PHIG Policy Framework v1.2 · Policy 37 · Adopted 1 September 2026 · References: ASF Policy 32; GDPR Art. 32 (security of processing); NIS2 principles; ISO/IEC 27001 controls (reference); 2 CFR 200.303 (safeguarding information)
1. Purpose and scope
PHIG runs more than twenty websites, databases and automated services. This policy protects their confidentiality, integrity and availability. Applies to the Board, the Director, staff, consultants, volunteers, experts, partners and suppliers of PHIG and all platforms of its network.
2. Policy
- Individual accounts for every person; least privilege; two-factor authentication for all administrator and e-mail accounts; passwords from a manager; shared passwords prohibited; access removed within one working day of departure.
- Credentials, API keys and tokens are stored in a password manager, never in documents, chats or code; rotated when exposed.
- All sites and servers kept updated; unused plugins and accounts removed; web application firewall and malware scanning; TLS everywhere; daily automated backups stored off the production server and restore tested quarterly.
- Change control for production: changes tested, reversible, documented; critical third-party systems (e.g., SupplementIndex, OJS, MasterStudy) modified only by additive, reversible means.
- Automated content systems (desks) run only from published sources under editorial rules; logs retained.
- Devices used for PHIG work are encrypted and locked; public Wi-Fi only with VPN; phishing awareness training annually.
- Security incidents reported immediately under the Incident Reporting Policy; data breaches under the Data Protection Policy.
3. Procedures
- Access register; backup log; quarterly restore test; annual security review.
Responsibilities
Director; site administrators.
Review
Every two years and when donor rules change.
Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).