Technical-Security-Documentation

Information Security Policy (ISP)

1. Purpose

This policy establishes a framework for protecting the confidentiality, integrity, and availability of Information and Operational Technology assets. It ensures the safe delivery of energy services while protecting personnel, the environment, and the company’s reputation.

2. Scope

This policy applies to:

3. Core Security Principles

| Principle | Oil & Gas Context | | :— | :— | | Safety First | Cybersecurity measures must never compromise Personnel or Process Safety (QHSE). | | Defense in Depth | Multiple layers of security controls across both physical and digital perimeters. | | Asset Integrity | Ensuring that sensor data and valve controls are accurate and tamper-proof. | | Resiliency | The ability to maintain or quickly restore production during a security event. |

4. Network Segmentation (The Purdue Model)

The organization shall maintain strict logical and physical separation between the Corporate Office Network and the Field Production Network.

5. Access Management

6. Physical Security

7. Vulnerability & Patch Management

8. Incident Response and Recovery

The organization shall maintain a specific Cybersecurity Incident Response Plan (CIRP) integrated with the existing Emergency Response Plan (ERP).

9. Compliance and Standards

This policy aligns with: