Human Resources Security & Awareness Policy
Governs security across the employment lifecycle — before, during, and after engagement — and the security-awareness programme. Subordinate to the Information Security Policy.
| Policy owner | COO (Payeli) — People & Operations |
| Applies to | All Finaisse personnel and contractors |
| Effective | 2026-08-27 (v0.1 draft) |
| Review cadence | Annual + on major organisational change |
| Classification | Internal-confidential |
| SOC 2 / ISO | CC1.4, CC2.2 · ISO 27001 A.6.1–6.6 |
1. Purpose
Ensure that personnel understand and uphold their security responsibilities, that access follows the employment lifecycle, and that the human layer — the most common attack vector for a finance platform with email ingestion — is actively strengthened. Closes the gap in Domain 20 — People & Awareness (F-33).
2. Before engagement
- 🎯 Target — background/reference checks proportionate to the role and data access, where legally permissible.
- All personnel and contractors acknowledge the Acceptable Use Policy and sign a confidentiality/NDA agreement before receiving access.
3. During engagement
- Security awareness training — 🎯 Target — at onboarding and at least annually, covering phishing/BEC (given the finance domain and email ingestion), data handling, and incident reporting (owner: Security & Infrastructure Owner).
- 🎯 Target — periodic phishing simulation, BEC-focused.
- Personnel follow all subordinate policies and use least-privilege access granted per the Access Control Policy.
- A clear channel exists to report a security concern without fear of reprisal; suspected incidents follow the Incident Response Policy.
4. Onboarding & offboarding
- Access is provisioned to role on documented business need at onboarding.
- 🎯 Target — a formal joiner/mover/leaver workflow: on leaving or role change, access is revoked and secrets the person could access are rotated within a defined SLA (Access Control Policy §3.3). Today, personnel access is limited and managed directly by the owner; this becomes a documented checklist as the team grows.
4.1 Device change for continuing personnel
A change of endpoint — hardware failure, upgrade, or return of a device by someone who remains with Finaisse — is neither a joiner nor a leaver event, and so is easily missed by a lifecycle process framed only around those two. It nonetheless changes which endpoints hold access, and is therefore in scope here.
On any device change, the retired device's Zero Trust enrolment is revoked and the replacement is enrolled before Finaisse work resumes, with credentials held locally on the retired device rotated. The steps are set out in Mobile Device & Remote Working Policy §4.2; personnel access itself (GitHub organisation membership, portal policies) is unchanged by a device swap and is not revoked.
5. Accountability
- Security responsibilities are a condition of engagement. Violations may result in access revocation and disciplinary action, up to termination, per the Information Security Policy §8.
6. Review
Reviewed annually and on major organisational change (notably team growth, which converts several 🎯 targets above into operating controls).
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Security & Infrastructure Owner | Initial draft |
| 0.2 | 2026-09-03 | Security & Infrastructure Owner | §4.1 added — device change for continuing personnel is in lifecycle scope, distinct from joiner/leaver |