Skip to content
Last updated: Sep 25, 2026

Human Resources Security & Awareness Policy ​

Governs security across the employment lifecycle — before, during, and after engagement — and the security-awareness programme. Subordinate to the Information Security Policy.

Policy ownerCOO (Payeli) — People & Operations
Applies toAll Finaisse personnel and contractors
Effective2026-08-27 (v0.1 draft)
Review cadenceAnnual + on major organisational change
ClassificationInternal-confidential
SOC 2 / ISOCC1.4, CC2.2 · ISO 27001 A.6.1–6.6

1. Purpose ​

Ensure that personnel understand and uphold their security responsibilities, that access follows the employment lifecycle, and that the human layer — the most common attack vector for a finance platform with email ingestion — is actively strengthened. Closes the gap in Domain 20 — People & Awareness (F-33).

2. Before engagement ​

  • 🎯 Target — background/reference checks proportionate to the role and data access, where legally permissible.
  • All personnel and contractors acknowledge the Acceptable Use Policy and sign a confidentiality/NDA agreement before receiving access.

3. During engagement ​

  • Security awareness training — 🎯 Target — at onboarding and at least annually, covering phishing/BEC (given the finance domain and email ingestion), data handling, and incident reporting (owner: Security & Infrastructure Owner).
  • 🎯 Target — periodic phishing simulation, BEC-focused.
  • Personnel follow all subordinate policies and use least-privilege access granted per the Access Control Policy.
  • A clear channel exists to report a security concern without fear of reprisal; suspected incidents follow the Incident Response Policy.

4. Onboarding & offboarding ​

  • Access is provisioned to role on documented business need at onboarding.
  • 🎯 Target — a formal joiner/mover/leaver workflow: on leaving or role change, access is revoked and secrets the person could access are rotated within a defined SLA (Access Control Policy §3.3). Today, personnel access is limited and managed directly by the owner; this becomes a documented checklist as the team grows.

4.1 Device change for continuing personnel ​

A change of endpoint — hardware failure, upgrade, or return of a device by someone who remains with Finaisse — is neither a joiner nor a leaver event, and so is easily missed by a lifecycle process framed only around those two. It nonetheless changes which endpoints hold access, and is therefore in scope here.

On any device change, the retired device's Zero Trust enrolment is revoked and the replacement is enrolled before Finaisse work resumes, with credentials held locally on the retired device rotated. The steps are set out in Mobile Device & Remote Working Policy §4.2; personnel access itself (GitHub organisation membership, portal policies) is unchanged by a device swap and is not revoked.

5. Accountability ​

  • Security responsibilities are a condition of engagement. Violations may result in access revocation and disciplinary action, up to termination, per the Information Security Policy §8.

6. Review ​

Reviewed annually and on major organisational change (notably team growth, which converts several 🎯 targets above into operating controls).

Revision history ​

VersionDateAuthorChange
0.12026-08-27Security & Infrastructure OwnerInitial draft
0.22026-09-03Security & Infrastructure Owner§4.1 added — device change for continuing personnel is in lifecycle scope, distinct from joiner/leaver

Finaisse Internal — Confidential. Access-restricted; not for external distribution.