Information Security Policy
About This Document
This policy establishes the overarching information security commitments of 7 Minute Security LLC. It is the parent document for all security sub-policies and is published in our Trust Center for customer and partner review.
1. Purpose
7 Minute Security LLC ("7MinSec") is a cybersecurity services company. We help small and mid-sized organizations improve their security posture, and we hold ourselves to the same high standards we recommend to our clients. This Information Security Policy defines our core security commitments and serves as the governing document for all security-related practices within our organization.
This policy applies to all 7MinSec personnel, contractors, and systems that create, process, store, or transmit information on behalf of 7MinSec or its clients.
2. Scope
This policy applies to:
- All full-time and part-time employees of 7 Minute Security LLC
- Contractors, consultants, and third-party vendors with access to 7MinSec systems or client data
- All 7MinSec-owned or 7MinSec-managed systems, networks, and cloud services
- Any personal devices used to access 7MinSec resources (BYOD)
3. Policy Statement
7 Minute Security is committed to protecting the confidentiality, integrity, and availability of all information assets entrusted to us, our own and our clients'. We accomplish this through:
3.1 Governance and Accountability
Security is a shared responsibility at 7MinSec. The President (Brian Johnson) holds ultimate accountability for information security. All personnel are responsible for complying with this policy and immediately reporting potential security incidents.
3.2 Risk Management
We take a risk-based approach to security. We periodically assess threats and vulnerabilities, prioritize controls based on risk, and make security decisions that are proportionate and practical for our business context.
3.3 Access Control
Access to systems and data is granted on a least-privilege, need-to-know basis. All accounts require strong, unique passwords managed in an enterprise password manager. Multi-factor authentication (MFA) is required for all cloud services, remote access, and administrative accounts. Access is reviewed regularly and revoked promptly when no longer needed.
3.4 Data Protection
We classify data based on sensitivity and handle it accordingly. Client data is treated as confidential at all times. Data is encrypted in transit and at rest wherever technically feasible. We maintain an inventory of the data we hold and where it lives.
3.5 Logging, Monitoring, and Vulnerability Management
Security-relevant events on 7MinSec-managed systems are centrally collected, correlated, and retained for a minimum of one year through a self-hosted security monitoring platform. Collected events include authentication attempts, privileged actions, account and credential changes, file integrity events, and access to audit data. Alerts are reviewed and triaged by the President. The same platform provides continuous visibility into missing security updates and configuration drift across monitored systems. 7MinSec additionally performs authenticated vulnerability scanning against its own systems at least quarterly, and following any security incident.
7MinSec triages vulnerabilities identified through authenticated scanning and through continuous monitoring, and remediates them according to severity, using the CVSS base score as the severity rubric. Remediation timeframes match the patch timeframes set out in Access Management Policy Section 7.1: Critical within 7 days, High within 30 days, Medium within 60 days, and Low within 90 days, measured from the date the vulnerability is identified.
3.6 Incident Response
7MinSec maintains an Incident Response Policy that defines how we detect, respond to, and recover from security incidents. All personnel understand their obligation to report potential incidents without delay. Affected clients will be notified of confirmed incidents in a timely manner consistent with applicable law and contractual obligations.
3.7 Vendor and Third-Party Management
Before engaging vendors or tools that will access client or sensitive data, 7MinSec evaluates their security practices. We prioritize vendors who maintain recognized security certifications or who can demonstrate strong security controls.
7MinSec maintains an inventory of the service providers that store, process, or transmit 7MinSec or client data. For each provider the inventory records the service supplied, the classification of data involved, the business impact should that provider fail or be compromised, and a security contact. The inventory is reviewed at least annually, and whenever a provider is added, removed, or materially changed. This inventory is established by January 1, 2027.
All subcontractors are required to sign a 7MinSec Partnership Agreement prior to engagement. The agreement sets out confidentiality and data handling obligations, including the requirement to hold client data only on encrypted devices and to destroy sensitive client information within 60 days.
Compliance with this policy suite is established and maintained through the 7MinSec Subcontractor Security Acknowledgment form, which each subcontractor signs before engagement and re-signs annually. On that form the subcontractor attests, policy by policy and control by control, to having read and agreed to our policies and to having the required security controls active on every device used for 7MinSec or client work.
