Information Security Policy

ARRA FINANCE, LLC ONLINE information security POLICY

INTRODUCTION

Arra Finance, LLC (“Arra” or “Company”) has established this Information Security Policy (the “IS Policy”) which is a component of Arra’s overall information security management framework and part of Arra’s Compliance Management System Safeguards Policy. Arra is expected to preserve confidentiality, integrity, and availability of information, including information supplied by, generated for, and held on behalf of third parties.

This IS Policy outlines Arra’s approach to information security management. It provides the guiding principles and responsibilities necessary to safeguard the security of the organization’s information systems and protect customer information.

Compliance with this policy is necessary to ensure business continuity and minimize business damage by preventing and mitigating the impact of security risks and incidents.

The objective of this IS Policy is to establish the  policies, procedures and an organizational structure that are appropriately designed to protect the Company’s information assets and critical activities from  related threats and to ensure applicable regulatory, statutory, contractual, and legislative requirements are met (aka “Safeguards Program”). This policy is part of Arra’s Compliance Management System Safeguards Policy. This IS Policy describes policies and procedures for securing data, software, systems and equipment, and describes methodologies designed to prevent and respond to a variety of threats including unauthorized access, disclosure, duplication, modification, destruction, loss, misuse, or theft of information owned by or in the custody of Arra.

The primary objectives of this policy are as follows:

•         To educate Arra Users (defined below) about their responsibilities to protect data, software systems, and equipment; and

•         To establish the core principles for maintaining Arra information and data security.

SCOPE

This IS Policy applies to  systems and the hardware that the systems run on, the networks, and data that exist in any Arra location. Any Arra Users or third-party service providers / vendors (“Vendors”) who have access to Arra networks, systems, or data belonging to Arra or Arra Customers are bound by this IS Policy, including:

•         Full or part time employees and contractors of Arra (“Arra Users”)

•         Arra Vendors

Violation of Information Security Policy

Any violation of this IS Policy by an Arra User could negatively and severely impact Arra and may result in disciplinary and legal action, at the discretion of Arra’s senior management. Severe, deliberate, or repeated violations may be considered grounds for dismissal, or in the case of an Arra contractor or subcontractor, termination of contracted services.

IT Security Organization

The IT Security organization consists of the Chief Information Security Officer (“CISO,” also known as the “Qualified Individual”) and IT Security team. The CISO reports to the Chief Technology Officer (“CTO”). The IT Security team consists of the CTO, CISO, and IT Security Analysts and reports through the Information Technology office up to the Chief Financial Officer (“CFO”). Together this organization is responsible for:

•         Maintaining this IS Policy and all supporting Information Security Policies.

•         Defining the security requirements, controls, and mechanisms applicable to all data assets.

•         Defining  other applicable data security usage, processing, transmission, storage and disposal processes and procedures.

•         Defining the procedures necessary to ensure compliance with this IS Policy by all Arra Users.

•         Facilitating the evaluation of new regulatory, legal, and best practice requirements as they are mandated or become recognized in industry.

•         Ensuring that  appropriate personnel are aware of this IS Policy and  supporting Information Security Policies.

•         Monitoring enforcement of this IS Policy and responding to breaches of the same.

Specific questions about the policies described herein must be directed to the CISO.

Technology Steering Committee

The Technology Steering Committee (“TSC”) includes Arra’s Chief Financial Officer, Chief Technology Officer, Chief Information Security Officer, Chief of Staff, Chief Operating Officer, and Head of Compliance. The TSC is responsible for:

•         Oversight of information technology matters, including selection, purchasing, implementation, security, and maintenance of Arra technology.

•         Providing recommendations to Arra’s Executive  Team regarding major technology investments.

•         Ensuring that the Company’s IT policies and procedures are updated and approved by the CFO and CEO each year.

•         Overseeing the annual updates, testing and employee training related to the Company’s disaster recovery plans.

•         Oversight of technology vendor management.

Management

Management and supervisors have the responsibility to:

•         Provide appropriate support and guidance to assist employees to fulfill their responsibilities under this IS Policy.

•         Ensure their staff complies with this IS Policy and  supporting Information Security Policies.

•         Enforce this IS Policy.

Support Personnel

The IT Security team, in collaboration with the IT Department, is responsible for the activation of all mandated security controls and mechanisms in this IS Policy.

Arra Users

All Arra Users are responsible for familiarizing themselves and complying with this IS Policy, and any related Arra policies, procedures, and standards dealing with information security. All Arra Users must understand the importance of information protection and their security responsibilities as part of their job function. Security questions must be directed to the IT Security team.

IT Personnel Policy

Arra will hire individuals to manage and perform IT duties as appropriate for the size and complexity of Arra’s IT infrastructure. Consultants and contractors may be used to augment the staff or to provide expertise not readily available by staff.

