Do you have a Corporate Security Policy?

CellStream, Inc. Corporate Security Statement and Policy

Purpose

CellStream, Inc. is committed to protecting the security and confidentiality of information entrusted to us by our customers, students, employees, business partners, and service providers.

As a telecommunications consulting and training organization, we recognize that our work may provide us with access to customer information, network information, technical documentation, packet captures, system configurations, proprietary information, credentials, and other sensitive data.

CellStream maintains administrative, technical, and operational safeguards designed to protect this information and the systems used to process it.

Security is an ongoing responsibility. Our security practices are reviewed and updated as technologies, threats, business requirements, and accepted cybersecurity practices evolve.

Scope

This policy applies to all CellStream employees, contractors, consultants, and other individuals who are provided access to CellStream systems or sensitive information.

It applies to information that is stored, processed, transmitted, or otherwise handled using systems owned, operated, leased, or authorized by CellStream.

This includes, as applicable:

  • Computers and workstations
  • Laptops and mobile devices
  • Servers and cloud-based systems
  • Networking equipment
  • Wireless systems
  • Email and collaboration systems
  • Websites and web applications
  • Storage and backup systems
  • Software and applications
  • Removable storage
  • Telecommunications systems
  • Third-party services authorized for CellStream business

Our Employees

Every person with access to CellStream information or information systems shares responsibility for protecting those resources.

Employees and authorized users are expected to:

  • Follow CellStream security and privacy requirements.
  • Protect passwords, authentication credentials, and security tokens.
  • Use company information only for legitimate business purposes.
  • Protect customer, student, employee, and business-partner information.
  • Use only authorized systems and services for CellStream business.
  • Promptly report suspected security incidents, phishing attempts, lost devices, unauthorized access, or other security concerns.
  • Avoid circumventing security controls.
  • Complete appropriate security-awareness training.

Access to information and systems is provided according to business need and may be modified or removed when an individual’s responsibilities change.

Access is removed when employment, contractual relationships, or other authorized access ends.

Our Documents and Information

CellStream creates, receives, and maintains information as part of normal business operations.

Some of this information may contain customer data, student information, internal business information, network information, financial information, credentials, intellectual property, or other information that should not be publicly disclosed.

Access to sensitive information is restricted on a need-to-know and least-privilege basis.

Sensitive information must not be copied, transmitted, published, uploaded, or shared with unauthorized individuals or services.

This requirement applies regardless of whether the information exists as a document, email message, database record, screenshot, photograph, network diagram, configuration file, log file, packet capture, or other format.

Customer Network and Technical Information

Because CellStream provides telecommunications consulting and technical training services, we may occasionally receive or generate information concerning customer networks and systems.

Examples may include:

  • Network diagrams
  • IP addressing information
  • Device configurations
  • Routing information
  • Wireless-network information
  • Network-management information
  • Troubleshooting logs
  • Packet captures
  • Protocol traces
  • Performance information
  • Technical documentation

We treat customer network information as confidential unless the customer has explicitly authorized its disclosure.

Customer information obtained during consulting, troubleshooting, or training engagements will not knowingly be published or reused in public materials without authorization or appropriate sanitization.

Packet Capture and Protocol Analysis Data

Packet captures can contain considerably more information than may be immediately apparent.

A packet capture may reveal addresses, hostnames, DNS requests, protocol exchanges, application information, network architecture, device information, and potentially sensitive user or customer data.

CellStream therefore treats customer-provided packet captures and protocol traces as potentially sensitive information.

Packet captures used for public demonstrations, training materials, articles, exercises, or downloadable resources must be specifically created for that purpose, appropriately sanitized, or used with authorization.

Our Networks

CellStream uses network-security controls appropriate to the systems and services being protected.

Our security practices include, as appropriate:

  • Firewall protection
  • Access controls
  • Secure network configuration
  • Segmentation where warranted
  • Secure administrative access
  • Restriction of unnecessary services
  • Monitoring and logging
  • Encryption
  • Software and firmware maintenance
  • Protection of wireless networks

Network services and systems that are not required for legitimate business purposes should be disabled or removed.

