Accessing Sensitive Information Policy

Purpose

The purpose of the Sensitive Information Policy (The Policy) is to outline the principles and behaviours adopted by OpenSSL when accessing Sensitive Information.

OpenSSL has a responsibility to maintain security for all sensitive information under its control and to secure this information against intentional or unintentional loss of confidentiality or integrity, so as to avoid financial loss, reputational damage or adverse impacts on our customers, contractors and contributors.

Scope

The policy applies to all OpenSSL contributors, contractors and individuals who use OpenSSL information resources.

The Policy establishes who can decide on what is deemed sensitive information, who can authorise access to it, which persons or roles have access to it, what they can access, under what circumstances they can access it and how the sensitive information can be used.

Note: The Policy doesn’t cover how they physically access the sensitive information.

Principles

Definition

Sensitive Information is defined as any information classified by OpenSSL or by law as private and confidential. Sensitive Information shall not include records that by law must be made available to the general public.

The Sensitive Information Table (SIT) will include the types of information that is considered by OpenSSL to be sensitive, this list is not exhaustive and by default includes any information deemed sensitive under legislation whether it is specifically listed or not.

Deciding what is Sensitive Information

Authorisation to access sensitive information

Use of Sensitive Information

Sensitive Information can only be accessed and used for business purposes ie in the performance of a person’s role, allocated task or duties as assigned to them by OpenSSL in the course of conducting OpenSSL business activities.

Breaches of The Policy

Where any OpenSSL contractor, contributor, or individual who uses OpenSSL information resources is found in violation of The Policy they may be subject to disciplinary action, up to and including termination of any contractual arrangements.