Skip to main content

AG Mortgage Bank PLC

Information Transfer Policy

1Introduction

To meet the AG Mortgage Bank business objectives and ensure confidentiality, integrity and availability of the bank’s information, an information transfer policy, procedure and agreement has been defined and established.

There are many occasions when information is transferred between AG Mortgage Bank and third-party service providers or other external interested parties over the network, this shall be done using the official email platform.

In every transfer, there is a risk that the information may be lost, misappropriated, or accidentally released. For legal reasons such as confidentiality or data protection, and to maintain the trust of our service users and partners, it is essential that the transfer is performed in a way that adequately protects the information.

1.1Purpose

This document outlines the policy, procedure and transfer agreement to ensure the minimum-security requirements for information transfer within the Bank. This information refers to textual information (e.g., word processed documents, reports, attachments and spreadsheets).

1.2Scope

This policy applies to all AG Mortgage Bank staff and any third party that processes the Bank’s information.

2Information Transfer Policy and Procedure

To prevent AG Mortgage Bank confidential and restricted information from being seen by unauthorized individuals during transfer, the following procedures have been put in place:

  • Zoho mail has been deployed as the approved electronic medium for the transfer of information within and outside the AG Mortgage Bank.
  • All information transferred using the Bank’s email is secured through the Zoho mail encryption, transport layer security and information rights management.

AG Mortgage Bank recognizes its responsibility to process its information correctly and in line with all legal, regulatory, and internal policy requirements. The following policy has been put in place to ensure appropriate control of information transfer in the Bank:

  • All information transferred must be done using an approved secure transfer process.
  • All information must be transferred using the Bank’s official email.
  • All staff must not assume that the information requester is authorized or legally entitled to have it. If in doubt, staff should confirm with their line manager.
  • Before any information is transferred, staff must ensure that the transfer is necessary and is legal.
  • You must not release the Bank’s confidential and restricted information to unauthorized persons. This can open the Bank to legal sanction or litigation.
  • In cases where removable devices are used for information transfer, it must be scanned for viruses and malware.
  • On occasions, when information may need to be transferred in person, careful consideration must be given to all the potential security and confidentiality risks involved. This must be done in line with this policy.

3Information Transfer Agreement

On a very rare occasion, AG Mortgage Bank might want to share business information with third parties and vice versa. The following terms of agreement have been put in place to ensure the secure transfer of information between AG Mortgage Bank and third parties while using email:

  • The recipient agrees to comply fully with procedural controls specified by the Transferor which are designed to secure the confidential information during its transfer and prevent its disclosure to any third party.
  • A confidentiality agreement or non-disclosure agreement must be established between the Bank and the recipient before confidential information is transferred. The agreement should also include security controls to be implemented by both parties to ensure the confidentiality, integrity, and availability of the information.
  • The agreement does not grant the Recipient any license, with respect to intellectual property rights of the Transferor except, the right to make reasonable copies of the confidential information solely for the purpose of the engagement.

The Information Security Manager shall verify compliance to this policy through various methods, including but not limited to, periodic walk-throughs, business tool reports, internal and external audits, and feedback to the policy owner.

4Physical Media Transfer Policy

The primary area of concern is the secure management of media to protect sensitive or personal information from intentional or accidental exposure or misuse. The following shall be implemented:

  • All staff handling bank-sensitive data must get approval for all physical media data transfers from their Line Manager and ISMS Manager.
  • Data (sensitive or not) should only be transferred when it is strictly necessary for the effective running of AG Mortgage Bank’s business operations.
  • When dealing with third parties, consider whether any data-sharing agreements or contracts are in place that cover the transfer of that data.
  • A check must be conducted to ascertain whether there are any stipulations in place regarding the method of transfer that should be used.
  • For all transfers of information containing personal or sensitive data, it is essential that you appropriately establish the identity and authorization of the recipient.
  • Risks to information and the media on which it resides shall be securely managed throughout the lifecycle of procurement, use, storage, and disposition.
  • Erasure of information from media shall be done by approved standards and secure disposal of media shall be followed using documented procedures.
  • Physical media shall be handled according to the highest level of sensitivity of contained information.
  • Media shall be protected from theft or tampering.
  • Where there is re-assignment or destruction of hardware and media, inventory records shall be kept current.
  • A signature must be obtained at each point in the process where the physical media changes hands.
  • Legal advice should be sought to ensure compliance before media containing encrypted information or cryptographic controls are moved across jurisdictional borders.
  • If physical media is lost or damaged in any way during the transfer process, the Chief Information Security Officer must be informed.
  • Physical media must be signed for by an authorized individual only.

5Physical Media Transfer Procedure

5.1Incoming Physical Media

  • On getting to the Bank, the security team will run security checks on the incoming package.
  • All incoming physical media should be recorded after the security check has been conducted.
  • Any physical media postmarked for the attention of an individual will be passed directly to the relevant member of staff unopened. Any post marked as ‘confidential and restricted’ will be passed unopened to the Head of the IT Department or the ISMS Manager.
  • More attention should be paid to Confidential and Restricted incoming physical media.

5.2Outgoing Post

  • All outgoing physical media must follow this policy.
  • Any Confidential and Restricted physical media must be marked as such.
  • Only approved couriers will be used to transfer physical media if the need arises.
  • Physical media containing data will be protected against unauthorized access, misuse or corruption during transfer.
  • For encrypted data, the encryption key should only be released after the package has arrived and been signed for.

All logs of physical media transferred from the Bank must be captured and maintained.