Individuals who fail to pass an appropriate background check that indicates untrustworthiness will not be hired into IT positions of trust.

Individuals that have been convicted of violating wire, electronic, computer or identity related laws will not be hired at Arra to perform information security work.

Separation of Duties

“Separation of Duties” is the concept of having more than one person required to complete a task. This serves two key purposes: ensures that there is oversight and acts as a review to catch errors. Within IT systems, separation of duties will ensure that privileged users who configure and/or administer the network devices or critical systems do not have access to review, modify, or remove logs from the associated monitoring services.

Security Awareness Training

All Arra employees are required to take “Security Awareness” training, both during new employee onboarding as well as at least once annually.

The IT Security team also  sends out email communications to keep security best practices at the forefront of each employee’s mind.

data security

The day-to-day operations of Arra involve the handling of Company or customer data that can be considered confidential in nature. Confidential data is any information that is not to be publicly disclosed and includes, but is not limited to:

•         Company strategic plans

•         Customer records (including any list, description, or other grouping of consumers that is not publicly available)

•         Social Security Numbers

•         Loan or account information (including any combination of customer name plus customer account number)

As such, Arra, its users, contractors, vendors, and all other business partners, have a duty to keep this data secure from unauthorized access or disclosure. The following sections describe the policies and general guidelines for the safe handling of information owned by or in the possession of Arra.

Digital Data Transmission

All data transmitted to or from Arra’s network, over public networks, such as the internet, must be encrypted if it is known or suspected to have data that is confidential in nature, regardless of transmission methods, including, but not limited to email and FTP. The level of encryption used must fall within the guidelines outlined in Arra’s Encryption Policy.

All proposed data integrations are subject to approval by IT Security prior to implementation. Any existing integrations/data transmissions (FTP, SFTP, FTPS, API, batch jobs, etc.) will be reviewed at regular intervals. Certificates and passwords used to protect data transfers will also be reviewed and renewed when applicable.

Shipping and Manual Handling of Information

If sending confidential data in digital format by U.S. mail or express carriers, the following precautions must be taken:

•         Confirm recipient addresses are correct.

•         Encrypt the confidential data.

•         Ensure the method used to send the information can be tracked and delivery can be verified.

Data Removal from Premises

Confidential or proprietary data may not be removed from Arra premises unless specifically authorized by Senior Management. This policy includes confidential or proprietary data stored on laptop hard disks, optical media, USB devices, hard-copy output, paper memos, faxes, etc. An exception to this requirement is made for authorized off-site back-ups.

Data Storage

All Company data must be stored on network drives where possible, rather than the local desktop hard drive. This offers additional security and ensures the data can be reliably backed up. All Arra Users are provided with a network folder (My Documents) for data storage. Arra Users will (within any applicable guidelines for information retention) periodically delete files that are no longer needed. Common network storage areas are also provided for sharing data in and between departments (network shares, SharePoint, etc.).

Portable Storage Devices

Portable storage devices such as USB drives and RW optical drives are not to be used without specific permission of the IT Security team. Arra’s Wireless Network Policy will be used to disable these devices when connected to the network. If an exception is provided, only encrypted USB drives provided by IT will be permitted.

Confidential customer data will not be stored on mobile computing devices such as PDAs and laptops.

Data Storage in Cloud/Shared Infrastructure Environments

All confidential data stored in a cloud or shared infrastructure environment must be encrypted at rest. Encryption ciphers and key strength will follow the guidelines outlined in Arra’s Encryption Policy.

When entering into a contract for a cloud infrastructure environment, Arra will require contractual provisions for secure data storage with the vendor in question, including constraints on the geographical location of the data.

Data Disposal

Confidential data in hard copy format, such as printed reports, must be disposed of in a secure manner. Arra provides numerous secured shredder boxes for this purpose. Disposal of documents containing confidential information in unsecured trash cans or recycling bins is prohibited.

Secure electronic data deletion (including data overwriting according to DoD standards) will always be performed on company hard drives, by the IT Department, prior to physically disposing of end point or server devices. When electronic data deletion is not possible, hard drives will be physically destroyed (crushed, shredded, melted, et al.). If a third-party vendor is providing disposal services, a “death certificate” must be obtained per hard drive destroyed. The IT Department will keep accurate records of device disposals including serial numbers, asset tags, and disposal dates.

When entering into a contract for a cloud/shared server environment, Arra will require contractual provisions for secure data deletion with the vendor in question. The vendor will provide the ability to securely wipe all Company data (file shares, databases, and application data where applicable), while also providing deletion verification and/or death certificates back to Arra.

Non-Disclosure Agreements – Third Parties

Outside consultants, contractors, and vendors with access to confidential information must sign a nondisclosure agreement with Arra, outlining the Third Party’s information security responsibilities when dealing with access to company data or facilities.

