Skip to main content

Security & Privacy 6.0

Page 1


LARC Security Posture Summary

Overview

LARC operates a secure, cloud-first environment with no internally hosted servers or applications

Access Control

Least privilege access, MFA enforced, and annual access reviews.

Data Protection

Data stored in Google Workspace, Dropbox, Digify, and SolidWorks with encryption at rest and in transit.

Endpoint Security

Company-managed macOS and iOS devices with full-disk encryption and automatic updates.

Monitoring & Incident Response

Security alerts monitored; incidents handled via documented response with 48-hour notification.

Vendor Management

Approved vendors include Google Workspace, Dropbox, Digify, and SolidWorks; reviewed periodically.

Backup & Recovery

Cloud-based redundancy with periodic recovery verification.

Physical Security

Controlled access to devices and secure handling practices

Governance: Aligned with ISO 27001 principles; annual assessments and designated security contact.

LARC Security & Privacy Policy (V6.0)

1. Purpose

This policy defines the security and privacy requirements used by Logistics Advanced Research Center (“LARC”) to protect company systems, company data, and customer-provided information, including exportcontrolled data (e.g., ITAR-controlled technical data). It establishes baseline security controls appropriate to LARC’s operating environment and supports customer and partner security expectations.

2. Scope

This policy applies to all LARC employees, contractors, and authorized users, and covers company-managed devices (Apple macOS laptops and iPhones), company accounts (e.g., Gmail), and approved cloud and SaaS services used to store or share business files (e.g., Dropbox, Digify, SolidWorks). LARC does not operate company-managed servers or internally hosted application platforms; the security program is endpoint- and cloud-service–focused and proportionate to this environment This policy also applies to the handling of:

Controlled Unclassified Information (CUI), if applicable

Export-controlled data subject to ITAR or EAR

3. Operating Environment

LARC’s environment consists of company-managed Apple macOS laptops and iPhones, Gmail accounts, and approved SaaS platforms including Dropbox, Digify, and SolidWorks. There are no internally hosted servers, applications, or software development environments. Controls and assessments are implemented proportionately to this model. Where export-controlled data is handled, additional access, storage, and transmission controls are applied as defined in this policy

4. Policy Requirements

4.1 Security & Privacy Governance

LARC maintains a documented security and privacy program aligned with accepted industry standards (including principles from ISO/IEC 27001) and reviews policies at least annually LARC designates a Security & Privacy Point of Contact responsible for program oversight, incident coordination, risk management, export control compliance coordination (e.g., ITAR data handling) and responding to customer security inquiries

4.2 Annual Self-Assessment and Continuous Improvement

LARC performs an annual, risk-based security self-assessment to evaluate the effectiveness of controls and alignment with industry best practices

At minimum, the assessment reviews endpoint security configuration, vulnerability and patching effectiveness, access control practices, secure handling of customer-provided materials (e.g., CAD files), incident readiness, and security awareness practices

Findings and improvement actions are documented, tracked, and used to update controls and procedures as needed

4.3 Endpoint Security

LARC enforces baseline security requirements for company-managed Apple devices, including supported OS versions, automatic updates, strong authentication, device auto-lock, and full-disk encryption (FileVault on macOS and native encryption on iOS)

Built-in Apple security protections such as Gatekeeper and System Integrity Protection must remain enabled. Endpoint protection and monitoring are used as appropriate for an endpoint-only environment, and users must not disable system security controls

4.4 Approved Software and Application Management

LARC requires the use of vendor-supported software and prohibits unauthorized or pirated software Users may install software only from trusted sources (e.g., App Store or approved vendors), and browser extensions are limited to those required for business use.

Only approved software may be used to access or store export-controlled data

Unauthorized cloud services or plugins are prohibited for such data

4.5 Data Handling, Storage, and Classification

Company and customer files must be stored only on company-approved devices and approved cloud or SaaS services Sensitive customer materials (e g , CAD files) must not be copied to personal devices, removable media, or unapproved services

Customer-provided files must be used only for approved business purposes, shared externally only when authorized, and deleted or archived securely when no longer required.

