The framework governing the management, security and use of Western Fintrade's IT systems, infrastructure, applications and data — protecting confidentiality, integrity and availability.
1. INTRODUCTION
This Information Technology (IT) Policy of Western Fintrade Private Limited (“WFPL” or “the Company”) establishes the framework for the governance, management, security, and use of information technology systems, infrastructure, applications, and data within the organization.
The policy is designed to:
Support business objectives through secure and efficient IT systems.
Protect confidentiality, integrity, and availability of company information.
Ensure compliance with applicable regulatory and statutory requirements.
Establish clear accountability for IT governance and cyber security.
Minimize operational, cyber, and information security risks.
Enable business continuity and disaster recovery.
This policy shall apply to all employees, directors, consultants, vendors, contractors, and third-party service providers who access or manage the Company’s IT resources.
2. OBJECTIVES OF THE IT POLICY
The objectives of this policy are:
To align IT infrastructure and operations with business goals.
To provide reliable, secure, and efficient IT services.
To safeguard Company data and systems against unauthorized access, misuse, alteration, and destruction.
To establish IT governance, risk management, and internal control mechanisms.
To ensure continuity of operations during disruptions or cyber incidents.
To encourage secure adoption of emerging technologies.
To define employee responsibilities regarding IT usage and security.
To ensure compliance with regulatory, contractual, and legal obligations.
3. IT GOVERNANCE STRUCTURE
3.1 IT Governance Responsibility
The Board of Directors and Senior Management shall oversee the implementation and effectiveness of this policy.
The Company may constitute an IT Governance Committee consisting of:
Managing Director / Director
Chief Technology Officer (CTO) / IT Head
Compliance Officer
Finance Representative
Operations Representative
3.2 Responsibilities of IT Governance Committee
The Committee shall:
Approve IT strategy and security initiatives.
Review cyber security posture and risks.
Monitor IT investments and operational efficiency.
Review IT incidents and audit findings.
Ensure regulatory compliance.
Review disaster recovery and business continuity preparedness.
The committee shall meet at least quarterly or as required.
4. IT ASSET MANAGEMENT
4.1 Asset Inventory
The IT Department shall maintain an updated inventory of:
Servers
Desktops and laptops
Mobile devices
Network devices
Licensed software
Cloud subscriptions
Databases and applications
4.2 Procurement
All IT hardware and software procurement shall:
Be based on approved business requirements.
Follow procurement approval processes.
Be purchased only from authorized vendors.
Include licensing and warranty documentation.
4.3 Asset Usage
Company IT assets shall be used only for authorized business purposes.
Users shall:
Protect assigned devices.
Avoid unauthorized software installation.
Immediately report loss, theft, or compromise.
4.4 Asset Disposal
Before disposal:
Data must be securely erased.
Storage devices must be sanitized.
Disposal must be approved by management.
5. INFORMATION SECURITY POLICY
5.1 Information Security Principles
The Company shall maintain:
Confidentiality
Access to information shall be restricted to authorized users.
Integrity
Information shall be protected against unauthorized modification.
Availability
Critical systems and data shall remain available for business operations.
Accountability
User activities shall be traceable through logs and audit trails.
6. PHYSICAL SECURITY
The Company shall implement physical controls including:
Restricted access to server/network rooms.
CCTV monitoring where applicable.
UPS and power protection.
Fire safety mechanisms.
Secure storage of backup media.
7. NETWORK AND SYSTEM SECURITY
The Company shall implement:
Firewall protection
Antivirus and anti-malware solutions
Endpoint security tools
VPN for remote access
Intrusion detection and prevention systems
Secure Wi-Fi controls
Periodic patch management
Web and email filtering
Only authorized IT personnel may modify network configurations.
8. USER ACCESS MANAGEMENT
8.1 User Accounts
Every authorized user shall receive:
Unique User ID
Role-based access permissions
Secure authentication credentials
8.2 Access Approval
Access shall be granted only upon approval by the reporting manager and IT Department.
8.3 Least Privilege Principle
Users shall receive the minimum access necessary to perform their duties.
8.4 User Deactivation
Upon resignation, termination, or transfer:
User access shall be revoked immediately.
Email access shall be disabled.
Devices and credentials shall be recovered.
9. PASSWORD POLICY
9.1 Password Standards
Passwords shall:
Be minimum 8 characters long.
Include uppercase, lowercase, numeric, and special characters.
Not contain dictionary words or personal information.
Be changed every 90 days.
Not be reused.
9.2 Password Security
Users shall not:
Share passwords.
Write passwords openly.
Store passwords in unsecured files.
Multi-factor authentication (MFA) should be enabled wherever feasible.
10. EMAIL AND INTERNET USAGE POLICY
10.1 Acceptable Use
Company email and internet services are provided for official business purposes.
Users shall not:
Access illegal or inappropriate websites.
Download unauthorized software.
Send offensive or fraudulent communications.
Share confidential information without authorization.
10.2 Monitoring
The Company reserves the right to monitor:
Internet usage
Email usage
Network activity
System access logs
in accordance with applicable laws.
11. DATA PROTECTION AND BACKUP
11.1 Data Classification
Company data shall be classified as:
Public
Internal
Confidential
Restricted
11.2 Data Backup
The IT Department shall:
Perform regular backups.
Maintain secure backup copies.
Periodically test restoration processes.
Maintain offsite or cloud backups.
11.3 Data Retention
Business and regulatory data shall be retained in accordance with legal and compliance requirements.
Emergency changes shall be documented retrospectively.
16. THIRD-PARTY AND VENDOR MANAGEMENT
Third-party vendors with access to Company systems or data shall:
Sign confidentiality agreements.
Follow Company security standards.
Use authorized access methods.
Be monitored for compliance.
Vendor access shall be time-bound and revoked when no longer required.
17. IT AUDIT AND COMPLIANCE
The Company may conduct:
Internal IT audits
Vulnerability assessments
Penetration testing
Security reviews
Compliance assessments
Employees shall cooperate with audit activities.
18. REMOTE WORK AND MOBILE DEVICE SECURITY
Employees accessing Company systems remotely shall:
Use approved devices where possible.
Use secure VPN access.
Avoid public unsecured Wi-Fi.
Maintain updated antivirus software.
Ensure physical security of devices.
19. POLICY VIOLATIONS
Violation of this policy may result in:
Disciplinary action
Suspension of access privileges
Financial liability
Legal proceedings
Termination of employment or contract
20. REVIEW OF POLICY
This policy shall be reviewed at least annually or earlier if required due to:
Regulatory changes
Cyber security risks
Business changes
Technology upgrades
Audit observations
21. APPROVAL AND EFFECTIVE DATE
This Information Technology Policy is approved by the Management/Board of Western Fintrade Private Limited and shall come into effect from the date of approval.
Approved By
Designation
Signature
Date
Director / Managing Director
CTO / IT Head
Compliance Officer
ANNEXURE – EMPLOYEE ACKNOWLEDGEMENT
I hereby acknowledge that I have read and understood the Information Technology Policy of Western Fintrade Private Limited and agree to comply with the same.