Scope
This policy covers every information security role at botBrains and applies to both team members and any contractor or supplier acting on our behalf.Named accountability
Liam van der Viven (CTO) is the CISO and holds top-level accountability for information security at botBrains. The CISO approves every policy, owns the ISMS, decides on risk treatment and exceptions, and is the point of contact for security and privacy matters. Following the named-individual principle, accountability rests with this single named person and isn’t diffused across an unnamed committee. Ben Meyer-Meisel is the co-founder and shares operational security duties, primarily for engineering and infrastructure. Either co-founder may carry out routine security operations; only the CISO holds the named accountability described above.Roles
Both co-founders hold most of these roles jointly. Where a single person both performs and approves an action, botBrains relies on compensating controls described in the Secure Development Policy and the Access Control Policy, and records the resulting segregation-of-duties limitation in the risk register.
Responsibilities of all personnel
- Read, understand, and follow this and every other ISMS policy.
- Protect the confidentiality and integrity of any information classified Internal, Confidential, or Customer Data. See the Data Classification Policy.
- Report actual or suspected security events through the Incident Management Policy.
- Complete security awareness activities and acknowledge policies when onboarding and after material changes. See the Human Resource Security Policy.