Policy Hub Official Speaxa Policy
SPEAXA LEGAL HANDBOOK
INFORMATION SECURITY, CYBERSECURITY & BUSINESS CONTINUITY POLICY
SPEAXA LEGAL & COMPLIANCE HANDBOOK
PART XII
INFORMATION SECURITY, CYBERSECURITY & BUSINESS CONTINUITY POLICY

Applicable to:

SPEAXA Website

SPEAXA Android Application

SPEAXA iOS Application

Learning Management System (LMS)

Student Portal

Parent Portal

Teacher Portal

Administrative Dashboard

Internal Information Systems

Cloud Infrastructure

Employees, Teachers, Vendors and Authorised Service Providers

1. PURPOSE

SPEAXA recognises that information security is fundamental to maintaining the trust of students, parents, teachers and institutional partners.

This Policy establishes the principles for protecting:

Information Assets.

Digital Infrastructure.

Personal Information.

Academic Records.

Intellectual Property.

Software Systems.

Business Operations.

The objectives are to:

Preserve confidentiality.

Maintain integrity.

Ensure availability.

Minimise cyber risks.

Strengthen operational resilience.

Support uninterrupted educational services.

2. INFORMATION SECURITY PRINCIPLES

SPEAXA shall make reasonable efforts to ensure that information is:

Confidential.

Accurate.

Complete.

Available when required.

Protected against unauthorised access.

Protected against unauthorised disclosure.

Protected against unauthorised alteration.

Protected against accidental loss or destruction.

3. INFORMATION ASSETS

Information assets include, but are not limited to:

Student Records.

Parent Records.

Teacher Records.

Lesson Plans.

Assessments.

Question Banks.

Recordings.

Source Code.

Databases.

Cloud Infrastructure.

Learning Analytics.

Artificial Intelligence Models.

Business Documents.

Financial Information.

Intellectual Property.

Internal SOPs.

Contracts.

Vendor Information.

4. ACCESS CONTROL

Access to SPEAXA systems shall be based on the principle of least privilege.

Accordingly:

Users shall receive only the access reasonably necessary for their role.

Administrative access shall be limited to authorised personnel.

Access rights shall be reviewed periodically.

Access may be modified or revoked when roles change or engagement ends.

5. PASSWORD & ACCOUNT SECURITY

Users are responsible for protecting their accounts.

Accordingly, users should:

Use strong passwords.

Keep passwords confidential.

Avoid password reuse across services.

Change passwords if compromise is suspected.

Sign out from shared devices.

Enable additional security features where available.

SPEAXA may require password resets or other authentication measures where reasonably necessary to protect accounts.

6. MULTI-FACTOR AUTHENTICATION

Where supported, SPEAXA may implement additional authentication measures, including multi-factor authentication (MFA), particularly for administrative or sensitive accounts.

7. ENCRYPTION

SPEAXA aims to protect sensitive information through appropriate security measures, which may include:

Encrypted data transmission.

Encrypted storage where appropriate.

Secure authentication mechanisms.

Protected backups.

The specific security controls may evolve with technology and operational requirements.

8. CYBERSECURITY MONITORING

SPEAXA may monitor its systems to:

Detect suspicious activity.

Identify attempted unauthorised access.

Investigate security incidents.

Improve system security.

Maintain platform integrity.

Monitoring shall be conducted in accordance with applicable law and SPEAXA's privacy commitments.

9. SECURITY INCIDENT RESPONSE

Where a cybersecurity incident is identified, SPEAXA may:

Activate its incident response procedures.

Contain the incident.

Investigate the cause.

Restore affected services.

Preserve relevant evidence.

Notify affected users or authorities where required by applicable law.

Implement corrective and preventive measures.

10. DATA BACKUP & RECOVERY

To support continuity of operations, SPEAXA may maintain backup processes for critical information and systems.

Backup procedures are intended to assist in recovery following events such as:

Hardware failure.

Software failure.

Human error.

Cybersecurity incidents.

Natural disasters.

Other operational disruptions.

11. BUSINESS CONTINUITY

SPEAXA will make reasonable efforts to maintain continuity of educational services during disruptions.

Business continuity measures may include:

Alternative teaching arrangements.

Cloud-based infrastructure.

Backup systems.

Remote operational capability.

Disaster recovery planning.

Service restoration procedures.

Despite these efforts, uninterrupted availability cannot be guaranteed under all circumstances.

12. THIRD-PARTY SECURITY

Where SPEAXA engages third-party vendors or service providers, it may take reasonable steps to ensure that they maintain appropriate security standards consistent with the services they provide.

Third-party providers remain responsible for their own systems and services.

13. EMPLOYEE & TEACHER RESPONSIBILITIES

Every employee, teacher and authorised user shall:

Protect confidential information.

Follow security procedures.

Report suspected incidents promptly.

Avoid sharing credentials.

Use authorised software and systems.

Exercise caution regarding suspicious emails, messages or links.

14. PHISHING & SOCIAL ENGINEERING

Users should remain vigilant against attempts to obtain confidential information through deception.

Users are encouraged to report suspected phishing, impersonation or other fraudulent communications through SPEAXA's official support channels.

15. SOFTWARE SECURITY

SPEAXA seeks to maintain secure software development and operational practices, which may include:

Security reviews.

Testing procedures.

Updates and maintenance.

Vulnerability management.

Change management.

Security practices will evolve in line with technological developments and business requirements.

16. SECURITY AUDITS

SPEAXA may periodically conduct internal or external reviews of its security practices to:

Identify risks.

Improve controls.

Verify compliance with internal standards.

Enhance operational resilience.

17. POLICY REVIEW

This Policy may be reviewed and updated periodically to reflect:

Emerging cybersecurity threats.

Technological advancements.

Regulatory developments.

Operational improvements.

Industry best practices.

18. REPORTING SECURITY CONCERNS

Users who become aware of a potential security issue are encouraged to report it promptly through SPEAXA's officially designated support or security contact channels.

Reports made in good faith will be reviewed appropriately.

19. ACKNOWLEDGEMENT

By accessing or using SPEAXA's systems, users acknowledge that:

They have read and understood this Policy.

They agree to follow reasonable security practices.

They understand their role in protecting information and systems.

They will cooperate in the event of a security investigation where appropriate.

20. SPEAXA'S COMMITMENT

SPEAXA is committed to fostering a secure, resilient and trustworthy educational ecosystem by continually improving its information security, cybersecurity and business continuity practices.

While no technology environment can eliminate all risks, SPEAXA will make reasonable efforts to safeguard its users, information assets and educational services in accordance with applicable laws and recognised security principles.