# Baltika Freight Systems OÜ — Information Security Policy

**Document ID:** POL-BLTK-2026-02 · **Version:** 2.1 · **Owner:** Head of Engineering · **Approved by:** CEO, 14 January 2026 · **Review cycle:** annual

> Baltika Freight Systems OÜ is a fictional company. This document was authored as the subject fixture for a published worked example and contains deliberate control gaps.

## 1. Purpose and scope

This policy defines the information security requirements for Baltika Freight Systems OÜ ("Baltika"), a provider of freight-forwarding and customs-clearance SaaS to logistics operators in the Baltic region. It applies to all employees, contractors, production systems, and corporate IT, including the Baltika TMS platform and its supporting infrastructure.

## 2. Governance and responsibilities

The CEO holds ultimate accountability for information security. Day-to-day responsibility is delegated to the Head of Engineering, who acts as security officer, reports on security matters to management quarterly, and maintains this policy. Management reviews and re-approves this policy annually or after any material incident.

## 3. Risk management

Baltika performs an information security risk assessment once per year, covering the TMS platform and corporate IT. Identified risks are recorded in the engineering backlog and prioritised alongside feature work. Risk acceptance above severity "high" requires CEO sign-off.

## 4. Access control

Access to production systems and customer data follows the principle of least privilege and is role-based. Access rights are reviewed quarterly, and revoked within one business day when employment ends. Passwords must be at least 12 characters and unique per system; a company password manager is provided to all staff. Shared accounts are prohibited in production.

## 5. Cryptography

All data in transit between customers and the Baltika TMS platform is encrypted using TLS 1.2 or higher. Data at rest is encrypted where the underlying hosting platform makes this technically feasible. Encryption keys for customer-facing services are managed by the hosting provider.

## 6. Incident management

Suspected security incidents must be reported to the security officer immediately. The security officer classifies incidents within 4 hours using a three-level severity ladder (minor / major / critical) and leads the response. For incidents affecting customer data or service availability, affected customers are notified within 72 hours of classification. A post-incident review is held within two weeks for all major and critical incidents, and lessons learned are recorded.

## 7. Business continuity and backups

Production databases are backed up daily to a separate availability zone, with backups retained for 35 days. A restore test is performed once per year. In a regional outage, the platform is restored from backup in the secondary zone; engineering maintains a written recovery runbook.

## 8. Vulnerability and patch management

Operating systems and third-party dependencies of the TMS platform are patched on a monthly cycle. Vulnerabilities rated critical by the vendor are patched within 72 hours of a fix becoming available. Dependency scanning runs in the CI pipeline and blocks builds on known-critical findings.

## 9. Security awareness and training

All staff complete security awareness training at onboarding and annually thereafter, covering phishing, password hygiene, data handling, and incident reporting. Engineering staff additionally receive secure-development training every two years.

## 10. Human resources security

Employment contracts include confidentiality obligations. References are checked for all hires with production access. On termination, access is revoked per Section 4 and company equipment is returned before the final working day.

## 11. Physical security

Baltika's office is access-controlled by keycard. Production infrastructure is hosted with a cloud provider certified to recognised security standards; Baltika holds no server hardware of its own.

## 12. Policy compliance and exceptions

Deviations from this policy require a written, time-limited exception approved by the security officer and recorded in the exception register. Wilful violation of this policy is grounds for disciplinary action.