Clean Desk Policy

Arra maintains a Clean Desk Policy, to ensure best practices for maintaining a secure workspace in regard to sensitive data, by maintaining a clean desk and clear screen in compliance with applicable federal and state privacy laws. This policy applies to all Company employees, contractors, and affiliates, including those working offsite, and covers all sensitive data, customer or employee related, whether in print or digital format. IT Security and Compliance may conduct unannounced, random audits to determine compliance with the policy.

Access control

Arra Users will be granted access to the network, systems, and data only on an as needed basis. The access needed is determined by the Business Unit Department Manager and the Chief Information Security Officer based on the job function and will be limited to the minimum rights necessary to perform the given job duties. The IT Department will issue user IDs and make necessary additions, changes, or deletions. Each Arra User must read and acknowledge the Information Technology Acceptable Use Policy in order to maintain system access. The preferred mechanism for authentication to all Arra Applications, Websites and Systems is Single Sign On where possible.

User Creation

New user creation will be initiated through an official HR request only. Standard role-based rights for network and application access, as dictated by job code, will be issued to the new user. Any additional access must be requested through the IT ticketing system by the user’s Business Unit Department Manager (see III.A.3 “Additional Access Requests” below).

User Transfer / Termination

When a user is promoted, reassigned, and/or transferred into a different role within Arra, system privileges will be modified, when necessary, to reflect the new job responsibilities. Access based on previous job responsibilities that are no longer necessary will be removed.

Upon termination of employment or other association with Arra, all system access privileges must be immediately terminated. User terminations will be initiated through an official HR request only.

Additional Access Requests

Access that is required to perform new or modified job responsibilities, which are not part of an official job transfer, must be requested through the IT ticketing system by the user’s Business Unit Department Manager. This includes all new requests for network, system, or application access. IT Security will not review access requests entered by a user on behalf of themselves.

Privileged Access

Access that can override network, system, or application controls is considered privileged and is in addition to basic access when needed. A request for privileged access must be requested through the IT ticketing system and approved by IT Security, and in some cases, the Chief Technology Officer before it will be granted.

User IDs

All access control systems must utilize User IDs unique to each user. User IDs provide a way to determine the identity of the user accessing system resources. The User ID provided to each Arra User is the sole responsibility of that individual and must never be shared with another employee.

Anonymous or Shared User-IDs

Users will not log into any network or system by utilizing a “shared” or “anonymous” user-ID (e.g., multiple users logging into Shaw with “admin1”). Exceptions due to system limitations may be provided, subject to IT management approval.

 

Administrative User IDs

Whenever feasible, administrators of networks, systems, or applications will be given a separate set of unique credentials to utilize when performing administrative tasks. User’s unique personal User-IDs must not be used when performing administrative tasks (e.g., “bsmith” used for server maintenance).

Common or default system administrator User-IDs will not be for general use. Whenever feasible, common or default User-ID names will be changed.

User ID Review

The IT Security organization will perform a regular periodic review of access levels for all user and system User IDs. Access rights will be modified as deemed necessary by the review. The IT Security organization will perform a monthly review of all User IDs to ensure accounts belonging to terminated or inactive employees are not active.

User IDs will be considered inactive after 30 days without a valid login. Inactive accounts will be disabled and deleted unless HR has provided prior notification to IT Security of employee leave.

User Passwords

All Arra Users are responsible for taking the appropriate steps, described below, to select and secure their passwords. All User IDs must have passwords.

 

Password Care

Passwords must be changed at least every ninety (90) days. Whenever a user suspects that a password may have been compromised, the user must report his or her suspicions to their manager as well as IT Security and change the password immediately. Systems that have password controls must set the password expiration to ninety (90) days or less.

Passwords must never be shared or disclosed to others. IT support staff will never ask a user to reveal their personal password.

Password Storage

Passwords must never be written down in any format.

Electronic storage of passwords is only permitted through the Arra provided password manager. All other forms of electronic storage, including online password managers, Word documents, or encrypted spreadsheets, are strictly prohibited.

Similarly, passwords must not be stored unencrypted in batch files, automatic login scripts, software macros, terminal function keys, or in other locations where unauthorized persons are likely to discover them.

Administrator or master passwords will be stored and kept current in the Arra provided Privileged Access Management (PAM) solution and be made accessible only by authorized personnel.

Password Parameters

Passwords must meet the following requirements for all applications, websites, and systems (hereinafter referred to as services) where possible:

•         Be at least twelve (12) characters in length (though Microsoft Entra ID only enforces 8)

•         Contain ASCII or Unicode characters from three of the following five categories:

◦          Upper case letters (A…Z)

◦          Lower case letters (a…z)

◦          Numbers (0…9)

◦          Any special characters (!#,&,%,$, etc.)

