This policy defines the minimum security requirements for contractors who access Company systems, accounts, code, or data.
The purpose of this policy is to reduce the risk of unauthorized access, data loss, credential compromise, and avoidable security incidents.
This policy applies to all devices, accounts, software, tools, and storage locations used for Company work, whether owned by the contractor or provided by the Company.
Contractors must:
Shared credentials are prohibited unless the Company has explicitly authorized a controlled shared account for a specific purpose.
Devices used for Company work must: