CivicActions Information Security Policies
CivicActions has established the following policies to safeguard the security, confidentiality, availability and integrity of CivicActions data, as well as that of our personnel, clients and client website users. All CivicActions employees and contractors are expected to accept and abide by these policies. These polices are reviewed and updated on a regular schedule. If you have questions or comments about these polices please contact your supervisor. We invite your feedback.
Acceptable Use Policy
The purpose of the Acceptable Use Policy (AUP) is to set clear expectations and requirements for how CivicActions team members use company and client IT resources. The AUP connects CivicActions security and compliance commitments to day‑to‑day expectations for a remote‑first workforce, enabling team members to do great work while protecting our clients, colleagues, and organizational reputation. This policy defines expected behaviors that complement technical safeguards on company-managed devices, personal devices used for CivicActions work, and cloud services.
Data Security and Handling Policy
The purpose of this policy is to set guidelines for all CivicActions team members for protecting company and client information (also identified as "data" in this and other documentation). This policy covers all stages of the data lifecycle: creation, access, updating, storing, sharing, archiving, and destruction.
Controlled Unclassified Information (CUI) Policy
The purpose of this policy is to establish guidelines for CivicActions employees regarding the responsible and secure handling of Controlled Unclassified Information (CUI). This policy aims to prevent the unauthorized disclosure of CUI and provides a default overview of sensitive information types and methods of special protection and handling when not covered by an Originating Agency's CUI policies.
Incident Response Policy
The purpose of this policy is to define how CivicActions prepares for, detects, responds to, and learns from security incidents across company-managed systems and services. This policy establishes an incident response (IR) lifecycle that enables effective mitigation and continuous improvement.
Physical Security Policy
The purpose of this policy is to provide guidelines for physical and environmental security measures for CivicActions environment. CivicActions is a remote-first workforce, with no physical or centrally-owned location. Therefore, this policy focuses on securing home workspaces and travel environments for team members.
Additional Policies
- Information Security Policy
- Access Control Policy
- Identification Poplicy
- Risk and Security Assessment Policy
- Maintenance Policy
- Disaster Recovery Plan
- Third-Party Management Policy
- Document and Record Control Policy
Security awareness and tools
We maintain a Security Awareness and Tools document that dives deeper into these and some additional topics, including:
- Password Management Tools
- Multi-Factor Authentication
- Phishing and Social Engineering
- Backups
- Secure Delete Files and Wiping Disks
Finally, in addition to the above policies, CivicActions Engineers -- who may have elevated privileges in specific environments -- are required to align with the Engineering Security and Compliance guidelines.