◦          Any Unicode character that is categorized as an alphabetic character but is not uppercase or lowercase. This group includes Unicode characters from Asian languages.

•         Not contain sequential or repetitive characters (e.g., 12345 or aaaaa)

•         Be difficult to guess and not contain easy to obtain context specific information such as family or pet names, birthdays, addresses, company names, etc.

•         Not able to reuse the previous password.

The password requirements described above will be programmatically enforced.

Default Passwords

For new User ID creation, the user must be forced to change the password upon the first login. To prevent unauthorized access, all vendor-supplied default passwords must be changed before any computer or communications system is placed into production use.

 

Expiration

Systems that have password controls must set the password expiration to ninety (90) days or less.

System Controls

No Trespassing Banners

No trespassing logon banners will be used on all Arra networks and computers that are directly accessible through external networks. These banners will employ standard no trespassing warning notices approved by the IT Security organization and will not disclose the fact that Arra systems have been reached, the nature of the information available on these systems, or the specific systems software running on these computers.

 

Screen Savers

Arra has enabled time-out protection through a screen saver on all Company computers. After a period of fifteen (15) minutes of inactivity, screen savers will blank the screen, lock the computer, and then require a password before a user can resume work.

When leaving their desk or computer to go on break, lunch, or any other activity, Arra Users must manually lock their computers by pressing “Windows Key + L” or pressing “Control + Alt + Delete” and selecting “Lock Computer.”

 

Locking

On all systems that support it, User IDs will be locked out after no more than 3 incorrect password attempts in a 24-hour period. Accounts locked out shall not be unlocked until verbal confirmation is received from user and shall only be performed by Help Desk personnel.

Multifactor Authentication (MFA) for High-Risk Access

Arra provided Multifactor Authentication shall be required for access to perform high-risk transactions. Examples of high-risk transactions covered by this policy include:

•         Electronic payments taken by an Arra employee or third-party on behalf of an Arra customer as well as payments from external institutions to Arra accounts.

•         Pulling individual credit reports on Arra customers when done outside of an automated, systemic workflow.

•         Accessing a Privileged Access Management (PAM) solution or password vault.

While the use of the Arra provided authenticator app is preferred, applications and services that only allow multifactor authentication through another means (such as OTP, hardware token) may be used where it is the only means feasible.

 

IP Restrictions

All third-party, SaaS applications or services shall be configured with IP restrictions or an equivalent mechanism to prevent access from outside of the Arra network.

Deviations from Policy

In cases where not all the user password requirements from Section III.C, or system control requirements from Section III.D are met and deviations from this policy are required, there must be documentation of what requirements are supported for each non-conforming service, what compensating controls have been documented and implemented and must be approved by the Chief Technology Officer and by the Chief Information Security Officer for each non-conforming service. Such approvals shall be periodically reviewed at a frequency of no less than every 12 months, at which time those approvals must be renewed.

Network Security

Perimeter Security

All in-bound connections from external public networks (i.e., Internet) to Arra internal networks must pass through a firewall. No Arra computer system may be attached to the Internet unless protected by a firewall.

 

Firewall

Firewalls must be placed between the Arra network and the Internet to prevent unauthorized access to Company data and voice networks and will be configured according to approved Company firewall configuration standards. The standard firewall configuration will default to denying access to Company networks from the internet or other external networks.

 

Network Device Configuration

The configuration of network firewalls and routers must be administered by staff members who are trained to make changes, as circumstances require. The privileges necessary to modify the functionality, connectivity, and services supported by the network devices must be restricted to the minimum number of technically trained individuals necessary to administer those devices. Unless explicit permission from the Chief Technology Officer has been obtained, these privileges must be granted only to individuals who are full-time permanent employees of Arra, and not to temporary employees, contractors, consultants, or outsourcing personnel.

Firewall, router and switch devices must be updated in a timely manner with any security patches or vendor releases.

All changes to Company networks must only be made by authorized and qualified persons in accordance with Arra’s IT Change Control Policy.

All firewalls, routers and switch configurations will be backed up regularly and maintained in a secure location.

Logging

The firewall must log all network traffic. Logs must be monitored and suspicious activity investigated as described in the Security Services section.

 

Intrusion Detection and Prevention Systems

An intrusion detection or prevention system must be configured, continuously running, and monitored by IT Security for Company networks connected to the Internet or external networks.

 

Web Filter

A web filter will be configured to evaluate all production network web browsing/Internet requests from end users. Websites that contain content including but not limited to pornography, gambling, gaming, violence, file sharing, social media, chat rooms, and other malicious intent will be blocked by the web filter and recorded for later reporting.