3.8 Physical Security
Work is conducted in controlled environments. Sensitive conversations and work involving client data are not conducted in public spaces. Devices are locked when unattended. Portable media is encrypted.
3.9 Professional Development and Threat Currency
7MinSec is a team of experienced security practitioners, and we maintain currency through continuous professional development rather than generic awareness training. Each practitioner pursues at least one industry certification or recertification per year (for example CISSP or OSCP), and the nature of our work keeps us engaged with emerging threats and techniques daily.
Should 7MinSec engage personnel whose role does not involve hands-on security work, those personnel will complete security awareness training on hire and at least annually thereafter, covering phishing and social engineering, data handling and classification, acceptable use, and incident reporting. No such personnel are engaged at the date of this revision.
3.10 Business Continuity
7MinSec maintains backup procedures (cloud and local) and business continuity plans to ensure we can continue serving clients during disruptions. Backups are tested periodically to confirm they are recoverable. Backup copies are protected by logical and physical controls equivalent to those applied to the primary copy, including encryption at rest, access restricted to the President, and storage in locations consistent with the classification of the data they contain.
3.11 Asset Inventory
7MinSec maintains inventories of the hardware and software it owns or operates. The hardware inventory covers endpoints, servers, virtual machines, and network devices. The software inventory covers operating systems, applications, and cloud services in use. Each record identifies the owner, the purpose of the asset, and the highest classification of data it may hold.
Both inventories are reviewed at least annually, and updated when an asset is added or retired. Assets no longer required are decommissioned, with their access paths and credentials revoked and their monitoring enrolment removed.
Both inventories are established by January 1, 2027.
3.12 Network Infrastructure Management
Network devices under 7MinSec control run vendor-supported firmware and are patched on the timeframes set out in Access Management Policy Section 7.1. Management interfaces are reachable only over encrypted protocols, HTTPS or SSH, are never exposed to the public internet, and authenticate against accounts distinct from those used for routine work. Default credentials are replaced before a device is placed in service.
Systems are placed on separate network segments according to function, and traffic between segments is denied by default at the perimeter firewall. Exceptions are explicit, individually justified, and limited to what a documented function requires. Assessment and laboratory systems therefore have no network path to systems holding client deliverables.
3.13 Penetration Testing Authorization
All penetration testing, whether performed for a client or against 7MinSec's own systems, requires written authorization from the President before testing begins. Client engagements are authorized through a signed scoping and authorization form recording the agreed scope, the testing window, the permitted techniques, and the named point of contact. Testing conducted outside an authorized scope is a violation of this policy and of the Access Management Policy.
3.14 Secure Development
Where 7MinSec writes scripts, tooling, or automation used in service delivery or in the operation of its own systems, that code holds no embedded credentials, is reviewed before it is put into use, and is stored with access restricted to authorized personnel. Third-party dependencies are kept current with security updates, and are avoided entirely where the standard library will serve.
4. Related Policies
This master policy is supported by the following sub-policies:
5. Compliance and Enforcement
Compliance with this policy is mandatory. Violations may result in disciplinary action up to and including termination of employment or contract. Suspected violations should be reported to the President. 7MinSec will cooperate fully with law enforcement investigations when appropriate.
Security Concerns or Incidents?
Contact us at: security@7minsec.com For vulnerability disclosures, please see our Vulnerability Disclosure Policy
6. Policy Review and Maintenance
This policy is reviewed at least annually or following any significant organizational change, security incident, or change in applicable law. The most current version is published in the 7MinSec Trust Center.
7. Exceptions
Requests for exceptions to this policy must be submitted in writing to the President and include a description of the business justification and proposed compensating controls. Approved exceptions are documented and time-limited.
8. Key Definitions
Policy Approval
The signed master copy of this policy is maintained in Word format and is available to customers and partners on request.
Change Log
This log records all changes made to this policy over time.
Document Feedback
To suggest changes to this policy or report an issue, contact: security@7minsec.com
Last reviewed: October 2, 2026