Information Security Policy
Insight Media Labs maintains a written Information Security policy that defines employee's responsibilities and acceptable use of information system resources. The organization requires signed acknowledgment from users before granting system access, and reviews policies periodically.
Security policies address general compliance standards like account and data security, plus specialized standards for internal applications.
Asset Management
The organization manages both customer/end-user assets and corporate assets under defined security procedures. Authorized personnel who handle these assets are required to comply with the procedures and guidelines defined by Insight Media Labs security policies.
Personnel Security
Employees must conduct themselves consistent with company guidelines regarding confidentiality and ethics. New hires sign confidentiality agreements and acknowledge the code of conduct policy, which emphasizes lawful, ethical business practices. Security training is provided during orientation, and all staff must complete code of conduct training.
Operational Security
Supplier and Vendor Relationships
The company partners with suppliers sharing similar values around lawfulness and ethics. Vendors handling customer data face confidentiality and security obligations, with periodic audits to ensure data protection.
Antivirus and Malware Protection
Centrally managed antivirus and malicious code protection retrieve updated signatures automatically. Anti-virus tools are configured to run scans, virus detection, real-time file write activity and signature file updates. Coverage extends to remote and laptop users.
System Backups
Backup standards and guidelines and associated procedures for performing backup and restoration of data are maintained in scheduled, timely manner. Controls protect both onsite and offsite backed-up data, with periodic recovery testing.
Network Security
Infrastructure servers operate behind high-availability firewalls monitoring for threats. By default, all access is denied and only explicitly allowed ports and protocols are allowed based on business need.
The company maintains separate development and production environments. Automated tools provide near-real-time threat analysis, while next-generation firewalls monitor outbound communications for unauthorized activities.
Vulnerability Management
Security assessments identify vulnerabilities and evaluate patch management effectiveness. Each vulnerability undergoes review for applicability, risk ranking, and assignment for remediation.
Secure Network Connections
HTTPS encryption is configured for customer web application access. Encryption levels negotiate between SSL or TLS based on browser capability, ensuring data in transit remains secure.
Access Controls
Role Based Access
Role-based access controls restrict system access. Access controls to sensitive data in our databases, systems, and environments are set on a need-to-know / least privilege necessary basis. Procedures address employee termination scenarios.
Authentication and Authorization
Authorized users receive unique account IDs. Password policies enforce complexity requirements to prevent unauthorized access.
Software Development Lifecycle
The organization follows a defined methodology for developing secure software that is designed to increase the resiliency and trustworthiness of our products. Security testing occurs throughout development, with quality assurance involved at each phase. Standard security practices include vulnerability testing, regression testing, penetration testing, and product security assessments.
Business Continuity and Disaster Recovery
A disaster recovery program operates across all data centers to minimize service interruption. For business critical applications, application data is replicated to multiple systems within the data center and, in some cases, replicated to secondary or backup data centers that are geographically dispersed. High-speed connections support swift failover.
Data Protection
The organization applies a common set of personal data management principles to customer data using appropriate physical, technical, and organizational security measures. Additional care addresses sensitive personal data while respecting local laws. Processing remains compatible with collection purposes per the privacy policy, with reasonable steps taken against loss, misuse, or unauthorized access.