Any requests to unblock a particular website must be submitted in an official “whitelist” request via the IT ticketing tool, subject to IT Security approval.

Remote Access and Multi-Factor Authentication (MFA)

Remote access will only be provided to employees with a valid requirement. Remote access is only allowed through an external virtual desktop or a software VPN client. All methods must utilize the Arra provided multifactor authentication application. Computers accessing the Arra network must be current on security patches and have up to date antivirus software.

Vendors and contractors may also be granted remote access with the following requirements:

•         They must have an internal Arra sponsor and the approval of IT Security.

◦          They must comply with access requirements, this IS Policy, and any additional restrictions deemed necessary by Arra.

•         Accounts for remote access will have an expiration date set.

•         Accounts for remote access may only access the network during defined and approved hours. Standard hours are 7am–6pm CT. Exceptions made only with IT Security approval.

•         When remote access is no longer needed, the Arra internal sponsor will notify the Help Desk or IT Team within one business day to discontinue access.

Virtual Private Networks (VPN)

Approved users must utilize the benefits of a VPN provided by Arra when working outside an Arra office location. The IT Security team shall be responsible for the installation and maintenance of Arra VPN client software.

Additionally:

•         All VPN connections will employ the required multifactor authentication every time the connection is created.

•         Approved users with VPN privileges have the responsibility to ensure unauthorized users are not allowed access to Arra’s internal networks through the provided VPN.

•         When actively connected to the Company network, VPNs will force all traffic to and from the PC over the VPN and all other traffic will be disallowed.

•         Individual approved users shall be automatically disconnected from Arra’s network after no more than 10 hours of session initiation.

•         If an approved user is inactive for a 30-minute period, a mandatory sleep mode with network and VPN disconnect are enforced on all Arra-owned equipment. Similar safeguards are required of vendor owned equipment connecting via Arra’s VPN. Upon disconnect, the approved user must then fully authenticate again to reconnect to the network.

•         In addition, if an approved user is at any time during a session inactive for a 15-minute period a mandatory screensaver / lock screen (per Section III.D.2 Screen Savers) is enforced.

•         Pings or other artificial network processes must not be used to keep the connection open.

•         Users of computers that are not Arra owned equipment must configure the equipment to comply with Arra’s security policies.

•         Only approved VPN client software may be used.

•         By using VPN technology, approved vendors and contractors must understand that their machines are a de facto extension of Arra’s network, and as such are subject to the same rules and regulations that apply to Arra-owned equipment.

Web Linking

Arra has several links to external sites on its website. Due to compliance and reputation risks associated with providing these links, a disclaimer will be included on every web page that contains external links. These links will be reviewed by IT Security on a periodic basis to ensure the appropriate disclosures are in place and the links are functioning properly.

 

Wireless Technologies

All wireless technology shall follow all stipulations found in Arra’s Wireless Network Policy. Any wireless router placed onto the Arra network must be approved, owned, and operated by the Arra Information Technology Department. The users of approved and Company owned wireless routers will be limited to:

•         Authorized Arra employees who require wireless access to perform their assigned duties.

•         Guests of Arra including vendors and auditors, with independently owned devices.

The Arra Wi-Fi network must have the appropriate controls to ensure only authorized personnel can access the network.

Voice over IP (VoIP)

VoIP technology in use at Arra must be appropriately secured and conform to the applicable security policies set forth in this document. Additionally, the following must be in place:

•         Emergency calls originated from any location must report the appropriate location to the emergency responders.

•         Analog lines must be in place to allow a limited number of outgoing and incoming calls in the event the primary VoIP telephony system becomes inoperable.

Systems Security

All Arra systems must be secured in a manner that appropriately addresses its intended function. Systems in this context include but are not limited to file, email, web and application servers, firewalls, routers, switches, desktops, laptops, smart phones, and other portable devices.

 

Authentication

Access to Arra systems will be restricted to authorized personnel in accordance with the Access Control standards set forth in this IS Policy.

 

Configuration and Hardening

Every system in the environment must be configured according to the secure baseline configuration standards set by the system vendor and/or IT Security. Any computer or networked device that is connected to Arra’s networks by any means will be hardened against attack by malware (viruses, worms, ransomware, DDoS, and Trojans). All computers or networked devices will have the applicable operating system and application security patches and updates installed prior to initial connection to the network.

 

Equipment Taken Out of Service

Equipment taken out of service will be removed from current asset inventories according to defined IT asset handling procedures. System administrators must also ensure that all information is permanently erased from computer equipment taken out of service. All hard drives (desktops, laptops, tablets, servers, printers, copiers, fax machines) will be sanitized, according to the IT media handling procedures (as described in II.E. Data Disposal).

All newly acquired digital copiers, faxes and scanning equipment with hard drives will include encryption and overwrite protection.