Default vendor credentials and other insecure default configurations must be changed before systems are placed into service.

Administrative interfaces should not be unnecessarily exposed to public networks.

Specific information concerning CellStream’s internal network architecture, firewall rules, security products, or defensive configurations is considered confidential and is not published as part of this policy.

Authentication and Access Control

Access to CellStream systems must be appropriately authenticated.

Individual user accounts are preferred over shared accounts so that access can be associated with a specific authorized user.

CellStream uses the principles of least privilege and need-to-know access when granting permissions.

Passwords and passphrases must be:

  • Sufficiently long and difficult to guess
  • Unique to the account or service
  • Protected from unauthorized disclosure
  • Changed when compromise is known or reasonably suspected

CellStream does not rely solely on arbitrary periodic password changes as a primary security control.

Multi-factor authentication is used where appropriate and is particularly important for systems involving administrative access, remote access, email, cloud services, sensitive information, and other higher-risk resources.

Password managers may be used to securely generate and maintain strong, unique credentials.

Authentication credentials must not be shared with unauthorized individuals.

Our Computers and Devices

CellStream computers and devices used to conduct company business must be appropriately protected.

Depending upon the system and its function, protections may include:

  • Current operating-system and application security updates
  • Endpoint security and malware protection
  • Host-based firewall protection
  • Device encryption
  • Screen locking
  • Strong authentication
  • Multi-factor authentication
  • Secure backups
  • Restricted administrative privileges
  • Secure configuration
  • Removal or disabling of unnecessary software and services

Devices that are no longer supported by their manufacturer or software provider must be evaluated before continued use for CellStream business.

Lost, stolen, or potentially compromised devices must be reported promptly.

Software Updates and Vulnerability Management

Operating systems, applications, network devices, plugins, firmware, and other software must be maintained at appropriate security levels.

Security updates are evaluated and installed according to the risk associated with the vulnerability, the affected system, and operational requirements.

Known critical security vulnerabilities should be addressed as quickly as reasonably practical.

Systems and applications that are no longer supported should be upgraded, replaced, isolated, or otherwise managed to reduce associated risk.

Encryption

Sensitive information transmitted across public or untrusted networks must be protected using appropriate encryption whenever practical.

CellStream uses secure protocols and encrypted communications for systems and services where confidential information or authentication credentials may be exposed.

Encryption may also be used to protect stored information and computing devices when appropriate.

Obsolete or known-insecure protocols and encryption methods should not be used when reasonable secure alternatives are available.

Email, Phishing, and Social Engineering

Email and electronic communications remain significant sources of security risk.

CellStream personnel are expected to exercise appropriate caution when handling:

  • Unexpected attachments
  • Links in unsolicited messages
  • Requests for passwords or credentials
  • Unexpected multi-factor authentication requests
  • Financial or payment instructions
  • Requests to change account information
  • Messages creating unusual urgency
  • Messages requesting confidential information

Suspicious requests should be independently verified before sensitive information, credentials, or funds are provided.

Remote Access

Remote access to CellStream systems must be appropriately secured.

Remote access should use encrypted connections, strong authentication, and multi-factor authentication where available and appropriate.

Access should be limited to authorized individuals and to those resources necessary to perform legitimate business functions.

Remote-access permissions should be removed when no longer required.

Artificial Intelligence and Online Services

Artificial intelligence systems, cloud applications, online analysis tools, and other Internet-based services can provide significant business benefits, but information submitted to such services may leave CellStream’s direct control.

Employees and authorized users must therefore consider the sensitivity of information before submitting it to an AI system or other third-party online service.

Customer confidential information, personally identifiable information, credentials, proprietary configurations, unsanitized packet captures, private network diagrams, or other restricted information must not be submitted to an unauthorized external service.

Sensitive material should be sanitized, anonymized, or otherwise protected before being submitted to an authorized service when appropriate.

Work-approved services and accounts should be used when business information requires additional privacy, contractual, or administrative protections.

Our Data

CellStream protects sensitive information from unauthorized access, disclosure, modification, destruction, or misuse.

