IT Security & Data Privacy Policy

Policy Number: KB-POL-SEC-001  |  Version: 3.1  |  Effective: 15 February 2025  |  Owner: Marcus Chen (IT Lead)

1. Purpose

This policy establishes the rules and guidelines for protecting customer data, company information systems, and network infrastructure at KangaByte Computer Repair. Compliance is mandatory for all employees and contractors.

2. Customer Data Protection

IMPORTANT: Under the Australian Privacy Act 1988 and APP (Australian Privacy Principles), mishandling of customer personal information can result in fines of up to $2.5 million for the company and personal liability for individuals.

2.1 Data We Handle

During the repair process, we may access or store:

  • Personal Information: Customer names, phone numbers, email addresses, physical addresses
  • Device Data: Hard drive contents, browser history, saved passwords, personal files
  • Financial Data: Payment details (processed via terminal only — never recorded manually)
  • Business Data: For business customers, potentially sensitive commercial information

2.2 Handling Requirements

RuleDetailsPenalty
Never access personal files unnecessarilyOnly access files directly related to diagnosing the reported issueWritten warning
No copying of customer dataDo not copy, transfer, or share any customer files to personal devices or accountsTermination
No photographing customer screensDo not take photos of customer desktops, documents, or personal contentTermination
Privacy screen filtersUse privacy filters on workbenches when servicing devices with personal data visibleVerbal warning
Disposal of drivesAll old/replaced hard drives must be physically destroyed or degaussed before disposalWritten warning

3. Password & Access Control

  • Password requirements: Minimum 12 characters, must include uppercase, lowercase, numbers, and special characters
  • Password rotation: Every 90 days — you will receive a prompt
  • Multi-factor authentication: Required on all systems that support it
  • Never share passwords — not even with managers or IT staff
  • Lock your workstation when stepping away (Win+L or Cmd+Q on Mac)
  • Do not use personal devices to access company systems unless approved and encrypted

4. Acceptable Use of Company Systems

Company computers, networks, and internet access are provided for business use. Limited personal use is permitted provided it does not interfere with work duties, consume excessive bandwidth, violate laws, or involve inappropriate content.

Prohibited activities include:

  • Installing unauthorized software on company machines
  • Using peer-to-peer file sharing or torrenting
  • Connecting personal devices to the repair network
  • Using company email for personal business

5. Network Security

Network Architecture: KangaByte operates three separate networks — Repair LAN (10.0.1.0/24), Office LAN (10.0.2.0/24), and Guest Wi-Fi (10.0.3.0/24). Customer devices being repaired must NEVER be connected to the Repair LAN or Office LAN.
  • Customer devices connect to the isolated test network (VLAN 50) only
  • Report any suspicious network activity to IT immediately
  • Do not plug in unknown USB devices — ever
  • VPN must be used when accessing company systems remotely

6. Physical Security

  • All repair benches must be locked at end of day
  • Customer devices must be stored in numbered lockers — one device per locker
  • The server room is access-restricted — authorised personnel only
  • CCTV operates 24/7 in all work areas
  • Visitors and customers must be escorted in the workshop area

7. Incident Response

If you suspect a data breach or security incident:

  1. Contain: Immediately disconnect affected systems from the network
  2. Report: Notify Marcus Chen (Ext. 101) or Ben Wallace within 30 minutes
  3. Document: Record what happened, when, and what data may be affected
  4. Preserve: Do not delete logs or attempt to "fix" the issue yourself

8. Remote Work Security

  • Only company-issued or approved devices may be used for remote access
  • VPN connection is mandatory — no exceptions
  • Do not work on customer data from public Wi-Fi networks
  • Home networks must use WPA3 or WPA2 encryption with a strong password
Acknowledgement Required: All employees must confirm they have read and understood this policy. This is recorded during your onboarding induction and at each quarterly review.