Arybit Technologies

Corporate Policy

Information Security
Policy

Commitment to Secure Operations

Information Security Policy

INFORMATION SECURITY POLICY

Document Number: ISP-001 | Version: 1.0 | Effective Date: July 2026

Classification: Internal / Procurement Support

1. Policy Statement

Arybit Technologies is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by our clients, partners, employees, and stakeholders.

Information security is a fundamental component of our business operations and software development practices. We integrate security into the design, development, deployment, and support of our products and services to reduce risk, maintain trust, and support business continuity.

This policy establishes the principles and responsibilities for managing information security across Arybit Technologies. Our practices are progressively aligned with internationally recognized frameworks, including ISO/IEC 27001, the NIST Cybersecurity Framework (CSF), and the OWASP Application Security Verification Standard (ASVS).

2. Purpose & 3. Scope

This policy aims to protect company and client information, reduce cybersecurity risks, support secure development, and meet legal obligations. It applies to all employees, contractors, and third parties, and covers all information systems, applications, networks, and data managed by Arybit Technologies.

Objectives & Classification

4. Information Security Objectives

  • Protect confidential information from unauthorized access.
  • Preserve the integrity and accuracy of data.
  • Maintain the availability of critical services.
  • Secure customer environments and data.
  • Reduce cyber risk through proactive controls.
  • Strengthen resilience against security threats.

5. Information Classification

Information shall be classified according to its sensitivity to ensure appropriate levels of protection.

Public

Information approved for public release (e.g., marketing materials, public website content).

Internal

Information for internal business use (e.g., internal procedures, operational documents).

Confidential

Information requiring controlled access (e.g., client documents, contracts, source code, project information).

Restricted

Highly sensitive information requiring the highest level of protection (e.g., credentials, encryption keys, production secrets).

Responsibilities & Access Control

6. Roles and Responsibilities

Management

Responsible for approving security policies, allocating resources, managing organizational risk, and supporting continual improvement.

Employees and Contractors

Responsible for protecting company information, following security procedures, and reporting suspected incidents.

Technical Teams

Responsible for secure system architecture, secure software development, vulnerability remediation, and infrastructure hardening.

7. Access Control

Access to information systems shall follow the principle of least privilege. Controls include Role-Based Access Control (RBAC), strong authentication (MFA where supported), unique user accounts, regular access reviews, and prompt removal of unnecessary access.

8. Password and Authentication Requirements

Authentication credentials must be protected. Requirements include strong passwords or passphrases, no sharing of credentials, and prompt revocation of compromised credentials. Default passwords must be changed before production use.

Data, Development & Infrastructure Security

9. Data Protection

Arybit implements safeguards to protect data throughout its lifecycle. Controls include encryption of sensitive data in transit (TLS) and at rest (AES-256), secure backup procedures, data minimization, and secure disposal of obsolete information.

10. Secure Software Development

Security is integrated throughout the Software Development Lifecycle (SDLC). Practices include secure coding standards, code review, dependency management, vulnerability assessment, security testing, and change management.

11. Infrastructure Security

Infrastructure shall be configured using secure baseline standards. Controls include network segmentation, firewalls, secure cloud configuration, patch management, endpoint protection, logging and monitoring, and backup and recovery.

12. Cloud Security

Where cloud services are used, Arybit aims to apply secure configuration practices, restrict administrative access, monitor cloud resources, protect encryption keys, and maintain backup and recovery capabilities.

Operational Security, Governance & Compliance

13. Physical Security

Reasonable measures shall be taken to protect physical assets and equipment, including controlled access to work areas, secure storage of equipment, and secure disposal of media.

14. Incident Management

Security incidents shall be reported immediately to management. The response process includes identification, containment, investigation, eradication, recovery, and lessons learned.

15. Business Continuity

Arybit supports operational resilience through regular backups, recovery planning, and infrastructure redundancy where practical. This is addressed in a separate Business Continuity and Disaster Recovery Plan.

16. Third-Party Security & 17. Security Awareness

Third-party providers are assessed for security risks, and contracts include appropriate confidentiality and data protection obligations. Arybit promotes a culture of security awareness through ongoing education on threats like phishing and social engineering.

18. Compliance

Arybit seeks to comply with applicable contractual, legal, and regulatory obligations. The organization progressively aligns its security practices with standards like ISO/IEC 27001, NIST CSF, and OWASP ASVS.

Policy Lifecycle & Approval

19. Policy Review & 20. Enforcement

This policy shall be reviewed at least annually or following significant changes. Failure to comply may result in corrective action consistent with company procedures, contractual obligations, or applicable law.

Management Approval

Arybit Technologies recognizes that information security is essential to maintaining client trust, protecting organizational assets, and delivering secure digital solutions. Management is committed to providing the leadership, resources, and oversight necessary to continually strengthen the company's information security program.


Document Control & Approval

Document Title: Information Security Policy
Document Number: ISP-001
Version: 1.0
Effective Date: July 2026
Next Review: July 2027
Owner: Founder & Principal Consultant

Arybit Technologies Signature

Stephen Karitu Wambui

Founder & Principal Consultant, Arybit Technologies