Access Control Policy

Last Reviewed: 1 March 2025
Version: 1.0
- Purpose
The purpose of this Access Control Policy is to establish guidelines for granting, managing, and revoking access to Dang Lifestyle’s physical premises, IT systems, and sensitive information. This ensures that only authorized personnel can access specific resources, reducing security risks such as data breaches, theft, and unauthorized modifications. - Scope
This policy applies to:
a. All Dang Lifestyle employees, contractors, third-party vendors, and partners with access to company systems or facilities.
b. Physical access to offices, warehouses, fulfillment centers, and restricted areas.
c. Digital access to company networks, databases, applications, and sensitive information. - Access Control Principles
Dang Lifestyle follows these key principles to enforce access control:
a. Need-to-Know Basis: Access is granted based on job roles and responsibilities. Employees receive only the access necessary to perform their duties.
b. Least Privilege Principle: Users are assigned the minimum level of access required to perform their tasks.
c. Role-Based Access Control (RBAC): Permissions are assigned based on job function (e.g., Sales, HR, IT, Finance).
d. Multi-Factor Authentication (MFA): Sensitive systems require an extra layer of authentication (e.g., password + one-time code).
e. Regular Access Reviews: User access is reviewed quarterly to ensure compliance and remove unnecessary permissions.
f. Immediate Revocation: Access is revoked immediately when employees exit the company or change roles. - Physical Access Control
To protect Dang Lifestyle’s facilities and inventory, the following measures apply:
Office & Warehouse Access: Only authorized personnel can enter restricted areas. Employee ID badges must be worn at all times.
Visitor Management: Visitors must be pre-registered, sign in at reception, and be escorted by an authorized employee.
Surveillance Monitoring: CCTV cameras monitor entry/exit points for security and compliance purposes. - System & Data Access Control
Dang Lifestyle enforces strict digital security controls, including:
User Account Management:
• Employees are issued unique login credentials—sharing of credentials is strictly prohibited.
• Temporary accounts for contractors/vendors are time-restricted and deactivated after project completion.
Password & Authentication:
• Passwords must be at least 6 characters long, including uppercase, lowercase, numbers, and symbols.
• Multi-Factor Authentication (MFA) is mandatory for accessing sensitive company data.
Data Access Restrictions:
•HR & Payroll Data: Accessible only to HR and Finance personnel.
•Customer & Sales Data: Restricted to Sales, Marketing, and authorized management.
•Financial Records & Reports: Accessible only to Finance and executive leadership.
Network & Device Security:
• Company Wi-Fi requires authentication—guest access is on a separate network.
• USB drives and external storage devices are restricted to prevent data leaks.
• Remote access is granted only through VPNs with secure encryption. - Access Review & Auditing
Regular Audits:
• System and physical access logs are reviewed quarterly for security risks.
• Any unauthorized access attempts are investigated immediately.
Employee Role Changes:
• Access permissions are updated when employees change job roles.
• Former employees and third-party vendors must return keycards, devices, and access credentials immediately upon exit. - Violation & Enforcement
Policy Violations Include:
• Sharing passwords or unauthorized access to restricted areas.
• Attempting to bypass security controls.
• Granting access to unauthorized individuals.
Consequences:
• First offense: Formal warning & retraining.
• Second offense: Suspension of access & disciplinary action.
• Third offense: Termination & potential legal action. - Review & Updates
This policy will be reviewed annually or updated based on changes in security risks, business needs, or regulatory requirements. - Contact Information
For any access-related issues, report to:
jo**@***********le.co
08020728741