Data is classified based on sensitivity (e g , confidential, internal, public, export-controlled), and appropriate controls are applied to protect company and customer information based on classification Export-Controlled Data Requirements:

Export-Controlled Data Requirements:

Stored only in approved systems with access restricted to U S persons (if ITAR applies)

Not stored on personal devices or unapproved platforms

Not transmitted outside the United States without proper authorization

Shared strictly on a need-to-know basis

4.6 Access Control

LARC limits access to sensitive or confidential information to authorized users with a legitimate business need

Access requires documented approval by the data owner.

Access to export-controlled data is limited to:

Authorized personnel

U S persons (where ITAR applies)

Access is granted based on least privilege and is reviewed at least annually to ensure continued business need Access reviews are documented and include verification of user roles, privileges, and authorization

Multi-factor authentication (MFA) is required for access to company accounts and approved cloud services. Passwords must not be shared, and strong authentication controls are enforced.

4.7 Configuration Management

LARC manages configuration standards for endpoint devices and key SaaS platforms where feasible

Baseline configurations support consistent security, reliability, and compliance

4.8

Change Management

LARC maintains a documented change management process for changes that affect security, privacy, or customer information

Changes are reviewed for impact, approved, tested as appropriate, and documented Records are retained for at least 90 days

4.9 Risk Management

LARC maintains a documented risk management process that evaluates risks to confidentiality, integrity, and availability Risks are assessed, assigned ownership, tracked, and mitigated through appropriate controls

4.10

Security Training and Awareness

LARC provides security awareness training covering acceptable use, data handling, phishing awareness, export control awareness (ITAR/EAR fundamentals, where applicable) and incident reporting. Training occurs at onboarding and periodically thereafter

4.11

Personnel Security

LARC performs pre-employment screening appropriate to the role, including CV/resume verification, reference checks, and criminal background checks where permitted.

Personnel with access to export-controlled data are verified as U.S. persons (as defined under ITAR).

4.12

Physical Security

LARC applies physical security measures appropriate to its operating environment

Facilities use controlled access where applicable, and employees are responsible for securing devices and preventing unauthorized physical access.

4.13 Logging and Monitoring

LARC uses monitoring controls appropriate for an endpoint and SaaS-based environment, including device security alerts, SaaS platform alerts, and user-reported events

Security alerts and logs are reviewed periodically by the Security & Privacy Point of Contact to identify potential incidents.

Logs are retained for at least 90 days and protected from unauthorized access

4.14

Incident Management

LARC maintains an incident management process covering identification, escalation, containment, remediation, and recovery.

Incidents are documented and reviewed. Customers will be notified of applicable data breaches without undue delay and no later than 48 hours after discovery

4.15 Audits and Remediation

LARC reviews its security program annually and may engage external reviewers when required Findings are documented and tracked to completion.

4.16 Vendor and Third-Party Management

LARC maintains a record of third-party providers and evaluates them periodically

Vendors must agree to appropriate data protection and confidentiality obligations

Vendors must not be given access to export-controlled data unless:

Authorized under applicable regulations

Approved by the customer

4.17 Backup, Recovery, and Data Disposal

LARC uses secure, encrypted storage and backup methods where applicable Data is deleted when no longer required unless retention is required by law or contract.

Devices are sanitized in accordance with recognized standards (e.g., NIST SP 800-88).

LARC maintains business continuity practices appropriate to its cloud-based environment, including reliance on provider redundancy and periodic verification of recovery capabilities

5. Roles & Responsibilities

Security & Privacy Point of Contact oversees policy, risk, and incidents.

Management ensures resources and enforcement.

Employees follow policy and report incidents

6. Exceptions

Exceptions must be documented, approved, and reviewed annually.

7. Enforcement

Failure to comply may result in disciplinary action, access removal, or contract termination.

Turn static files into dynamic content formats.

Create a flipbook
Security & Privacy 6.0 by LARCCRATE - Issuu