Information Security Policy
Last Updated: July 5, 2026 | Effective Date: July 5, 2026
1. Policy Overview
This Information Security Policy establishes the framework for protecting ShambaCare's information assets, including user data, agricultural records, and system infrastructure. This policy applies to all employees, contractors, and third parties with access to ShambaCare systems.
2. Policy Objectives
The objectives of this policy are to:
- Protect the confidentiality, integrity, and availability of information assets
- Ensure compliance with the Kenya Data Protection Act, 2019 and other regulations
- Establish clear security roles and responsibilities
- Implement appropriate technical and organizational measures
- Provide a framework for continuous security improvement
3. Scope
This policy covers:
- All electronic and physical information assets
- User personal data and agricultural records
- ShambaCare's IT infrastructure and systems
- Cloud services and third-party processors
- Employees, contractors, and third-party partners
4. Security Principles
4.1 Confidentiality
Information is accessible only to authorized individuals. We implement:
- Role-based access controls (RBAC)
- Authentication and authorization mechanisms
- Encryption of sensitive data at rest and in transit
- Secure communication channels
4.2 Integrity
Information is accurate and complete. We ensure:
- Data validation and verification processes
- Change management for system modifications
- Audit trails for critical operations
- Regular data integrity checks
4.3 Availability
Information and systems are available when needed. We maintain:
- High-availability infrastructure
- Backup and disaster recovery procedures
- Redundant systems where critical
- Incident response capabilities
5. Asset Management
5.1 Asset Classification
Information assets are classified based on sensitivity:
- Confidential: User personal data, financial records, diagnostic results
- Internal: Business operations, internal communications
- Public: Marketing materials, website content
5.2 Asset Inventory
We maintain an inventory of all information assets including:
- Hardware and software systems
- Data repositories and databases
- Cloud services and third-party integrations
- Mobile devices and storage media
6. Access Control
6.1 User Access Management
Access to systems is based on the principle of least privilege:
- Users are granted minimum necessary access for their role
- Access is reviewed and approved by managers
- Access is revoked when employment or contract ends
- Temporary access is time-limited
6.2 Authentication
We implement strong authentication measures:
- Unique user IDs for all system access
- Strong password policies (minimum 12 characters, complexity requirements)
- Multi-factor authentication (MFA) for administrative access
- Regular password expiration and rotation
6.3 Session Management
Session security measures include:
- Automatic session timeout after inactivity
- Secure session tokens
- Termination of sessions on logout
- Monitoring for suspicious session activity
7. Data Protection
7.1 Encryption
We use encryption to protect sensitive data:
- At Rest: AES-256 encryption for databases and storage
- In Transit: TLS 1.3 for all network communications
- Key Management: Secure key generation, storage, and rotation
7.2 Data Loss Prevention
Measures to prevent unauthorized data disclosure:
- Data classification and labeling
- Content filtering and monitoring
- Restrictions on data export and transfer
- Secure disposal of data and equipment
7.3 Backup and Recovery
Backup procedures ensure data availability:
- Daily automated backups of critical systems
- Geographically distributed backup storage
- Regular backup integrity verification
- Documented recovery procedures
- Annual disaster recovery testing
8. Network Security
8.1 Network Architecture
Our network is designed with security in mind:
- Network segmentation to isolate critical systems
- Firewalls to control traffic between segments
- Intrusion detection and prevention systems (IDS/IPS)
- Secure remote access (VPN)
8.2 Wireless Security
Wireless networks are secured using:
- WPA3 encryption for all wireless access points
- Separate guest networks with restricted access
- Regular security configuration reviews
9. Application Security
9.1 Secure Development
Applications are developed following security best practices:
- Secure coding guidelines and training
- Code reviews for security vulnerabilities
- Static and dynamic application security testing (SAST/DAST)
- Regular dependency updates and vulnerability scanning
9.2 Web Security
Our web applications implement:
- HTTPS for all connections
- Input validation and output encoding
- Protection against OWASP Top 10 vulnerabilities
- Content Security Policy (CSP) headers
- Regular penetration testing
10. Physical Security
10.1 Facility Security
Physical access to our facilities is controlled:
- Access control systems (keycards, biometrics)
- Visitor registration and escort procedures
- Security cameras and monitoring
- Secure storage for sensitive documents
10.2 Equipment Security
Physical security of equipment includes:
- Device encryption (laptops, mobile devices)
- Cable locks for portable equipment
- Inventory tracking of all hardware
- Secure disposal of old equipment
11. Cloud Security
11.1 Cloud Service Providers
We use reputable cloud service providers with:
- Industry-standard security certifications (ISO 27001, SOC 2)
- Data residency options for Kenyan data
- Clear data processing agreements
- Regular security assessments
11.2 Cloud Configuration
Cloud resources are configured securely:
- Identity and access management (IAM) policies
- Network security groups and firewalls
- Encryption of cloud storage
- Regular security configuration reviews
12. Third-Party Risk Management
12.1 Vendor Assessment
Before engaging third parties, we assess:
- Security policies and practices
- Compliance with relevant regulations
- Data protection capabilities
- Incident response procedures
12.2 Ongoing Monitoring
We continuously monitor third-party security through:
- Regular security reviews
- Contractual security requirements
- Incident notification obligations
- Right to audit provisions
13. Incident Management
13.1 Incident Response
We maintain an incident response process as detailed in our Incident Response Plan, including:
- Incident detection and reporting procedures
- Classification and severity assessment
- Containment, eradication, and recovery steps
- Post-incident analysis and improvement
13.2 Breach Notification
In the event of a data breach:
- Affected users are notified within 72 hours
- Regulatory authorities are notified as required
- Clear communication about the breach and remediation
14. Security Awareness and Training
14.1 Training Programs
All personnel receive security training covering:
- Security policies and procedures
- Phishing and social engineering awareness
- Data handling best practices
- Incident reporting procedures
14.2 Regular Updates
Security awareness is maintained through:
- Annual mandatory security training
- Monthly security communications
- Phishing simulation exercises
- Updates on emerging threats
15. Compliance and Monitoring
15.1 Compliance Requirements
We comply with applicable regulations including:
- Kenya Data Protection Act, 2019
- Kenya Computer Misuse and Cybercrimes Act, 2018
- GDPR (for EU data subjects)
- Industry-specific agricultural regulations
15.2 Monitoring and Review
Security is continuously monitored through:
- Security information and event management (SIEM)
- Regular vulnerability assessments
- Annual security audits
- Policy review and updates
16. Policy Enforcement
Violation of this policy may result in:
- Disciplinary action for employees
- Contract termination for contractors
- Legal action for malicious activities
- Criminal prosecution for illegal activities
17. Policy Review
This policy is reviewed annually and updated as necessary to reflect:
- Changes in technology and threat landscape
- Updates in regulatory requirements
- Lessons learned from security incidents
- Changes in business operations
18. Contact Information
For questions about this Information Security Policy or to report security concerns:
- Security Team: shambacare@proton.me
- Address: Taveta Sub-County, Taita Taveta County - Kenya