Document content
Information Security & Incident Response Policy
Tajarat Platform
First: Purpose
This Policy aims to protect the information assets of the Tajarat Platform, ensure the confidentiality, integrity, and availability of data, and establish a unified framework for preventing, responding to, and recovering from security incidents in a manner that supports business continuity and compliance with applicable laws.
Second: Scope of Application
This Policy applies to:
All Platform employees.
Technical departments.
Merchants when using the systems.
Service providers that may access Platform systems.
Any party authorised to access Platform data or systems.
Third: Policy Objectives
This Policy aims to:
Protect data from unauthorised access.
Protect systems from cyberattacks.
Ensure continuity of Platform operations.
Reduce the impact of security incidents.
Protect the Platform's reputation and users' trust.
Support compliance with legal and regulatory requirements.
Fourth: Information Security Principles
The Platform adopts the following principles:
Confidentiality: restricting access to information to authorised persons.
Integrity: protecting data against unauthorised modification or destruction.
Availability: ensuring systems and data are available when needed.
Accountability: enabling activities and operations to be traceable.
Risk Management: applying security controls proportionate to the level of risk.
Fifth: Access Management
The Platform will:
Grant permissions in accordance with the principle of least privilege.
Review user permissions periodically.
Revoke or modify permissions when they are no longer required.
Use appropriate authentication methods, including multi-factor authentication (MFA) where available.
Prohibit sharing login credentials between users.
Sixth: Data Protection
The Platform will apply appropriate controls to protect data, including:
Encrypting sensitive data in transit and at rest where appropriate.
Creating periodic backups.
Testing the ability to restore data.
Protecting databases against unauthorised access.
Securely disposing of data when it is no longer required.
Seventh: Systems Security
Subject to technical capabilities and the nature of the risks, the Platform will:
Update systems and software periodically.
Use anti-malware software.
Monitor security logs.
Conduct periodic security testing where appropriate.
Remediate security vulnerabilities within a reasonable period proportionate to their severity.
Eighth: Reporting Security Incidents
Any person who discovers or suspects a security incident must immediately report it to the responsible function within the Platform and provide available information, such as:
The date and time of the incident.
Affected systems.
Type of incident.
Actions taken, if any.
Ninth: Incident Classification
Incidents may be classified according to the following severity levels:
Low
Incidents that do not materially affect the service or data.
Medium
Incidents that may affect certain services or users and require urgent remediation.
High
Incidents affecting core systems, sensitive data, or business continuity, requiring activation of the response plan and immediate action.
Tenth: Incident Response Procedures
When a security incident occurs, the Platform follows, as appropriate to the nature of the incident, the following stages:
Detection and reporting.
Initial assessment of the incident.
Containment and limitation of impact.
Investigation and root-cause analysis.
Restoration of systems and services.
Documentation of the incident and lessons learned.
Implementation of corrective and preventive measures.
Eleventh: Crisis Management and Business Continuity
In the event of serious incidents, the Platform may activate business continuity and disaster recovery plans to maintain essential services with the least possible interruption.
Twelfth: Responsibilities of the Parties
Management Responsibilities
Approve security policies.
Provide necessary resources.
Review incident reports.
Support awareness and training programmes.
Employee Responsibilities
Comply with security policies.
Protect login credentials.
Report any incident or suspicion.
Not install or use unauthorised software.
Service Provider Responsibilities
Comply with contractual security controls.
Cooperate when incidents occur.
Notify the Platform of any breach affecting its services or data.
Thirteenth: Awareness and Training
The Platform works to raise information-security awareness through periodic training programmes for personnel, with emphasis on common threats such as phishing, password management, and data protection.
Fourteenth: Policy Review
This Policy is reviewed at least once annually, or whenever there is a material change in systems, legal requirements, or the level of risk.
Appendix
Initial Security Incident Report Form
