Information security policy and program
October 1, 2026
Purpose and scope
This program defines how Modern Training Solutions, LLC protects information used to deliver Learning Cub services. Its goals are to keep information accessible only to authorized people, accurate and protected against unauthorized changes, and available when needed.
It applies to employees, contractors, and company-managed systems supporting Learning Cub, including its website, learning platforms, business accounts, software, devices, and customer information. For customer-managed or vendor-managed systems, responsibilities must be agreed with the relevant party. Outsourcing a service does not remove our responsibility to assess how our information is protected.
Responsibilities
Management approves the program, appoints a security coordinator, provides reasonable resources, and decides whether significant unresolved risks are acceptable. The coordinator may be an existing staff member; a separate security department is not required.
The security coordinator maintains the program, coordinates risk reviews and incident handling, and tracks improvements. Technical staff manage access, updates, backups, and security settings for systems under their control. All employees and contractors must protect company and customer information, follow applicable procedures, and promptly report suspected problems to the coordinator or management.
One person may hold multiple roles. Assigned names and internal contact details are maintained in an internal record available to staff.
Identify systems and assess risks
The coordinator maintains a simple list of important systems, their owners, key service providers, and the types of information they handle. Information is treated as public, internal, or confidential. Personal information, credentials, and nonpublic customer records are confidential.
At least annually, and before significant changes, the coordinator reviews likely risks such as stolen accounts, accidental disclosure, software vulnerabilities, service outages, and data loss. Each material risk is recorded with its likely impact, priority, responsible person, and planned action or management-approved acceptance.
A spreadsheet or issue tracker is sufficient. Higher-impact and actively exploited risks receive priority. Applicable customer commitments and legal requirements are considered when choosing safeguards.
Basic safeguards
The following requirements apply to systems and information within our control:
- Access: Give each person only the access needed for their work. Use individual accounts where supported, approve administrative access, and remove access promptly when it is no longer needed. Review access to important systems at least annually and when responsibilities change.
- Privileged accounts: Administrative and other elevated access must be approved by management or the security coordinator and limited to people who need it for their duties. Use individually assigned accounts and use standard access for routine work where practical. The security coordinator or designated technical person reviews privileged accounts at least annually and when staff leave or responsibilities change, including employee, contractor, and service accounts. Remove or reduce unnecessary privileges promptly. Record the review date, reviewer, accounts checked, and any resulting actions in a ticket or spreadsheet.
- Account protection: Use strong, unique passwords and a password manager. Enable multi-factor authentication for administrative accounts, business email, and remote access where supported. Record unsupported cases and alternative protections through the exception process below.
- Devices: Protect work laptops, phones, tablets, and other mobile devices with screen locks, supported software, security updates, and appropriate malware protection. Enable full-disk or device encryption using a supported implementation of AES-128, AES-256, or an equivalent strong industry-standard algorithm on devices that store or access organizational or sensitive information, including personally owned devices used for work. Use encrypted connections when accessing organizational services. Store recovery keys securely with access restricted to authorized people, separately from the device. Verify encryption is enabled before granting access and at least annually afterward, recording the check in a ticket or device inventory. Devices that cannot meet these requirements must not store or access organizational or sensitive information.
- Data handling: Collect and retain only information needed for business, contractual, or legal purposes. Use approved services, encrypted connections for confidential data transfers, and encryption for stored confidential information where supported. Restrict access to exports and backups. Securely delete or anonymize information when it is no longer needed, accounting for backup retention and required records.
- Software and changes: Track relevant security updates and prioritize fixes according to risk. Review and test material changes before release, keep source changes in version control, and maintain a practical rollback approach. Keep passwords and other secrets out of source code and public documents.
- Security updates and patches: Technical staff check for available security updates at least monthly and apply applicable patches and fixes to all organization-managed servers and applications on a monthly cycle, with no applicable security update deferred beyond one calendar quarter without a documented, management-approved exception and temporary safeguards. Critical or actively exploited vulnerabilities receive priority for earlier remediation. Check that affected services work after updates and record completion in a ticket or maintenance log. For provider-managed systems, confirm the provider’s responsibility for patching.
- Third-party risk assessment: Before engaging subcontractors, affiliates, suppliers, or other third parties used to deliver customer services, the security coordinator or management assesses risks proportionate to the third party’s access to information and importance to service delivery. Consider the information they handle, their security and privacy safeguards, service reliability, and relevant customer requirements. Review available security documentation or request clarification where needed. Record the assessment, identified concerns, and approval in a ticket or spreadsheet. Address significant risks before engagement or document management’s acceptance with appropriate safeguards. Reassess important third parties at least annually and after significant service changes or security incidents.
Control gaps must be recorded and addressed through planned actions or approved exceptions; they must not be silently treated as implemented.
Detect and report problems
Technical staff enable useful security logs and available alerts for important systems, proportionate to risk. These may include unusual sign-ins, administrative changes, and backup failures. The coordinator records who receives alerts, how often logs need review, and any monitoring gaps. Logs must be protected against unauthorized access and retained for a documented period appropriate to operational and contractual needs.
