Document control
- Document
- BSHQ-LGL-015
- Version
- 1.0
- Status
- Published
- Effective
- 24 July 2026
- Last reviewed
- 24 July 2026
- Owner
- Office of Legal & Governance
- Approval
- Board of Directors
- Jurisdiction
- Republic of India
- Classification
- Public
I
Security Objective
BioStackHQ is committed to protecting information assets against unauthorised access, misuse, disruption or loss.
This Policy applies to BioStack HQ information systems, devices, accounts, networks, applications, records and facilities, as well as to personnel and third parties with authorised access to them.
Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.
Security controls are selected according to risk and may include identity management, least-privilege access, encryption, secure development, backup, logging, monitoring, supplier assurance and incident response. No control eliminates all risk; suspected incidents must be reported promptly through designated channels.
II
Security Controls
Appropriate administrative, technical and organisational safeguards are implemented based on the nature and sensitivity of information.
This Policy applies to BioStack HQ information systems, devices, accounts, networks, applications, records and facilities, as well as to personnel and third parties with authorised access to them.
Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.
Security controls are selected according to risk and may include identity management, least-privilege access, encryption, secure development, backup, logging, monitoring, supplier assurance and incident response. No control eliminates all risk; suspected incidents must be reported promptly through designated channels.
III
Continuous Improvement
Security practices are reviewed periodically to address evolving technology risks and operational requirements.
This Policy applies to BioStack HQ information systems, devices, accounts, networks, applications, records and facilities, as well as to personnel and third parties with authorised access to them.
The responsible owner shall maintain proportionate procedures, records and review arrangements to give effect to this provision. Any exception requires appropriate authority, documentation and, where the risk warrants it, consultation with the Office of Legal & Governance or another competent control function.
Security controls are selected according to risk and may include identity management, least-privilege access, encryption, secure development, backup, logging, monitoring, supplier assurance and incident response. No control eliminates all risk; suspected incidents must be reported promptly through designated channels.