Introduction
This Information Security Policy ("Policy") establishes the information security requirements for the QUIKER SaaS innovation management platform. The Policy applies to all users of the Platform, including employees, clients, partners, and suppliers.
Objective
The objective of this Policy is to protect the confidentiality, integrity, and availability of information stored and processed on the Platform. This Policy also aims to ensure that the Platform is used in a secure and responsible manner, in alignment with Canadian federal and provincial information security standards and best practices.
Scope
This Policy applies to all systems, networks, applications, and data associated with the Platform. It applies to all users of the Platform, including employees, clients, partners, and suppliers, regardless of their location or the devices they use to access the Platform.
Definitions
Confidentiality: The property whereby information is accessible only to authorized individuals or systems.
Integrity: The property whereby information is accurate and complete and has not been altered or corrupted without authorization.
Availability: The property whereby information is accessible and usable when required by authorized individuals or systems.
Data: Any information that can be stored, processed, or transmitted through a computer system.
Platform: The QUIKER SaaS innovation and project management platform.
Information Security: The protection of information against unauthorized access, use, disclosure, alteration, or destruction.
User: Any person or system that accesses or uses the Platform.
Access Control
- Access to the Platform is governed through authentication and authorization mechanisms.
- Only authorized users are granted access to data stored on the Platform.
- Access to data is granted based on the principle of least privilege, meaning users are given only the minimum level of access required to perform their duties.
- Passwords must be strong, kept confidential, and changed on a regular basis.
- Multi-factor authentication (MFA) is required where supported and strongly recommended for all user accounts.
Data Protection
- Data is protected against unauthorized access, use, disclosure, alteration, or destruction.
- Data is encrypted in transit using industry-standard protocols (e.g., TLS).
- Data is stored in secure environments with appropriate physical and logical access controls.
- Access to data is logged and audited to support accountability and incident investigation.
- Data handling practices comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, applicable provincial privacy legislation, including Quebec's Law 25.
Network Security
- The Platform's network infrastructure is protected against unauthorized access.
- The network is continuously monitored to detect and prevent malicious activity.
- Network security software and configurations are updated on a regular basis to address emerging threats.
Application Security
- Applications are developed and tested in accordance with secure software development practices.
- Platform applications are updated regularly to address known security vulnerabilities.
- User input is validated to prevent injection attacks and other common application-layer threats, in alignment with industry standards such as the OWASP Top 10.
Security Incident Management
When a security incident occurs on the Platform, a structured support and escalation model is in place to ensure an effective response and timely resolution.
Support Levels
Level 1 – Customer Success Team: This is the first point of contact for users reporting incidents through the support portal. Level 1 representatives are responsible for receiving and logging reported incidents. They perform initial triage and attempt to resolve straightforward issues or escalate to higher support levels as required.
Level 2 – Technical Team: This level consists of technical specialists with advanced knowledge of the Platform and its underlying systems. They are responsible for resolving complex issues that could not be addressed at Level 1. Level 2 support may involve in-depth investigation, log analysis, and direct engagement with affected users.
Level 3 – Chief Technology Officer (CTO): This level addresses advanced technical issues or infrastructure-related matters. The CTO is responsible for conducting detailed root cause analyses, identifying and correcting source code defects, performing advanced configuration adjustments, and providing customized solutions for specific issues.
Escalation Process
- Escalation is the process of referring an incident to a higher level of support or to individuals with the authority and expertise to resolve complex or critical issues.
- Level 1 support is responsible for determining whether an incident requires escalation based on severity, business impact, and technical complexity.
- Critical or high-priority incidents are escalated immediately to the appropriate support level.
- All escalations are documented and tracked to ensure timely and effective resolution.
Security incidents are investigated and remediated as quickly as possible. Where a breach poses a real risk of significant harm to individuals, QUIKER will comply with mandatory breach reporting obligations under PIPEDA, including notification to the Office of the Privacy Commissioner of Canada and to affected individuals.
Information Security and Remote Work
Information Security Obligations: All contractors and remote workers are required to fully comply with QUIKER's information security policies and procedures, ensuring the protection of data and digital assets. This includes implementing appropriate cybersecurity practices in software development, maintaining source code confidentiality, and adhering to applicable data protection guidelines. Non-compliance may result in immediate contract termination.
Use of Personal Devices (BYOD – Bring Your Own Device): Contractors who use personal devices to deliver services are responsible for ensuring those devices meet all of QUIKER's security requirements. This includes implementing and maintaining a personal firewall, antivirus and anti-malware software, Endpoint Detection and Response (EDR) solutions, and Data Loss Prevention (DLP) mechanisms. These security measures must be kept up to date and fully operational at all times.
