Information Security Policy

Last Updated: July 5, 2026  |  Effective Date: July 5, 2026


1. Policy Overview

This Information Security Policy establishes the framework for protecting ShambaCare's information assets, including user data, agricultural records, and system infrastructure. This policy applies to all employees, contractors, and third parties with access to ShambaCare systems.

2. Policy Objectives

The objectives of this policy are to:

3. Scope

This policy covers:

4. Security Principles

4.1 Confidentiality

Information is accessible only to authorized individuals. We implement:

4.2 Integrity

Information is accurate and complete. We ensure:

4.3 Availability

Information and systems are available when needed. We maintain:

5. Asset Management

5.1 Asset Classification

Information assets are classified based on sensitivity:

5.2 Asset Inventory

We maintain an inventory of all information assets including:

6. Access Control

6.1 User Access Management

Access to systems is based on the principle of least privilege:

6.2 Authentication

We implement strong authentication measures:

6.3 Session Management

Session security measures include:

7. Data Protection

7.1 Encryption

We use encryption to protect sensitive data:

7.2 Data Loss Prevention

Measures to prevent unauthorized data disclosure:

7.3 Backup and Recovery

Backup procedures ensure data availability:

8. Network Security

8.1 Network Architecture

Our network is designed with security in mind:

8.2 Wireless Security

Wireless networks are secured using:

9. Application Security

9.1 Secure Development

Applications are developed following security best practices:

9.2 Web Security

Our web applications implement:

10. Physical Security

10.1 Facility Security

Physical access to our facilities is controlled:

10.2 Equipment Security

Physical security of equipment includes:

11. Cloud Security

11.1 Cloud Service Providers

We use reputable cloud service providers with:

11.2 Cloud Configuration

Cloud resources are configured securely:

12. Third-Party Risk Management

12.1 Vendor Assessment

Before engaging third parties, we assess:

12.2 Ongoing Monitoring

We continuously monitor third-party security through:

13. Incident Management

13.1 Incident Response

We maintain an incident response process as detailed in our Incident Response Plan, including:

13.2 Breach Notification

In the event of a data breach:

14. Security Awareness and Training

14.1 Training Programs

All personnel receive security training covering:

14.2 Regular Updates

Security awareness is maintained through:

15. Compliance and Monitoring

15.1 Compliance Requirements

We comply with applicable regulations including:

15.2 Monitoring and Review

Security is continuously monitored through:

16. Policy Enforcement

Violation of this policy may result in:

17. Policy Review

This policy is reviewed annually and updated as necessary to reflect:

18. Contact Information

For questions about this Information Security Policy or to report security concerns:

My Crops Diagnostics Field Visits
More
More Options
Home Dashboard Profile Support Tickets Login