Skip to main content

governanceVersion 1SOC2ISO27001NIST800-171

Information Security Policy

The top-level commitment and principles governing how Rex Black protects information.

Download PDFSHA-256 3d7d9b8cfef74f63…

Information Security Policy

1. Purpose

This is the umbrella policy that establishes Rex Black's commitment to information security. Every other policy in this directory derives its authority from this one. Auditors: start here.

Rex Black collects, processes, and stores data that is material to our clients' businesses and, for regulated engagements, to the U.S. Government. We treat the security, confidentiality, integrity, and availability of that data as a first-class product requirement, not an overhead function.

2. Scope

This policy applies to:

  • All Rex Black employees, officers, and directors.
  • All contractors, consultants, and temporary staff acting on behalf of Rex Black.
  • All third parties (vendors, service providers, subprocessors) that access, process, or store Rex Black or client data.
  • All systems owned, operated, or contracted by Rex Black, including AWS accounts, SaaS tools, development endpoints, and personal devices used for Rex Black work (see 004-acceptable-use-policy.md).

3. Principles

Rex Black's security program is built on five principles:

  1. Least privilege: every person and every system gets exactly the access they need and no more.
  2. Defense in depth: no single control is trusted to prevent a compromise. Authentication, authorization, encryption, monitoring, and auditing each stand independently.
  3. Encryption by default: data is encrypted at rest and in transit with no exceptions for convenience.
  4. Zero silent failures: every security event is logged to a tamper-evident audit log (see 021-logging-and-monitoring-policy.md) and observed by an alerting pipeline.
  5. Transparency with clients: clients always know what we store about them, how long we keep it, and how to get it back or destroyed.

4. Policy statements

  1. Rex Black shall maintain an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022 and the SOC 2 Trust Services Criteria.
  2. The Security Officer (currently the CEO) is accountable for the implementation and operation of this program.
  3. Every control in this directory shall be reviewed at least annually or on material change to the system, whichever is sooner.
  4. Every employee and contractor shall read and acknowledge this policy and the Acceptable Use Policy at onboarding and annually thereafter.
  5. Any suspected or confirmed security event shall be reported to security@rexblack.com without delay, per the Incident Response Plan (012-incident-response-plan.md).
  6. Violation of this policy, or of any policy it incorporates, is grounds for disciplinary action up to and including termination of employment or contract, and (where applicable) civil and criminal referral.

5. Roles & responsibilities

Role Responsibility
CEO / Security Officer Final accountability; approves all policies and material changes.
Privacy Officer Accountable for GDPR/CCPA/privacy obligations.
Engineering leadership Operates technical controls, owns secure SDLC.
All personnel Comply with every policy in this directory.

6. Enforcement & exceptions

Non-compliance is handled per the HR Security Policy (024-hr-security-policy.md). Exceptions require a written request to the Security Officer, are time-boxed, tracked in the Risk Register, and approved only when a compensating control exists.

7. References

  • All policies in compliance/policies/
  • All registers in compliance/registers/
  • Cybersecurity insurance: $5,000,000 aggregate, policy on file with the CEO.

8. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial approved policy.

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center