We seek to collect and retain only the information reasonably necessary for legitimate business, contractual, legal, training, or operational purposes.

Access controls are used to restrict sensitive information to authorized individuals.

Information that is no longer required should be securely deleted, destroyed, anonymized, or otherwise disposed of when appropriate.

Physical documents containing sensitive information should be securely stored and destroyed when no longer needed.

Electronic storage devices containing sensitive information should be securely erased or destroyed before disposal or reuse when appropriate.

Payment Information

CellStream seeks to minimize its direct storage and handling of payment-card information.

Where payment-card information is processed, appropriate payment-processing services and security practices are used.

Systems or processes that directly handle cardholder data must comply with applicable current Payment Card Industry Data Security Standard (PCI DSS) requirements.

CellStream will not publish or unnecessarily retain complete payment-card information.

Backups and Recovery

Important CellStream business information and system configurations should be backed up according to their operational importance.

Backups should be protected against unauthorized access and, where appropriate, against alteration or deletion by the same systems they are intended to protect.

Backup and recovery capabilities are periodically reviewed to help ensure that critical information can be recovered following hardware failure, software failure, accidental deletion, cybersecurity incidents, or other disruptive events.

Our Service Providers

CellStream uses third-party providers for various business, communications, web, financial, cloud, and technology services.

Third-party access to sensitive information or systems is limited to legitimate business requirements.

Security and privacy considerations are included when evaluating services that will store, process, or have access to sensitive CellStream or customer information.

Third-party access should be removed when it is no longer required.

CellStream expects service providers handling sensitive information on our behalf to use reasonable security safeguards appropriate to the information and services involved.

Security Incidents

CellStream maintains procedures for responding to suspected or confirmed security incidents.

Security incidents may include:

  • Unauthorized system access
  • Compromised accounts
  • Malware
  • Phishing
  • Lost or stolen equipment
  • Accidental disclosure of sensitive information
  • Unauthorized changes to systems
  • Suspicious network activity
  • Compromise of a third-party service
  • Other events that may affect the confidentiality, integrity, or availability of CellStream information or systems

Suspected security incidents should be reported promptly.

Appropriate actions may include containment, investigation, preservation of relevant information, credential changes, system restoration, customer or partner communication, and other corrective measures based upon the nature of the event.

Security incidents are also reviewed for lessons that may improve future security practices.

Security Awareness and Training

CellStream recognizes that technical security controls alone are not sufficient.

Employees and authorized users receive security guidance and awareness information appropriate to their responsibilities.

Security awareness may include:

  • Password and authentication practices
  • Phishing and social engineering
  • Protection of customer information
  • Secure handling of documents
  • Remote-work security
  • Safe Internet use
  • Mobile-device security
  • AI and cloud-service usage
  • Reporting of security incidents

Security expectations are reinforced as technologies and threats change.

Physical Security

Reasonable measures are taken to protect CellStream equipment, documents, and information from unauthorized physical access.

Computers, mobile devices, storage media, and sensitive documents should not be left unnecessarily exposed or unattended in locations where unauthorized individuals could gain access.

Special care should be taken when traveling, working remotely, teaching at customer locations, or conducting field activities.

Compliance With Customer Requirements

When CellStream performs work for customers with specific contractual, confidentiality, data-handling, or security requirements, those requirements become part of our responsibilities for that engagement.

Customer information will be handled according to applicable contractual commitments in addition to CellStream’s internal security requirements.

Review of This Policy

Cybersecurity is an evolving process.

CellStream management reviews this security policy periodically and updates it as necessary to address changes in:

  • Technology
  • Business operations
  • Threats and vulnerabilities
  • Customer requirements
  • Applicable laws and regulations
  • Accepted cybersecurity practices

Employees and other authorized users are expected to comply with the current version of this policy.

Our Commitment

CellStream’s security objective is straightforward:

Protect the information entrusted to us, limit access to those who legitimately require it, use reasonable and current security practices, and respond quickly when something appears to be wrong.

Security is not a product that can simply be installed.

It is an ongoing responsibility that is part of how CellStream conducts business.

Leave a Comment

Scroll to Top