Effective Date: July 1, 2025
This Policy establishes requirements for protecting FNBubbles420 Org information assets, systems, and networks against unauthorized access, disclosure, alteration, or destruction. It applies to all volunteers, contractors, and systems under organizational control.
All information must be classified by sensitivity:
Volunteers must use organizational IT resources for authorized non-commercial purposes only. Prohibited activities include:
Access to systems and data must follow the principle of least privilege:
Confidential and Restricted data must be encrypted at rest and in transit using industry-standard algorithms (AES-256, TLS 1.2+). Volunteer devices must enable disk encryption and secure backups.
All systems and applications must be updated with security patches within 30 days of release. Critical vulnerabilities require patching within 7 days.
Any suspected security incident must be reported immediately to the Information Security Lead via Discord or email. An incident response plan will be activated to contain, investigate, and remediate.
Vendors and external services processing organizational data must demonstrate security controls equivalent to this Policy. Contracts must include data protection clauses.
This Policy and any disputes shall be governed by Michigan law without regard to conflict of laws principles. Legal action must be brought exclusively in Michigan courts.
This Policy will be reviewed annually by the Board of Directors. Amendments require majority approval and publication with an updated effective date.