handbook/handbook/security/information-security-framework/information-security-roles-and-responsibilities.md
Tuist GmbH is committed to conducting business in compliance with all applicable laws, regulations, and company policies. Tuist GmbH has adopted this policy to outline the security measures required to protect electronic information systems and related equipment from unauthorized use.
This policy and associated guidance establish the roles and responsibilities within Tuist GmbH, which is critical for effective communication of information security policies and standards. Roles are required within the organization to provide clearly defined responsibilities and an understanding of how the protection of information is to be accomplished. Their purpose is to clarify, coordinate activity, and actions necessary to disseminate security policy, standards, and implementation.
This policy is applicable to all Tuist GmbH infrastructure, network segments, systems, and employees and contractors who provide security and IT functions.
The audience for this policy includes all Tuist GmbH employees and contractors who are involved with the Information Security Program. Awareness of this policy applies for all other agents of Tuist GmbH with access to Tuist GmbH information and infrastructure. This includes, but is not limited to partners, affiliates, contractors, temporary employees, trainees, guests, and volunteers. The titles will be referred collectively hereafter as “Tuist GmbH community”.
| Roles | Responsibilities |
|---|---|
| Board of Directors | - Oversight of Cyber-Risk and internal control for information security, privacy and compliance. |
The IT Manager will measure the compliance to this policy through various methods, including, but not limited to—reports, internal/external audits, and feedback to the policy owner. Exceptions to the policy must be approved by the IT Manager in advance. Non-compliance will be addressed with management and Human Resources and can result in disciplinary action in accordance with company procedures up to and including termination of employment.
The version history of this document can be found in Tuist's handbook repository.