1. Introduction

Purpose

This policy is a guide for Corintech employees, and interested third parties, to establish guidelines and best practices for the protection of confidential, sensitive or proprietary information from unauthorized access, use, disclosure, alteration or destruction. Information is an asset and must be protected appropriately.

Definition

Information Security is the processes designed to protect data by mitigating risks. It includes digital data, physical data and cyber security.

A Cyber Vulnerability is a weakness in an IT system that can be exploited by an attacker.

Scope

This policy applies to all Corintech employees regardless of employment agreement, position, or location. It also applies to any contractors and third-party service providers who have access to Company information and information systems, and any third parties reporting a vulnerability.

Corintech shall comply with all relevant laws, regulations, and industry standards regarding information security where we do business.

2. Responsibility

The Company will ensure that all employees will be trained on their responsibilities and obligations regarding information security and that the relevant procedures are followed if a vulnerability is reported in accordance with this policy.

For the purposes of this policy, and some regional regulations, Corintech is a Data Controller (DC) and will ensure that there is an appointed Data Protection Officer (DPO) where applicable. This position should be adequately resourced, report to Directors, and not carry out any other tasks that could result in a conflict of interest. They are also the point of contact for any regional regulatory authority and individuals whose data is processed by the Company.

Management

Directors, Managers and Supervisors are tasked with implementing and overseeing policies and procedures that reduce the risk of data breaches and ensuring that there is sufficient planning to respond to incidents. Appropriate training should be provided to employees, depending on their roles and tasks.

The CIMSense IT Managers and regional IT support staff, are responsible for keeping software and devices updated with the latest security patches and updates, protecting networks from unauthorized access to systems and overseeing IT training.

Employees

All employees are required to:

  • Adhere to all Corintech policies and any additional procedures and guidelines within their Company employee handbook, or other relevant Company materials, relating to data handling, email and internet usage, device management and social networks.
  • Protect passwords and access credentials – create strong passwords, never share them, don’t use the same password across multiple accounts and if you access Company emails and/or documents on your personal mobile device make sure this device is sufficiently protected. As a minimum, this means making sure the device is protected with a password, pin, or biometric ID security.
  • Report security incidents – be vigilant for suspicious activity (phishing emails, malware infections, suspicious logins) and report any incidents to a CIMSense IT Manager or a regional IT support staff member immediately. Incidents can also be reported via email to support@cimsense.com.
  • Protect physical documents – physical documents containing sensitive information should be properly secured and securely disposed of when no longer needed.
  • Avoid high risk actions – use caution when accessing public WiFi networks by ensuring your device is protected with updated anti-virus software. Don’t download software from untrusted sources that could compromise the security of the Company’s information. Think carefully before using removable media (e.g. USB drive) and remember to remove it from the host device.

3. Access Control

Corintech will provide all employees and other users with the information they need to carry out their responsibilities effectively and efficiently. Access to information and information systems shall be granted following the principles of least privilege and need-to-know.

At a Group level, CIMSense has several ways of protecting Information that may be provided to them via its companies, including Corintech. These include but are not limited to the CIMSense Access Control Policy.

Physical Access Control

User accounts should be created with strong passwords, and access should be revoked upon termination of employment or contract.

Users should not share their login credentials with others or allow others to use their accounts. No generic or group IDs will normally be permitted.

Information systems shall have authentication and authorization mechanisms in place to ensure that only authorized users can access information including multi-factor authentication.

Remote users shall be subject to authorization by a CIMSense IT Manager or a regional IT support staff member. No uncontrolled external access shall be permitted to any network device or network system.

Digital Access Control

User accounts should be created with strong passwords, and access should be revoked upon termination of
employment or contract.

Users should not share their login credentials with others or allow others to use their accounts. No generic
or group IDs will normally be permitted.

Information systems shall have authentication and authorization mechanisms in place to ensure that only
authorized users can access information including multi-factor authentication.

Remote users shall be subject to authorization by a CIMSense IT Manager or a regional IT support staff
member. No uncontrolled external access shall be permitted to any network device of network system.

4. Data Protection

All Territories

Corintech has a separate Privacy Policy which details how the Company respects the privacy of individuals and is committed to protecting personal data.

Confidential, sensitive, or proprietary information shall be protected from unauthorized access, use, disclosure, alteration, or destruction. Corintech data usually includes names or numbers. Examples include employee details, product names, prices, costs, tax codes, registration marks, codes and dates.

Information shall be classified based on its sensitivity and appropriate controls implemented to protect it.

Encryption shall be used to protect sensitive information during transmission and storage.

Digital information shall be regularly backed up to prevent data loss in case of hardware failure or disaster. Third parties hosting digital data, e.g. Cloud Services, will be required to meet strict requirements and certification.

European Union and United Kingdom

The EU’s General Data Protection Regulations (GDPR), and the UK’s Data Protection Act 2018 that implements GDPR regulations protect personal data belonging to EU citizens or residents. As above, the Privacy Policy details how the Company handles and protects personal data.

In accordance with GDPR regulations, data subjects will be informed of any personal data breach within 72 hours of the incident.

5. Monitoring

Information systems shall be monitored for unauthorized access, use, or disclosure. Logs shall be regularly reviewed and analyzed to detect and respond to security incidents.

Vulnerability risk assessments and penetration testing shall be periodically performed to identify and mitigate potential security risks.

6. Security Incidents

Incidents can have a huge impact on a company in terms of cost, productivity and reputation. All security incidents should be reported to a CIMSense IT Manager, and regional IT support staff, immediately so that the incident can be contained and remediated as quickly as possible.