Patch Management and Vulnerability Scanning

The IT Department maintains an active “Patch and Vulnerability” Group (“PVG”), which is tasked with staying current on trending technology vulnerabilities, and the associated manufacturer’s patches. All procedures are documented in Arra’s IT Systems Patching Policy.

Continuous vulnerability scanning of all Company hardware (servers, end points, telephony, printers) is performed and documented by the IT Security Department. Vulnerabilities are ranked according to industry standards (“CVEs,” or “common vulnerability and exposure”) and are identified on a host-by-host basis according to the associated exposure.

In determining remediation (patches, hotfixes, service packs), PVG members must determine Arra’s exposure to the specific vulnerability and take appropriate measures to address the associated risk.

Patching on endpoints (computers, laptops, tablets, and printers) occurs monthly. Patches are distributed to test machines, and functionality verified, prior to production roll out. Patching on servers (physical and VM), network equipment, and telephony is performed monthly. Patches are distributed to test servers, and functionality verified, prior to a production roll out.

Critical patches, hotfixes, service packs, and security updates are to be applied immediately following submission of proper change request documentation, within one week of their availability. All other patch categories are to be applied during those systems designated maintenance window.

Malware Protection

Any computer connected to Arra’s network by any means must be protected by Company approved malware (anti-virus, spyware, ransomware) detection software at all times and must maintain up-to-date definition files.

IT Security shall actively manage all malware software to ensure that the latest software updates and virus definitions are installed. Where applicable, the malware software shall be configured to obtain automatic definition updates from the vendor or other approved source.

 

F.  Physical Access to Servers

All production servers must be securely stored and physical access to the servers must be controlled and restricted to authorized personnel, in accordance with the Physical Security standards set forth in this IS Policy.

 

G.  Change Control

All changes to Arra production hardware and software systems must only be made by qualified persons authorized by IT management. All changes to production systems must be requested and approved by IT management prior to implementation, in accordance with defined IT Change Control Policy.

Mobile Computing

Mobile computing devices include laptops, tablets, smart devices, and phones, such as iPads, iPhones, Android devices, etc. As applicable, all mobile devices will be used in accordance with the guidelines set forth in this policy, including the following.

•         All devices, including Company owned smart devices and phones, must be protected by power-on or operating system passwords.

•         All laptops and tablets connecting directly to Arra’s production network must be company owned and managed.

•         All employee owned (“BYOD” or “bring your own device”) smart devices and phones, enabled to receive Arra email, contacts, and calendars, must adhere to all requirements outlined in Arra’s Bring Your Own Device (BYOD) Policy.

•         All Arra laptop and tablet hard drives must have disk-level encryption enabled prior to end user delivery.

•         Devices must have appropriate malware protection software installed with current definition and software files.

•         Arra data within applications accessing Arra data via BYOD shall be protected by the Mobile Application Management (MAM) solution.

•         Public or home wired, or wireless network security is out of the control of Arra. As such, all Company owned devices accessing such a network must be connected to the Arra VPN.

•         The device’s wireless connection will be disabled when not in use.

•         Sensitive or confidential information will not be transmitted over an unsecured wireless connection.

Connected Devices – Internet of Things or “IoT”

Any device(s) that are “designed or optimized for internet connectivity,” must receive approval from the IT Security team before being allowed connectivity to the Arra network (with the exclusion of production model laptops, computers, tablets, or smartphones). This approval extends to any network segment (production, dev/test, or guest) and any network connectivity type (wireless or wired).

When purchasing IoT devices to perform specific Company functionality or interface with existing Company systems, care will be provided to ensure:

•         The manufacturer of the device provides regular software and/or firmware upgrades.

•         The manufacturer provides a user interface for each device, to reset default usernames and passwords.

•         The device’s connectivity occurs over a secured, encrypted connection.

These “Internet of Things” or “IoT” devices may include but are not limited to smart TVs, refrigerators, thermostats, door locks, badge readers, security cameras, vehicles, or any other IP enabled item.

Virtual Computing

Virtual computing makes it possible to maximize computer utilization while minimizing associated overhead of management, power consumption, maintenance, and physical space.

Access to the virtual server console and the hypervisor will be limited to authorized personnel only and will be based upon job function. Authorized personnel must be authenticated in accordance with Access Control section of this policy.

All physical machines running virtual servers, as well as the servers running in the virtual environment, must be recorded in the server inventory maintained by the IT Department. Remote access to the virtual server console is allowed but must comply with Arra’s Identity and Access Management (“IAM”) Privilege Access Procedure.

All virtual machines and underlying host hardware must be scanned for vulnerabilities and patched in accordance with the Patch Management and Vulnerability Scanning section of this policy.

The virtual server environment must be monitored, as well as all other servers, for performance, availability, capacity, and security events.

