governanceVersion 1SOC2ISO27001NIST800-171
Information Security Policy
The top-level commitment and principles governing how Rex Black protects information.
Information Security Policy
1. Purpose
This is the umbrella policy that establishes Rex Black's commitment to information security. Every other policy in this directory derives its authority from this one. Auditors: start here.
Rex Black collects, processes, and stores data that is material to our clients' businesses and, for regulated engagements, to the U.S. Government. We treat the security, confidentiality, integrity, and availability of that data as a first-class product requirement, not an overhead function.
2. Scope
This policy applies to:
- All Rex Black employees, officers, and directors.
- All contractors, consultants, and temporary staff acting on behalf of Rex Black.
- All third parties (vendors, service providers, subprocessors) that access, process, or store Rex Black or client data.
- All systems owned, operated, or contracted by Rex Black, including
AWS accounts, SaaS tools, development endpoints, and personal
devices used for Rex Black work (see
004-acceptable-use-policy.md).
3. Principles
Rex Black's security program is built on five principles:
- Least privilege: every person and every system gets exactly the access they need and no more.
- Defense in depth: no single control is trusted to prevent a compromise. Authentication, authorization, encryption, monitoring, and auditing each stand independently.
- Encryption by default: data is encrypted at rest and in transit with no exceptions for convenience.
- Zero silent failures: every security event is logged to a
tamper-evident audit log (see
021-logging-and-monitoring-policy.md) and observed by an alerting pipeline. - Transparency with clients: clients always know what we store about them, how long we keep it, and how to get it back or destroyed.
4. Policy statements
- Rex Black shall maintain an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022 and the SOC 2 Trust Services Criteria.
- The Security Officer (currently the CEO) is accountable for the implementation and operation of this program.
- Every control in this directory shall be reviewed at least annually or on material change to the system, whichever is sooner.
- Every employee and contractor shall read and acknowledge this policy and the Acceptable Use Policy at onboarding and annually thereafter.
- Any suspected or confirmed security event shall be reported to
security@rexblack.comwithout delay, per the Incident Response Plan (012-incident-response-plan.md). - Violation of this policy, or of any policy it incorporates, is grounds for disciplinary action up to and including termination of employment or contract, and (where applicable) civil and criminal referral.
5. Roles & responsibilities
| Role | Responsibility |
|---|---|
| CEO / Security Officer | Final accountability; approves all policies and material changes. |
| Privacy Officer | Accountable for GDPR/CCPA/privacy obligations. |
| Engineering leadership | Operates technical controls, owns secure SDLC. |
| All personnel | Comply with every policy in this directory. |
6. Enforcement & exceptions
Non-compliance is handled per the HR Security Policy
(024-hr-security-policy.md). Exceptions require a written request to
the Security Officer, are time-boxed, tracked in the Risk Register, and
approved only when a compensating control exists.
7. References
- All policies in
compliance/policies/ - All registers in
compliance/registers/ - Cybersecurity insurance: $5,000,000 aggregate, policy on file with the CEO.
8. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial approved policy. |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.