Incident response plans should be formulated and in place for all types of security breaches at a local and Group level. At Group level, CIMSense has an Incident Response Policy and an Incident Response Plan. All plans should be periodically tested to ensure their effectiveness.

7. Product Security Telecommunications Infrastructure (PSTI)

The Product Security Telecommunications Infrastructure Act 2022 is the UK’s Cyber Security regulation for consumer Internet of Thing products. Manufacturers of consumer connectable products (or ‘smart’ products) must comply with specific obligations to ensure they and their products meet minimum security requirements.

Passwords

Corintech’s products, and their associated software, will never provide a default password. Users will be
asked to create their own unique passwords which must meet a set of criteria.

Vulnerability Disclosure

Corintech has a procedure that allows responsible disclosure of security vulnerabilities by external parties. The aim of this procedure is to address and resolve the vulnerability before it could potentially be exploited maliciously. Guidelines for reporting are detailed below in section 8 of this policy.

Security Updates

Corintech extends the life of its products by providing free software upgrades. This includes important security updates. Corintech aims to provide security updates to all relevant ‘smart’ products, and their associated software, for a minimum of three years from the date of the product’s release. Corintech will fulfil this timeline whenever it is within their control, as manufacturer and primary code authors, to do so, but may be compromised if updated security related code is required from a component supplier.

8. Cyber Vulnerability Disclosure

Corintech is committed to designing, developing and maintaining products and services in accordance with secure development practices and does not intentionally release products with known unmitigated security vulnerabilities that present an unacceptable risk to customers and users of our products and services.

Corintech maintains a structured vulnerability management process to receive, assess, prioritise, remediate and disclose security vulnerabilities affecting its products and services throughout their supported lifecycle.

Reporting Guidelines

If you believe you have found a security vulnerability, please submit your report to security@corintech.com and include the following details:

  • A brief description of the type of security vulnerability
  • Specify the website/page/product/software/service and the associated version numbers, configurations and other relevant details where the vulnerability has been identified.
  • Detail the steps required to reproduce the vulnerability. These should be a benign, non-destructive, proof of concept. This helps to ensure that the report can be triaged quickly and accurately. It also reduces the likelihood of duplicate reports, or malicious exploitation of some vulnerabilities, such as sub-domain takeovers.

Expectations

The Company will acknowledge receipt of a vulnerability report within 5 working days and aim to complete an initial triage assessment within 10 working days and to keep reporters informed of progress.

Priority for remediation is assessed by looking at the impact, severity and exploit complexity. Vulnerability reports might take some time to triage or address. Reporters may enquire on the status of their disclosure but should avoid doing so more than once every 14 days. This allows our teams to focus on the remediation.

Corintech will notify reporters when the vulnerability is remediated, and may invite reporters to confirm the solution covers the vulnerability adequately.

Following remediation, Corintech will coordinate public disclosure with the reporter wherever possible. While collaborative disclosure is preferred, Corintech may in some cases make an independent disclosure to fulfil regulatory, legal, contractual, or customer commitments.

Where required by applicable legislation, including the EU Cyber Resilience Act, Corintech may notify relevant authorities, customers and stakeholders of actively exploited vulnerabilities, severe incidents or available mitigations in accordance with applicable reporting requirements.

Responsible Disclosure

Corintech welcomes vulnerability reports submitted in good faith and will not take legal action against individuals or organisations who test the security of our products and associated software and services, if they do so ethically as per this policy and they do NOT:

 

  • Break any applicable laws or regulations, act in any manner that is inconsistent with the law, or cause Corintech or partner organisations to be in breach of any legal obligations.
  • Access unnecessary, excessive or significant amounts of data.
  • Modify or delete data in Corintech’s systems, products or services.
  • Use high-intensity invasive or destructive scanning tools to find vulnerabilities.
  • Attempt or report any form of denial of service, e.g. overwhelming a service with a high volume of requests.
  • Disrupt the Company’s services or systems.
  • Submit reports detailing non-exploitable vulnerabilities, or reports indicating that the services do not fully align with “best practice”, for example, missing security headers.
  • Submit reports detailing TLS configuration weaknesses, for example “weak” cipher suite support or the presence of TLS1.0 support.
  • Communicate any vulnerabilities or associated details other than by means described in the published security.txt.
  • Social engineer, ‘phish’ or physically attack the Company’s staff or infrastructure.
  • Demand financial compensation in order to disclose any vulnerabilities.

 

Any individual or organisation researching or testing a vulnerability MUST:

  • Always comply with data protection rules and must not violate the privacy, safety or security of the Company’s users, staff, contractors, services or systems. You must not, for example, share, redistribute or fail to properly secure data retrieved from the systems or services.
  • Securely delete all data retrieved during your research as soon as it is no longer required or within 1 month of the vulnerability being resolved, whichever occurs first (or as otherwise required by data protection law).

 

The above applies to Corintech own-branded or group-branded products and services. It does not apply to products/services developed by Corintech for our customers.

No monetary rewards are offered for vulnerability disclosures.

9. Export Control

The export of certain goods and technology is regulated by the Export Control Organisation (ECO). The ECO controls these assets to promote global security and to protect national security. Corintech requires at least one Director, one Manager, one Operator and the Compliance Officer to be trained on Export Control, and only staff who have completed this training will be granted access to restricted files.

10. Non-Compliance & Disciplinary Actions

Violations of this policy could result in serious consequences for Corintech and cause personal distress to individuals. Any breach will be thoroughly investigated. Offending employees may face disciplinary action as outlined in the Company employee handbook. Offending third parties may be reported to law enforcement agencies or regulatory authorities.

Version 4.0

Corintech Logo

Request a Callback

Fill out the form below, and we will be in touch shortly.