Purpose
ASCO recognises the importance of cybersecurity in protecting the organisation's data, reputation, and stakeholder trust. This policy establishes guidelines for securing digital systems, networks, and information.
Scope
This policy applies to all ASCO digital assets, including websites, email systems, databases, cloud services, social media accounts, and any devices used to access organisational systems.
Access Controls
Access to ASCO's digital systems is granted on a need-to-know basis. Strong passwords are required for all accounts. Multi-factor authentication is enabled where available. Access is revoked promptly when no longer required.
Data Protection
ASCO protects personal data and sensitive organisational information in accordance with the Protection of Personal Information Act (POPIA) and applicable data protection laws. Data is encrypted in transit and at rest where feasible.
POPIA Compliance
ASCO complies with the Protection of Personal Information Act (POPIA) in all aspects of data collection, processing, storage, and disposal. Personal information is collected only for specified, lawful purposes and is not retained longer than necessary. Data subjects are informed of the purpose of collection and their rights under POPIA, including the right to access, correct, and request deletion of their personal information. ASCO maintains appropriate technical and organisational measures to prevent loss, damage, unauthorised destruction, and unlawful access to personal information.
Data Protection Procedures
ASCO implements the following data protection procedures: data minimisation — only information necessary for a given purpose is collected; access controls — only authorised personnel may access personal data; data retention schedules — personal information is destroyed or de-identified when no longer required; breach notification — data breaches affecting personal information are reported to the Information Regulator and affected data subjects as required by POPIA; and regular reviews of data processing activities to ensure ongoing compliance.
Incident Response
In the event of a cybersecurity incident, affected systems must be isolated immediately and the Executive Director notified. ASCO will assess the scope of the breach, contain the incident, and take steps to prevent recurrence.
Regular Review
ASCO reviews its cybersecurity practices at least annually and updates this policy as needed to address emerging threats and changes in technology.