Staff must promptly report suspected phishing, lost devices, exposed information, unauthorized access, or unusual system behavior to the coordinator or management. They should report concerns even if they are unsure an incident has occurred.
Security alerts must be configured for suspicious activity in organization-managed applications, platforms, and network devices, using available monitoring features or a centralized monitoring service. Technical staff select relevant events, such as repeated failed sign-ins, unexpected privileged-account changes, or suspicious network activity, and route notifications to a designated person for investigation. Check alert delivery when configured and at least annually. Record coverage, recipients, and any gaps in a ticket or monitoring inventory. For provider-managed infrastructure, confirm the provider’s monitoring responsibilities and how relevant incidents are reported to us.
Respond and recover
The security coordinator coordinates response to suspected incidents affecting customer assets or information, company systems, or service delivery. Management appoints a backup contact when the coordinator is unavailable. Keep internal escalation contacts and customer notification contacts in a restricted location accessible during an outage.
For a suspected incident, the coordinator works with technical staff and management to:
- Monitor and report: Use the monitoring and reporting arrangements in the “Detect and report problems” section to identify potential incidents. Employees and contractors must promptly report concerns to the coordinator or management without waiting for confirmation.
- Assess and escalate: Record when the concern was reported, what happened, and which customers, assets, systems, or information may be affected. Assess urgency based on potential exposure, disruption, and ongoing harm. Escalate serious or ongoing incidents to management immediately.
- Contain and preserve evidence: Limit harm, such as by disabling affected accounts or isolating devices. Preserve relevant logs, messages, and other evidence, restrict access to them, and record actions taken. Avoid unnecessarily altering evidence during investigation.
- Investigate: Assign technical staff or an appropriate service provider to determine the cause, scope, timeline, and whether customer assets or information were accessed, changed, lost, or disclosed. Document findings and remaining uncertainty.
- Notify: Management coordinates notification to affected customers without undue delay when an incident affects their assets or information, or when otherwise required by an applicable agreement or law. Follow specified notification deadlines and do not wait for the full investigation if earlier notice is required. Use agreed customer contacts and secure communication channels. Include known facts, likely impact, actions taken, recommended customer actions, and a follow-up contact. Provide updates as material information becomes available. Determine whether affected individuals, providers, or authorities also require notification, and record when, how, and to whom notices were sent.
- Recover and improve: Correct the cause, restore services from a known safe state, and check for continuing compromise. Record the outcome, lessons learned, and follow-up actions with responsible owners.
Keep incident records in a restricted ticket or document. Review these response and notification arrangements at least annually and after significant incidents. A brief walkthrough of an example incident is sufficient to check responsibilities, contacts, and response steps.
Important business data must have protected backups or another documented recovery method. Technical staff document backup frequency, retention, recovery priorities, and acceptable disruption based on business needs. Check backup results at a defined interval and test a representative restoration at least annually and after major recovery changes. Keep recovery information and necessary contacts available during an outage.
Business continuity
Management approves and supports a business continuity program to maintain or restore essential services during disruptions, including system outages, cyber incidents, loss of a key provider, or staff unavailability.
The security coordinator maintains a practical internal continuity plan with input from management and technical staff. The plan identifies:
- Essential services, their dependencies, and recovery priorities.
- Acceptable downtime and data loss, taking customer commitments into account.
- Responsible staff, backup contacts, and key service-provider contacts.
- Recovery steps and temporary working arrangements, including alternatives when key systems, providers, or personnel are unavailable.
- How employees, contractors, affected customers, and relevant providers will receive updates during a disruption.
Management approves the plan and significant changes, with approval recorded in a ticket, email, or meeting note. Communicate relevant responsibilities and arrangements to employees, contractors, and other interested parties, including customers and providers where applicable. Share only the information each party needs and keep sensitive operational details restricted.
During a disruption, management or its designated backup activates the plan, coordinates recovery, and ensures affected parties receive appropriate updates. Use the incident-response and backup arrangements in this program where relevant.
Review the plan at least annually and after significant disruptions or changes. Conduct a brief walkthrough or practical exercise at least annually, record the results, and assign any necessary improvements.
Staff guidance
Employees and contractors receive security guidance when they join and a brief refresher at least annually. Guidance covers account protection, phishing, safe handling of information, device security, and reporting concerns. A short briefing or written guidance with recorded acknowledgment is sufficient.
Review, exceptions, and records
At least annually, the coordinator reviews this program with management, including significant risks, incidents, access reviews, recovery checks, and overdue actions. Update it when services, risks, or obligations change materially.
If a requirement cannot reasonably be met, management must approve a documented exception stating the reason, risk, alternative safeguards, responsible person, and review or expiry date. Exceptions cannot override applicable legal or contractual obligations.
Maintain lightweight internal records of program approval, role assignments, system and risk lists, agreed operating schedules, staff guidance, key checks, incidents, and exceptions. Existing tickets, meeting notes, or spreadsheets may serve as evidence; a dedicated compliance platform is not required. Restrict sensitive operational details to authorized people.
This program is the foundation for supporting security policies and procedures. It does not by itself establish certification or compliance with a particular security standard.