Policy 37 — Information Technology and Cybersecurity

← All 75 policies · Full framework PDF · Forms · Print this policy · Governing text: English · Reviewed 6 October 2026

PHIG Policy Framework v1.2 · Policy 37 · Adopted 1 September 2026 · References: ASF Policy 32; GDPR Art. 32 (security of processing); NIS2 principles; ISO/IEC 27001 controls (reference); 2 CFR 200.303 (safeguarding information)

1. Purpose and scope

PHIG runs more than twenty websites, databases and automated services. This policy protects their confidentiality, integrity and availability. Applies to the Board, the Director, staff, consultants, volunteers, experts, partners and suppliers of PHIG and all platforms of its network.

2. Policy

  1. Individual accounts for every person; least privilege; two-factor authentication for all administrator and e-mail accounts; passwords from a manager; shared passwords prohibited; access removed within one working day of departure.
  2. Credentials, API keys and tokens are stored in a password manager, never in documents, chats or code; rotated when exposed.
  3. All sites and servers kept updated; unused plugins and accounts removed; web application firewall and malware scanning; TLS everywhere; daily automated backups stored off the production server and restore tested quarterly.
  4. Change control for production: changes tested, reversible, documented; critical third-party systems (e.g., SupplementIndex, OJS, MasterStudy) modified only by additive, reversible means.
  5. Automated content systems (desks) run only from published sources under editorial rules; logs retained.
  6. Devices used for PHIG work are encrypted and locked; public Wi-Fi only with VPN; phishing awareness training annually.
  7. Security incidents reported immediately under the Incident Reporting Policy; data breaches under the Data Protection Policy.

3. Procedures

  1. Access register; backup log; quarterly restore test; annual security review.

Responsibilities

Director; site administrators.

Review

Every two years and when donor rules change.


Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).

Operated by the Public Health Institute of Georgia (PHIG) · non-profit, ID 404407815 · 3 Betlemi Rise, Tbilisi 0105, Georgia · info@accreditation.ge · Policy Framework · Legal notice · Privacy · Accessibility · Part of the PHIG network