Prohibition on Unsecured Networks: The use of public or unsecured Wi-Fi networks to access QUIKER systems, code repositories, or any sensitive information is strictly prohibited. Any breach of this requirement will be considered a serious violation and may result in contract termination.
Active Personal Firewall: All devices used to deliver services must be protected by an active personal firewall, configured to block unauthorized access and monitor for suspicious network activity.
Antivirus and Anti-Malware: Devices must have robust and up-to-date antivirus and anti-malware software installed, capable of detecting and removing threats including viruses, spyware, ransomware, trojans, and other forms of malicious software. Automatic updates and regular scans are required.
Endpoint Detection and Response (EDR): Devices must be equipped with an EDR solution to continuously monitor endpoint activity and behaviour. The EDR solution must be capable of detecting, investigating, and responding to advanced threats or suspicious behaviour, and must maintain activity logs for audit purposes.
Protection of Source Code and Confidential Information: All confidential information, including source code, client data, trade secrets, and other sensitive information belonging to QUIKER, must be handled with the highest degree of confidentiality. Contractors must implement appropriate measures to ensure such information is not accessed, shared, or disclosed without authorization. Any security incident involving confidential information must be reported to QUIKER immediately.
Activity Monitoring and Access: QUIKER reserves the right to monitor activity on its systems and tools related to software development and service delivery, to ensure compliance with this Policy. Contractors agree to permit such monitoring, including oversight of version control tools and code repositories, and must provide activity logs upon request.
Responsibility for BYOD Security: Contractors are fully responsible for the physical and digital security of personal devices used in the delivery of services. This includes protection against theft, loss, and damage, as well as maintaining up-to-date software. In the event of a device being compromised, the contractor must take immediate steps to mitigate risk and notify QUIKER of the incident.
Security Audits and Compliance: QUIKER may conduct periodic audits to verify that contractors' BYOD devices comply with the security requirements set out in this Policy. Contractors must fully cooperate with such audits, providing access and information as needed to confirm compliance.
Security Training and Updates: Contractors are required to participate in mandatory cybersecurity training as requested by QUIKER, and to stay current with best practices in secure software development. Contractors must also ensure that all BYOD devices are updated with the latest security patches and software fixes on an ongoing basis.
Software Maintenance and Technical Support: Contractors are responsible for ensuring that all devices and software used for work are maintained in compliance with QUIKER's security standards. In the event of a technical failure that compromises the security of services, the contractor must seek technical support immediately and notify QUIKER of any disruption that may affect data integrity or service continuity.
Minimum Device Requirements
Data Loss Prevention (DLP): Contractors must implement DLP mechanisms to protect QUIKER's sensitive data, ensuring that confidential information cannot be copied, shared, or transmitted without authorization. DLP solutions must monitor and block unauthorized transfers of information.
Regular Software and Operating System Updates: All devices used for work must be kept current with the latest security patches, both for the operating system and for all software used in development. Automatic updates must be enabled, and any identified vulnerabilities must be remediated promptly.
Access Control: Devices must employ secure authentication methods, including strong passwords, multi-factor authentication (MFA), or biometric verification. Device access must be restricted to authorized personnel only, and any unauthorized access attempts must be blocked.
Secure Development Environment: The development environment must be isolated from personal activities and protected against external interference. Development tools such as IDEs and code repositories (e.g., Git) must be configured in accordance with security best practices, including the use of SSH and multi-factor authentication.
Physical Device Security: Contractors are responsible for the physical security of their devices, ensuring they are not accessed by unauthorized third parties or left unattended in unsecured locations. In the event of loss or theft, the contractor must notify QUIKER immediately and take all necessary steps to protect the data.
Security Awareness and Training
All users of the Platform are required to complete information security awareness training. Training content must be reviewed and updated on a regular basis to reflect the current threat landscape and evolving best practices.
Monitoring and Audit
The security posture of the Platform is monitored and audited on a regular basis. The results of monitoring and audit activities are used to continuously improve the Platform's information security controls and practices.
Compliance
This Policy is designed to comply with the following laws, regulations, and standards:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
- Applicable provincial privacy legislation, including Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25)
- Canada's Anti-Spam Legislation (CASL), where applicable
- ISO/IEC 27000 series Information Security Standards
- Brazil's Lei Geral de Proteção de Dados (LGPD), applicable to operations in Brazil
- Brazil's Marco Civil da Internet, applicable to operations in Brazil
Review and Update
This Policy must be reviewed and updated at least annually, or whenever there are significant changes to the Platform or to the broader security environment.
Enforcement
Non-compliance with this Policy may result in disciplinary action, up to and including termination of employment or contract, and may also give rise to civil or criminal liability under applicable Canadian law.
