Information security policy and program

October 1, 2026

Purpose and scope

This program defines how Modern Training Solutions, LLC protects information used to deliver Learning Cub services. Its goals are to keep information accessible only to authorized people, accurate and protected against unauthorized changes, and available when needed.

It applies to employees, contractors, and company-managed systems supporting Learning Cub, including its website, learning platforms, business accounts, software, devices, and customer information. For customer-managed or vendor-managed systems, responsibilities must be agreed with the relevant party. Outsourcing a service does not remove our responsibility to assess how our information is protected.

Responsibilities

Management approves the program, appoints a security coordinator, provides reasonable resources, and decides whether significant unresolved risks are acceptable. The coordinator may be an existing staff member; a separate security department is not required.

The security coordinator maintains the program, coordinates risk reviews and incident handling, and tracks improvements. Technical staff manage access, updates, backups, and security settings for systems under their control. All employees and contractors must protect company and customer information, follow applicable procedures, and promptly report suspected problems to the coordinator or management.

One person may hold multiple roles. Assigned names and internal contact details are maintained in an internal record available to staff.

Identify systems and assess risks

The coordinator maintains a simple list of important systems, their owners, key service providers, and the types of information they handle. Information is treated as public, internal, or confidential. Personal information, credentials, and nonpublic customer records are confidential.

At least annually, and before significant changes, the coordinator reviews likely risks such as stolen accounts, accidental disclosure, software vulnerabilities, service outages, and data loss. Each material risk is recorded with its likely impact, priority, responsible person, and planned action or management-approved acceptance.

A spreadsheet or issue tracker is sufficient. Higher-impact and actively exploited risks receive priority. Applicable customer commitments and legal requirements are considered when choosing safeguards.

Basic safeguards

The following requirements apply to systems and information within our control:

Control gaps must be recorded and addressed through planned actions or approved exceptions; they must not be silently treated as implemented.

Detect and report problems

Technical staff enable useful security logs and available alerts for important systems, proportionate to risk. These may include unusual sign-ins, administrative changes, and backup failures. The coordinator records who receives alerts, how often logs need review, and any monitoring gaps. Logs must be protected against unauthorized access and retained for a documented period appropriate to operational and contractual needs.

Staff must promptly report suspected phishing, lost devices, exposed information, unauthorized access, or unusual system behavior to the coordinator or management. They should report concerns even if they are unsure an incident has occurred.

Security alerts must be configured for suspicious activity in organization-managed applications, platforms, and network devices, using available monitoring features or a centralized monitoring service. Technical staff select relevant events, such as repeated failed sign-ins, unexpected privileged-account changes, or suspicious network activity, and route notifications to a designated person for investigation. Check alert delivery when configured and at least annually. Record coverage, recipients, and any gaps in a ticket or monitoring inventory. For provider-managed infrastructure, confirm the provider’s monitoring responsibilities and how relevant incidents are reported to us.

Respond and recover

The security coordinator coordinates response to suspected incidents affecting customer assets or information, company systems, or service delivery. Management appoints a backup contact when the coordinator is unavailable. Keep internal escalation contacts and customer notification contacts in a restricted location accessible during an outage.

For a suspected incident, the coordinator works with technical staff and management to:

  1. Monitor and report: Use the monitoring and reporting arrangements in the “Detect and report problems” section to identify potential incidents. Employees and contractors must promptly report concerns to the coordinator or management without waiting for confirmation.
  2. Assess and escalate: Record when the concern was reported, what happened, and which customers, assets, systems, or information may be affected. Assess urgency based on potential exposure, disruption, and ongoing harm. Escalate serious or ongoing incidents to management immediately.
  3. Contain and preserve evidence: Limit harm, such as by disabling affected accounts or isolating devices. Preserve relevant logs, messages, and other evidence, restrict access to them, and record actions taken. Avoid unnecessarily altering evidence during investigation.
  4. Investigate: Assign technical staff or an appropriate service provider to determine the cause, scope, timeline, and whether customer assets or information were accessed, changed, lost, or disclosed. Document findings and remaining uncertainty.
  5. Notify: Management coordinates notification to affected customers without undue delay when an incident affects their assets or information, or when otherwise required by an applicable agreement or law. Follow specified notification deadlines and do not wait for the full investigation if earlier notice is required. Use agreed customer contacts and secure communication channels. Include known facts, likely impact, actions taken, recommended customer actions, and a follow-up contact. Provide updates as material information becomes available. Determine whether affected individuals, providers, or authorities also require notification, and record when, how, and to whom notices were sent.
  6. Recover and improve: Correct the cause, restore services from a known safe state, and check for continuing compromise. Record the outcome, lessons learned, and follow-up actions with responsible owners.

Keep incident records in a restricted ticket or document. Review these response and notification arrangements at least annually and after significant incidents. A brief walkthrough of an example incident is sufficient to check responsibilities, contacts, and response steps.

Important business data must have protected backups or another documented recovery method. Technical staff document backup frequency, retention, recovery priorities, and acceptable disruption based on business needs. Check backup results at a defined interval and test a representative restoration at least annually and after major recovery changes. Keep recovery information and necessary contacts available during an outage.

Business continuity

Management approves and supports a business continuity program to maintain or restore essential services during disruptions, including system outages, cyber incidents, loss of a key provider, or staff unavailability.

The security coordinator maintains a practical internal continuity plan with input from management and technical staff. The plan identifies:

Management approves the plan and significant changes, with approval recorded in a ticket, email, or meeting note. Communicate relevant responsibilities and arrangements to employees, contractors, and other interested parties, including customers and providers where applicable. Share only the information each party needs and keep sensitive operational details restricted.

During a disruption, management or its designated backup activates the plan, coordinates recovery, and ensures affected parties receive appropriate updates. Use the incident-response and backup arrangements in this program where relevant.

Review the plan at least annually and after significant disruptions or changes. Conduct a brief walkthrough or practical exercise at least annually, record the results, and assign any necessary improvements.

Staff guidance

Employees and contractors receive security guidance when they join and a brief refresher at least annually. Guidance covers account protection, phishing, safe handling of information, device security, and reporting concerns. A short briefing or written guidance with recorded acknowledgment is sufficient.

Review, exceptions, and records

At least annually, the coordinator reviews this program with management, including significant risks, incidents, access reviews, recovery checks, and overdue actions. Update it when services, risks, or obligations change materially.

If a requirement cannot reasonably be met, management must approve a documented exception stating the reason, risk, alternative safeguards, responsible person, and review or expiry date. Exceptions cannot override applicable legal or contractual obligations.

Maintain lightweight internal records of program approval, role assignments, system and risk lists, agreed operating schedules, staff guidance, key checks, incidents, and exceptions. Existing tickets, meeting notes, or spreadsheets may serve as evidence; a dedicated compliance platform is not required. Restrict sensitive operational details to authorized people.

This program is the foundation for supporting security policies and procedures. It does not by itself establish certification or compliance with a particular security standard.