HLD Group
Information security policy
Enterprise information security requirements for HLD Group personnel, systems, and service delivery.
Last updated: 24 July 2026
Version 3.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This Information Security Policy is the top-level statement of how HLD Group protects the confidentiality, integrity, and availability of the information entrusted to it. It sits above the specific security, data, operational, and governance policies and establishes the management system that binds them together.
2. Scope
This policy applies to all information assets owned, leased, or processed by HLD Group, to all personnel, contractors, and third parties, and to all systems, facilities, and environments used for company business, including customer environments under our management.
3. Policy statement and objectives
HLD Group maintains an information security management system, overseen by the CISO and aligned to ISO/IEC 27001 and the SOC 2 Trust Services Criteria, that protects information in support of our business objectives, legal and contractual obligations, and the trust of our customers. Security is risk-driven, proportionate, and continually improved.
- Protect the confidentiality, integrity, and availability of information
- Meet legal, regulatory, and contractual obligations
- Manage information security risk to within our defined appetite
- Enable the business to deliver securely, not obstruct it
- Continually improve based on measurement, audit, and incidents
4. Security governance
The information security programme is governed under the Compliance and Governance Policy, with executive oversight, a named CISO, documented roles, and a security steering function. Security objectives and performance are reviewed by leadership.
5. Organisation of information security
- Documented roles and responsibilities for security
- Segregation of duties for financial and production changes
- Contact with authorities and special interest groups, including the ACSC and relevant ISACs
- Security requirements embedded in project and change methodology
6. Control domains
This policy is implemented through a set of supporting policies, each maintained to standalone depth:
- People — Personnel Security, Awareness and Training, Remote Work, Mobile Device
- Access and identity — Access Control, Password and Authentication, Privileged Access
- Data — Data Classification, Data Retention, Records Management, Data Processing, Encryption
- Operations — Change Management, Backup and Recovery, Business Continuity, Disaster Recovery, Logging and Monitoring
- Technology — Network Security, Cloud Security, Secure Development, Vulnerability and Patch Management, Email Security
- Assurance and response — Security Assessment, Incident Response, Breach Notification, Risk Management
- Specialised — CUI Handling, HIPAA Safeguards, AI Governance
7. Incident management and continuity
Security incidents are handled under the Incident Response Policy, with breach notification under the Breach Notification Policy, and continuity assured under the Business Continuity, Backup and Recovery, and Disaster Recovery Policies. Recovery objectives are defined for critical services.
8. Compliance and assurance
Legal, regulatory, and contractual requirements are identified and mapped to controls in the compliance register. Compliance is validated through internal review, independent audit, and certification, with findings tracked to closure.
9. Framework alignment
- ISO/IEC 27001:2022 (information security management system) and Annex A controls
- SOC 2 Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy)
- NIST Cybersecurity Framework and NIST SP 800-53 Rev. 5
- Sector and jurisdictional requirements integrated through the compliance register
10. Roles, exceptions, and review
The CISO owns this policy under executive oversight; all personnel are responsible for compliance. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.
For contractual attestations or audit packs, contact security@hldgroup.org.