Cloud Technology

Cloud computing is the delivery of computing services—including servers, storage, databases, networking, software, analytics, and intelligence—over the internet (“the cloud”) to offer faster innovation, flexible resources, and economies of scale. Cloud services are pay for use, helping to lower operating costs, run infrastructure more efficiently, and scale as business needs change.

Access to the cloud console will be limited to authorized personnel only and will be based upon job function. Authorized personnel must be authenticated in accordance with Access Control section of this policy.

All cloud resources must be managed and tagged according to Cloud Governance procedures. Remote access to cloud resources is allowed but must comply with Arra’s Access Management policies and procedures.

All cloud resources must be scanned for vulnerabilities and patched in accordance with the Patch Management and Vulnerability Scanning section of this policy.

The cloud environment must be monitored for performance, availability, capacity, and security events.

Physical Security

Physical security refers to the protection of the building site and all equipment housed therein, along with all Confidential Information, from physical penetration from unauthorized people, damage from environmental contaminants, accidental or intentional damage, man-made catastrophes, etc.

 

Data Center and Server Rooms

This section applies specifically to Arra’s data centers as well as any server room which houses Arra’s operational server hardware.

 

Environmental Controls

Fire detection and suppression, power conditioning, backup power, air conditioning, humidity control, and other computing environment protection systems must be maintained in the data center, as appropriate.

Uninterruptible Power Systems (UPS) must be in place to support critical servers and network devices. In the primary data center, a backup generator must be available to provide auxiliary power when needed. Backup power systems must be tested regularly and evaluated to ensure proper operation of systems and procedures.

Temperature control equipment will be utilized to maintain temperature and humidity at levels acceptable for electronic equipment.

An automatic, dry fire suppression system will be utilized at the main datacenter. All other locations will have portable fire extinguishers strategically located throughout the facility and clearly marked for ease of use.

Physical Access Controls

Access to every office, data center, and work area containing sensitive information will be physically restricted to limit access. All production computer and network devices must be physically located within a secure area. Keys, electro-mechanical door locks, and other security devices shall be utilized to control access. Video surveillance of secured areas will be utilized where possible.

Only authorized personnel with a specific need for access to computing and networking devices will be allowed access to the data center or server room.

Users must not attempt to enter restricted areas in Arra buildings or the Data Center for which they have not received access authorization.

Disaster Recovery

Disaster Recovery Plan

Arra will maintain an IT Disaster Recovery Plan. The plan identifies critical systems, defines the processes necessary to recover systems and networks needed to conduct Arra business, identifies the responsible parties and defines responsibilities of those parties.

Arra will update its disaster recovery plan at least annually and following any significant change to the computing or communications environment.

Arra IT Department will test the recovery plan at least once a year. Arra will identify deficiencies in its plan and update it accordingly.

Arra will provide training to users charged with the responsibility of implementing and executing Company disaster recovery plans. This training will consist of:

•         Making employees aware of the need for a disaster recovery plan.

•         Informing all employees of the existence of the plan and providing procedures to follow in the event of an emergency.

•         Providing a regular opportunity for recovery teams to practice disaster recovery skills and exercise business continuity plans.

Data Backups

All data considered critical to the operation of Arra’s business must be safeguarded against accidental or intentional loss due to man-made or natural disasters. This data includes, but is not limited to:

•         Core systems, financial and human resource data.

•         Email, messaging and collaboration data.

•         User data stored on shared file servers or company owned cloud services.

IT is responsible for backing up computer and communication systems used to support business functions per the IT Backup and Retention Policy. Backups of critical company systems will be performed every business day.

 

Backup Media Handling

Secure storage of backup media is the responsibility of IT management. Backup media will be transmitted securely to separate off site zones away from the system being backed up. All backup media must be encrypted and physically protected against unauthorized access. Backup media will be retained in accordance with defined Arra IT Policies and Procedures. Backups will be tested periodically to ensure backup systems are operating properly.

Software Licensing and Installation

It is the policy of Arra to respect computer software copyrights and to adhere to the terms of the software licenses to which Arra is a party. Arra will not permit any employee to intentionally use software in a manner inconsistent with the applicable license agreement.

 

Software Purchases and Licensing

All software installed on Arra desktops, laptops, tablets, and servers must be appropriately licensed. All software acquired by Arra must be purchased through the IT Department, including software that may be downloaded and/or purchased from the Internet.

Acquisition and registration of shareware products will be handled the same way as commercial software products.

Software owned by users or other non-Arra entities must not be installed on Arra equipment without notification and with the consent of the IT Department.

