Onboarding and Termination

Redacted version of Joiners and leavers policy

Purpose and Scope

This Policy defines the key responsibilities and processes associated with resource changes within the Force – new starters & leavers to the organisation. These responsibilities are key to safeguarding Nanonets' physical and data assets and ensuring the security of those assets at all times.

Background

In order to minimize the risk of information loss or exposure (from both inside and outside the organisation), the organisation is reliant on the principle of least privilege. Account creation and permission levels are restricted to only the resources absolutely needed to perform each person’s job duties. When a user’s role within the organisation changes, those accounts and permission levels are changed/revoked to fit the new role and disabled when the user leaves the organisation altogether.

Policy

a. During onboarding:

HR services shall:

1. Ensure that the appropriate pre-employment checks and screening are undertaken. Where access to more sensitive information or information systems is required, further vetting processes against standards shall be required;

2. Ensure that Employees commence employment with the appropriate paperwork and checks are completed and received;

3. Ensure that Employees security risks are effectively managed through robust security processes to ensure actions are in accordance with Nanonets' legal obligations;

4. Provide a legally binding contract of employment. The contract of employment shall explicitly state all applicable roles, benefits and responsibilities bestowed on the employee by Nanonets. From an information security perspective, it shall include the expected Employee Code of Conduct, confidentiality clauses, required compliance to legal requirements, policies and procedures, and the consequences of noncompliance and subsequent information breaches;

5. Ensure that prior to recruitment the security responsibilities are outlined to the candidates. This includes embedding these responsibilities appropriately into each job description.

Managers shall:

a. During offboarding:

HR services shall:

Managers shall:

Last updated