By Policy for processing sensitive data as an employee of Exos, it is required that each Exos Employee to complete the following prior to accessing sensitive material:
- Background verification checks on all candidates for Exos employees and contractors should be carried out in accordance with relevant laws, regulations, and ethics, and proportional to the business requirements, level of access, and the perceived risk.
- Exos employees, contractors, and third-party users must attest to the terms and conditions of their employment contract and comply with acceptable use.
- Exos employees must sign a confidentiality or non-disclosure agreement (NDA) prior to access to confidential information and processing
- Understand their responsibilities for the classification of information and management of Exos assets associated with information, information processing facilities, and information services handled by an employee or
- Know their responsibilities for information handling received from third
- Reviewing and agreeing with the security policies of
- Exos employees will go through an onboarding process that familiarizes them with the environments, systems, security requirements, and procedures Exos has in
- Exos employees will also have ongoing security awareness training that is
- Employee offboarding will include reiterating any duties and responsibilities still valid after terminations, verifying that access to any Exos systems has been removed, as well as ensuring that all Exos-owned assets are returned, where required.
- Exos and its employees will take reasonable measures to ensure no corporate data is transmitted via any unsecured digital communications such as unencrypted email or posted on social media outlets.
Exos requires all workforce members to comply with the following acceptable use requirements and procedures in order to ensure our remote workforce and those who serve our clients directly can manage optimal cyber hygiene.
- Exos employees may not leave computing devices (including laptops and smart devices) used for business purposes, including Exos-provided devices, unattended in public.
- Device encryption must be enabled for all mobile devices accessing Exos data, such as whole-disk encryption for all laptops.
- All email messages containing sensitive or confidential data will be
- Employees may not post any sensitive or confidential data in public forums or chat rooms. If a posting is needed to obtain technical support, data must be sanitized to remove any sensitive or confidential information prior to
- All data storage devices and media must be managed according to the Exos Data Classification specifications (seen above) and Data Handling procedures.