 

Periodic Audits

The IT Department will conduct periodic, unannounced audits of all Arra laptops, tablets, desktops, and servers to ensure that Arra is in compliance with software licensing requirements. Audits will be conducted using automated software auditing tools. It is strictly prohibited to uninstall, disable or otherwise interfere with the normal operation of these tools. Software not in compliance with applicable license agreements will be removed or the appropriate licenses must be obtained.

Software Copying

Arra provides a sufficient number of licensed copies of software such that users can get their work done in an expedient and effective manner. Arra management will make appropriate arrangements with the involved vendors for additional licensed copies, if and when additional copies are needed for business activities.

Users must not copy software provided by Arra to any storage media, transfer such software to another computer, or provide such software to outside parties without written permission from the IT Department. Ordinary back-up copies are an authorized exception to this policy.

 

Software Installation

Software installations are to be completed by IT employees only.

Only software from the Approved Software list may be installed on company systems. Illicit, illegal, or unapproved software (whether installed on systems or used “in the cloud” or online), including but not limited to peer-to-peer sharing, gambling, pornography, drugs, or violence, will not be tolerated within Arra. Users found to be in possession of illicit, illegal, or unapproved software will be forwarded to HR for disciplinary action.

Security Services

Security Management

On a frequent basis, IT Security must review all information security vulnerability advisories issued by trusted organizations (CCERT, FFIEC, FDIC, FBI, CISA, et al.) for items affecting Arra systems, as well as appropriate security logs and reports.

 

1Auditing

An external IT General Controls Review will be performed each year by a qualified independent auditor. In addition to the external audit, the IT Department will perform reviews of selected IT procedures and applicable reports on an ongoing basis. IT Management will respond to all audit reports. The reports and responses will be communicated to the Technology Steering Committee and subsequently the Board of Managers.

 

Security Testing

The effectiveness of security controls in place to protect Arra’s network and systems will be tested periodically. An external Network Penetration Test and Wireless Penetration Test will be performed at least annually by a qualified security professional. Vulnerabilities or weaknesses will be corrected and the results of the test and remediation presented to the Technology Steering Committee and subsequently to the Board of Managers. The results of these tests and the state of the vulnerability scanning program will be reviewed by an independent third party.

Logs for Critical Systems

To the extent that systems software permits, all Arra computers and network devices that handle confidential information will log all significant security events. Examples of significant security events include Users switching User-IDs during an online session, attempts to guess passwords, attempts to use privileges that have not been authorized, modifications to production application software, modifications to system software and changes to User privileges.

A Security Event and Incident Management (SEIM) log correlation system will monitor pre-determined business rules (domain admin group membership changes, system reboots, etc.) across critical servers, and alert IT Security on each instance.

Firewall monitoring and Intrusion Prevention Systems will alert IT Security to potential network and system security events based on pre-determined contact trees (high, med, low).

Malware software systems provide notifications to IT Security based off of real-time and heuristic malware scans network wide.

 

Log Retention

Logs containing significant security events must be retained for at least 90 days (and may be retained longer if required by applicable separate regulatory requirements

Log Review

The logs containing significant security events must be reviewed in a timely manner by IT Security staff. Suspicious activity will be monitored and an alert sent to management if an attempted break-in is suspected.

Security Incident Handling

The proper procedures for handling problem notification, damage control, and problem correction in the event of computer related emergencies such as virus infestations and hacker break-ins must be documented and communicated. The individuals responsible for handling information systems security incidents must be clearly defined and given the authority to handle emergency incidents. See IT Incident Response Plan.

Whenever a system is suspected of compromise, the involved computer must be immediately removed from all networks, and procedures followed to ensure that the system is free of compromise before reconnecting it to the network.

The Incident Response Plan and Disaster Recovery Plan must be available and clearly specifying how information security incidents will be handled.

Whenever unauthorized system access is suspected or known to be occurring, Arra personnel must take immediate action to terminate access or request assistance from the IT Department.

Intrusion Response

Information pertaining to the suspected intrusion must be captured whenever it is suspected that there has been unauthorized access to a computer or network. The relevant information must be securely stored offline until such time as it is determined that Arra will not need to use the information to pursue legal or other actions, or the information has been properly disclosed to the appropriate authorities. The information to be immediately collected includes the system logs, application audit trails, other indications of the current system states, and copies of all potentially involved files. The IT Security team will provide specific procedures for incident response, and these will be consulted before any action is taken on a compromised machine.

Review and Revision History

Periodic Review

This Policy will be reviewed at least annually by the Chief Technology Officer and Chief Information Security Officer, in coordination with the Head of Compliance. Updates will be made as needed to reflect changes in applicable law, regulatory guidance, technology, or the Company’s business operations. All updates shall be presented to the Technology Steering Committee for review and approved by the CFO and CEO.

 

Monitoring

The IT Security team and Compliance Department will monitor compliance with this Policy and will report any material deficiencies to senior management and the Technology Steering Committee.