed. |
| Least Privilege | Granting only the minimum access rights required to perform a function. |
| MFA | Multi-Factor Authentication, requiring two or more verification methods to access a system. |
| Client Data | Any information belonging to, or relating to, a 7MinSec client or their customers. |

!!!info Policy Approval
The signed master copy of this policy is maintained in Word format and is available to customers and partners on request.
!!!

## Change Log

This log records all changes made to this policy over time.

| Version | Date | Author | Description of Change |
|---|---|---|---|
| 1.0 | September 1, 2026 | Brian Johnson | Initial release. |
| 1.1 | September 23, 2026 | Brian Johnson | Added Section 3.5, Logging, Monitoring, and Vulnerability Management, describing how security-relevant events on our systems are centrally collected, retained, and reviewed; later subsections renumbered accordingly. Rewrote Section 3.9 to describe how our practitioners maintain currency, through at least one industry certification or recertification each year, rather than through generic awareness training we do not run. Corrected Section 3.7 to describe the subcontractor Partnership Agreement accurately: it sets out confidentiality and data handling obligations, while agreement to this policy suite is established through the Subcontractor Security Acknowledgment. Added the Vulnerability Disclosure Policy to Section 4 and linked every related policy. |
| 1.1.1 | September 24, 2026 | Brian Johnson | Editorial pass ahead of publication: em dashes removed throughout. No requirement changed. |
| 1.2 | September 28, 2026 | Brian Johnson | Incorporated recommendations from an independent policy review against the CIS Controls. Section 3.5 now sets a one-year minimum retention for security event records and describes vulnerability triage and remediation, using the CVSS base score as the severity rubric. Section 3.7 adds a service provider inventory. Section 3.9 extends to security awareness training for any non-technical personnel engaged in future. Section 3.10 requires backup copies to carry protection equivalent to the primary copy. Four new subsections: 3.11 Asset Inventory, 3.12 Network Infrastructure Management, 3.13 Penetration Testing Authorization, and 3.14 Secure Development. The service provider inventory and both asset inventories are established by January 1, 2027. |
| 1.3 | October 2, 2026 | Brian Johnson | Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. No change to this policy. Version aligned with the rest of the suite. |
| 1.4 | October 2, 2026 | Brian Johnson | No change to this policy. Version aligned with the rest of the suite. |

!!!info Document Feedback
To suggest changes to this policy or report an issue, contact: [security@7minsec.com](mailto:security@7minsec.com)
!!!

*Last reviewed: October 2, 2026*
