

![]()


Overview
LARC operates a secure, cloud-first environment with no internally hosted servers or applications
Access Control
Least privilege access, MFA enforced, and annual access reviews.
Data Protection
Data stored in Google Workspace, Dropbox, Digify, and SolidWorks with encryption at rest and in transit.
Endpoint Security
Company-managed macOS and iOS devices with full-disk encryption and automatic updates.
Monitoring & Incident Response
Security alerts monitored; incidents handled via documented response with 48-hour notification.
Vendor Management
Approved vendors include Google Workspace, Dropbox, Digify, and SolidWorks; reviewed periodically.
Backup & Recovery
Cloud-based redundancy with periodic recovery verification.
Physical Security
Controlled access to devices and secure handling practices
Governance: Aligned with ISO 27001 principles; annual assessments and designated security contact.
This policy defines the security and privacy requirements used by Logistics Advanced Research Center (“LARC”) to protect company systems, company data, and customer-provided information, including exportcontrolled data (e.g., ITAR-controlled technical data). It establishes baseline security controls appropriate to LARC’s operating environment and supports customer and partner security expectations.
This policy applies to all LARC employees, contractors, and authorized users, and covers company-managed devices (Apple macOS laptops and iPhones), company accounts (e.g., Gmail), and approved cloud and SaaS services used to store or share business files (e.g., Dropbox, Digify, SolidWorks). LARC does not operate company-managed servers or internally hosted application platforms; the security program is endpoint- and cloud-service–focused and proportionate to this environment This policy also applies to the handling of:
Controlled Unclassified Information (CUI), if applicable
Export-controlled data subject to ITAR or EAR
LARC’s environment consists of company-managed Apple macOS laptops and iPhones, Gmail accounts, and approved SaaS platforms including Dropbox, Digify, and SolidWorks. There are no internally hosted servers, applications, or software development environments. Controls and assessments are implemented proportionately to this model. Where export-controlled data is handled, additional access, storage, and transmission controls are applied as defined in this policy
LARC maintains a documented security and privacy program aligned with accepted industry standards (including principles from ISO/IEC 27001) and reviews policies at least annually LARC designates a Security & Privacy Point of Contact responsible for program oversight, incident coordination, risk management, export control compliance coordination (e.g., ITAR data handling) and responding to customer security inquiries
LARC performs an annual, risk-based security self-assessment to evaluate the effectiveness of controls and alignment with industry best practices
At minimum, the assessment reviews endpoint security configuration, vulnerability and patching effectiveness, access control practices, secure handling of customer-provided materials (e.g., CAD files), incident readiness, and security awareness practices
Findings and improvement actions are documented, tracked, and used to update controls and procedures as needed
LARC enforces baseline security requirements for company-managed Apple devices, including supported OS versions, automatic updates, strong authentication, device auto-lock, and full-disk encryption (FileVault on macOS and native encryption on iOS)
Built-in Apple security protections such as Gatekeeper and System Integrity Protection must remain enabled. Endpoint protection and monitoring are used as appropriate for an endpoint-only environment, and users must not disable system security controls
LARC requires the use of vendor-supported software and prohibits unauthorized or pirated software Users may install software only from trusted sources (e.g., App Store or approved vendors), and browser extensions are limited to those required for business use.
Only approved software may be used to access or store export-controlled data
Unauthorized cloud services or plugins are prohibited for such data
Company and customer files must be stored only on company-approved devices and approved cloud or SaaS services Sensitive customer materials (e g , CAD files) must not be copied to personal devices, removable media, or unapproved services
Customer-provided files must be used only for approved business purposes, shared externally only when authorized, and deleted or archived securely when no longer required.
Data is classified based on sensitivity (e g , confidential, internal, public, export-controlled), and appropriate controls are applied to protect company and customer information based on classification Export-Controlled Data Requirements:
Stored only in approved systems with access restricted to U S persons (if ITAR applies)
Not stored on personal devices or unapproved platforms
Not transmitted outside the United States without proper authorization
Shared strictly on a need-to-know basis
LARC limits access to sensitive or confidential information to authorized users with a legitimate business need
Access requires documented approval by the data owner.
Access to export-controlled data is limited to:
Authorized personnel
U S persons (where ITAR applies)
Access is granted based on least privilege and is reviewed at least annually to ensure continued business need Access reviews are documented and include verification of user roles, privileges, and authorization
Multi-factor authentication (MFA) is required for access to company accounts and approved cloud services. Passwords must not be shared, and strong authentication controls are enforced.
LARC manages configuration standards for endpoint devices and key SaaS platforms where feasible
Baseline configurations support consistent security, reliability, and compliance
4.8
LARC maintains a documented change management process for changes that affect security, privacy, or customer information
Changes are reviewed for impact, approved, tested as appropriate, and documented Records are retained for at least 90 days
LARC maintains a documented risk management process that evaluates risks to confidentiality, integrity, and availability Risks are assessed, assigned ownership, tracked, and mitigated through appropriate controls
4.10
LARC provides security awareness training covering acceptable use, data handling, phishing awareness, export control awareness (ITAR/EAR fundamentals, where applicable) and incident reporting. Training occurs at onboarding and periodically thereafter
4.11
LARC performs pre-employment screening appropriate to the role, including CV/resume verification, reference checks, and criminal background checks where permitted.
Personnel with access to export-controlled data are verified as U.S. persons (as defined under ITAR).
4.12
LARC applies physical security measures appropriate to its operating environment
Facilities use controlled access where applicable, and employees are responsible for securing devices and preventing unauthorized physical access.
LARC uses monitoring controls appropriate for an endpoint and SaaS-based environment, including device security alerts, SaaS platform alerts, and user-reported events
Security alerts and logs are reviewed periodically by the Security & Privacy Point of Contact to identify potential incidents.
Logs are retained for at least 90 days and protected from unauthorized access
4.14
LARC maintains an incident management process covering identification, escalation, containment, remediation, and recovery.
Incidents are documented and reviewed. Customers will be notified of applicable data breaches without undue delay and no later than 48 hours after discovery
LARC reviews its security program annually and may engage external reviewers when required Findings are documented and tracked to completion.
LARC maintains a record of third-party providers and evaluates them periodically
Vendors must agree to appropriate data protection and confidentiality obligations
Vendors must not be given access to export-controlled data unless:
Authorized under applicable regulations
Approved by the customer
LARC uses secure, encrypted storage and backup methods where applicable Data is deleted when no longer required unless retention is required by law or contract.
Devices are sanitized in accordance with recognized standards (e.g., NIST SP 800-88).
LARC maintains business continuity practices appropriate to its cloud-based environment, including reliance on provider redundancy and periodic verification of recovery capabilities
Security & Privacy Point of Contact oversees policy, risk, and incidents.
Management ensures resources and enforcement.
Employees follow policy and report incidents
Exceptions must be documented, approved, and reviewed annually.
7. Enforcement
Failure to comply may result in disciplinary action, access removal, or contract termination.
