# Eon Collective Policies

## 1. Governance and Leadership

### Core Policies
- [Data Governance Policy](/content/policies/data-governance/index.html)
- [Corporate Data Security Policy](/content/corporate-data-security/index.html)

### Purpose:
- Establish roles, responsibilities, and accountability for secure data handling.
- Drive strategic alignment across operational, security, and compliance domains.

### Key Actors:
- Executive Leadership, Operations Director, IT Manager

### Dependencies:
- A foundation for Incident Response and IT Risk Management.

## 2. Risk Management

### Core Policies
- [IT Assessment and Risk Management Policy](/content/policies/it-assessment-and-risk-management/index.html)
- [Data End of Life Policy](/content/policies/data-end-of-life/index.html)

### Purpose:
- Conduct continuous risk assessments to identify, mitigate, and monitor risks.
- Safeguard against risks associated with obsolete data and systems.

### Key Actors:
- IT Manager, Operations Director

### Dependencies:
- Informs Disaster Recovery and Backup strategies.

## 3. Operational Security

### Core Policies
- [Firewall Policy](/content/policies/firewall/index.html)
- [Corporate Data Security Policy](/content/corporate-data-security/index.html)
- [Malicious Code Anti-Virus Policy](/content/policies/malicious-code-anti-virus/index.html)

### Purpose:
- Protect systems with robust firewall configurations and anti-virus measures.
- Prevent unauthorized access or malicious code infiltration.

### Key Actors:
- IT Manager, Chief Technology Officer (CTO)

### Dependencies:
- Integrates with Incident Response and Backup Policies.

## 4. Access Management

### Core Policies
- [Physical Access Policy](/content/policies/physical-access/index.html)
- [Remote Access Policy](/content/policies/remote-access/index.html)

### Purpose:
- Ensure secure physical and remote access.
- Implement least-privilege principles and multi-factor authentication.

### Key Actors:
- IT Manager, Operations Director

### Dependencies:
- Linked to Security Monitoring and Encryption protocols.

## 5. Incident Response

### Core Policies
- [Incident Response Policy](/content/policies/incident-response/index.html)
- [Problem Management Policy](/content/policies/problem-management/index.html)

### Purpose:
- Provide a structured response to security incidents, minimizing impact.
- Coordinate with the Security Incident Response Team (SIRT).
- Identify and address root causes to prevent recurring incidents.

### Key Actors:
- Operations Director, SIRT members, IT Manager

### Dependencies:
- Backed by IT Assessment, Risk Management, and Backup Policies.

## 6. Backup and Disaster Recovery

### Core Policies
- [Backup and Recovery Policy](/content/policies/backup-and-recovery/index.html)
- [Disaster Recovery and Business Continuity Plan](/content/policies/disaster-recovery-and-business-continuity-plan/index.html)

### Purpose:
- Ensure continuity of operations and restoration of critical systems.
- Maintain secure and accessible off-site backups.

### Key Actors:
- IT Manager, Operations Director

### Dependencies:
- Relies on Risk Assessment and Firewall protections.

## 7. Encryption and Acceptable Use

### Core Policies
- [Acceptable Encryption Policy](/content/policies/acceptable-encryption/index.html)
- [Acceptable Use Policy](/content/policies/acceptable-use/index.html)

### Purpose:
- Enforce encryption standards to secure data at rest and in transit.
- Define acceptable use of EON systems to mitigate misuse and abuse.

### Key Actors:
- IT Manager, CTO

### Dependencies:
- Supports Corporate Data Security and Risk Management.

## 8. Change Management

### Core Policies
- [Change Management Policy](/content/policies/change-management/index.html)
- [Security Change Management Policy](/content/policies/security-change-management/index.html)

### Purpose:
- Implement structured processes for managing changes to systems and processes.
- Minimize risks during implementation and ensure accountability.
- Address security-specific change requirements and controls.

### Key Actors:
- Change Control Board (CCB), Operations Director, IT Manager

### Dependencies:
- Closely aligned with Backup and Incident Response for seamless transitions.

## 9. Training and Compliance

### Core Policies
- [Security Awareness Training Standards](/content/policies/security-awareness-training-standards/index.html)
- [Employee Computer and Application Usage Policy](/content/policies/employee-computer-and-application-usage/index.html)

### Purpose:
- Establish mandatory security training requirements for all staff to ensure understanding and compliance with security policies.
- Define acceptable use standards for company computing resources and applications.
- Create accountability measures to track and enforce compliance across the organization.

### Key Actors:
- HR Manager, IT Manager, Operations Director

### Dependencies:
- Supports all security policies through education and awareness.

## 10. Legal and Regulatory Compliance

### Core Policies
- [Privacy Policy](/content/policies/privacy-policy/index.html)
- Terms and Conditions
- Data Protection/GDPR Compliance
- Service Level Agreements (SLAs)

### Purpose:
- Define legal obligations to customers and partners.
- Establish data handling and privacy standards.
- Set service delivery expectations.
- Ensure regulatory compliance.

### Key Actors:
- Executive Leadership, Operations Director, Legal Counsel.

### Dependencies:
- Informs all data handling and incident response procedures.
