Policy
Cybersecurity Policy
How ChocoJava protects information systems, guest data, employee data, and investor data.
Framework
Key principles
GovernanceCybersecurity is overseen by an accountable executive and reported to the Board.
Access ControlsAccess to systems is granted on a least-privilege basis and reviewed regularly.
Data ProtectionSensitive data is protected in transit and at rest using industry-standard techniques.
Incident ResponseIncidents are triaged, contained, investigated, and reported to affected parties per applicable law.
Vendor RiskThird-party vendors handling sensitive data are subject to security due diligence.
AwarenessEmployees receive periodic training on secure operating practices.
Contact
Questions about this policy
Direct questions to [email protected].