Information Security Policy
Contents
INTRODUCTION TO INFORMATION SECURITY
- STANDARD OPERATING PROCEDURES
- PLANNING AND ACCEPTANCE OF INFORMATION SYSTEMS
- PROTECTION FROM MALICIOUS SOFTWARE (MALICIOUS AND MOBILE CODE)
- BACKUPS
- STORAGE MEDIA HANDLING (ELECTRONIC AND PRINTED)
- MONITORING
- NETWORK MANAGEMENT
- INFORMATION SECURITY IN RELATION TO EXTERNAL PROVIDERS
- ANNUAL STATUS AUDIT
- SECURE AREAS
- DOCUMENT AND EQUIPMENT SECURITY
- EQUIPMENT LIFECYCLE MANAGEMENT
- ACCESS TO INFORMATION SYSTEMS
- SOFTWARE
Introduction to Information Security
Definitions :
- The term “Information security” means maintaining the confidentiality, integrity, availability and accessibility of information.
- The term “information” means any element / data processed in the IT systems of PRIMER in the context of its activity.
- The term “Information processing” (elements / data) means any act or set of operations performed with or without the use of automated means on data or sets of data (including personal data), such as collection, recording, organization, structuring, storage, adaptation, modification, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of disclosure, correlation, combination, restriction, erasure, destruction.
- The term “Information Systems” means individual or combinations of hardware and software used by PRIMER to process and share information.
The information processed by PRIMER during its activity is considered an asset of utmost value and therefore every care is taken to protect it as well as the Information Systems that allow PRIMER to process and share the information.
At PRIMER, a Management System has been designed and is implemented with the aim of effectively managing and continuously improving the level of Information Security.
In the design of this Management System, all legislative, regulatory and contractual obligations that the Management of PRIMER is committed to complying with are taken into account.
The Management of PRIMER declares its commitment to provide all the resources required for the effective implementation of the Information Security Management System and the continuous improvement of its effectiveness.
PRIMER’s performance regarding Information Security is continuously monitored by the Management in the context of the implementation of the Management System, through the establishment of efficiency and effectiveness indicators of the processes and corresponding objective, measurable targets for Information Security.
This Information Security Policy is binding on all PRIMER personnel and associates whose activity may affect PRIMER’s performance regarding Information Security.
The Management of PRIMER has assigned the IS Manager (Υπ. ΣΔ) to ensure that this Policy is complied with in every aspect of the activity and that every member of PRIMER’s staff and external associates are informed and committed to comply with the said Policy.
The IS Manager is responsible for monitoring the level of compliance with the provisions of this Policy and reporting to the Management any incident (actual or potential) of breach of the Policy or information security.
To maintain the principles of this Information Security Policy, the Procedures and Instructions of the Management System must be taken into account, as well as the Job Descriptions where the responsibilities of those involved in information security are defined.
General Principles
General Points
- Information Security is everyone’s responsibility.
- The IT system of PRIMER is provided exclusively for use related to the activities of PRIMER.
- Use of the PRIMER IT system for personal reasons (including e-mail and the internet) is prohibited. There should be no expectations of privacy when an employee or associate uses the PRIMER IT system.
- PRIMER reserves the right to monitor every aspect of the IT system in order to protect its legitimate business rights. Information collected from any monitoring may be used to initiate or support disciplinary proceedings.
- Breach of the terms of this policy results in disciplinary actions which, depending on the severity of the breach, may include:-
- Oral warning / reprimand from the Management
- Formal written warning / reprimand for a serious offense
- Dismissal due to a serious offense
- Criminal proceedings
- Civil proceedings for the recovery of damages
- On the internet, information and material are circulated which is often described by the term “material which others may find offensive” and is often used by malicious elements to trap internet users with the ultimate aim of infecting systems with malicious software. This term includes but is not limited to:–Pornographic or sexual material
-Racist, sexist or homophobic material
-References of religious / political content
-Unsightly / antisocial material (such as vandalism, exercise of violence on people or animals) Accessing websites with this type of content is strictly prohibited through the network or using equipment belonging to the PRIMER IT system (it is a high-risk action for information security)
Compliance Actions
- Prudent, careful and reasonable use of IT systems.
- Immediate reporting of any incident or suspicion of an incident related to information security or facilities to the IS Manager.
Principles of proper management of Operations and Communications
1. Standard Operating Procedures
General Points
- At PRIMER, standard operating procedures are applied for the daily maintenance of its IT systems and infrastructures in order to ensure the highest possible availability and performance of these systems.
- Changes to PRIMER’s IT systems are implemented in a controlled manner for effective change management.
- The development and testing environments of the systems and applications are always kept separate from the live operational environment to reduce the risk of accidental changes or unauthorized access.
Compliance Actions
- Issuance and application of appropriate standard operating procedures / instructions.
- Evaluation of all significant changes to IT systems and core infrastructure for their impact on information security (an integral part of standard risk assessment).
- Separation of the operational environment and the development / testing environment with appropriate control means, including the following:
- Execution on separate computers, domains and networks.
- Different usernames and passwords.
- Use of dummy data and information during tests – checks
- Assignment to executives who are capable of evaluating and testing operating systems.
2. Planning and Acceptance of Information Systems
General Points
- All constituent parts and characteristics of the equipment and infrastructure of PRIMER’s IT systems are taken into account when preparing PRIMER’s annual budget and the necessary resources are provided for their procurement, maintenance, replacement so that they always adapt to the requirements based on the workload and operational needs of the company.
- As significant constituent parts and characteristics of the equipment and infrastructure of IT systems, the following are indicatively mentioned:
- File
- Replication
- Domain
- Web
- Printers.
- Networks.
- Support equipment (CCTV, Access Control, Server room, etc.)
Compliance Actions
- All departments must inform the IS Manager of the requirements for new equipment / systems or upgrades, or improvements required for existing systems.
- For the procurement of any new equipment / system, the relevant procedures of the Procurement and Materials Management Department are applied in consultation with the IS Manager.
- New IT systems, service upgrades, patches, etc. must undergo an appropriate check by the IS Manager before their acceptance and implementation in a live environment.
- Acceptance criteria must be clearly defined, recorded, and agreed with the supplier.
- Significant system upgrades must be thoroughly tested alongside the existing system in a secure testing environment.
-
Protection from Malicious Software (Malicious and Mobile Code)
General Points
- At PRIMER, all appropriate measures are taken to protect IT systems and infrastructures as well as the information and data they process, against Malicious Software.
- The operation of IT systems is always monitored by activated, appropriate and updated antivirus software on all servers and computers.
- In order to prevent malicious software, appropriate access controls are performed (e.g. Administrator, user rights) to prevent software installation by all users.
- Malicious Software (Malicious and Mobile Code) appears in new technologies and applications which are often found on websites, in emails, and include (indicatively mentioned):
- Activex.
- Java.
- Javascript.
- VBScript.
- Macros.
- HTTPS.
- HTML.
Compliance Actions
- PRIMER’s staff and external associates have an obligation:
- not to allow the occurrence of situations from which an infection of the PRIMER IT system by Malicious Software may originate, by faithfully applying the relevant standard operating Procedures / Instructions
- in case they detect or suspect an infection by Malicious Software in the IT system or on a storage medium of PRIMER, they must immediately inform the IS Manager.
- Software patches are appropriately applied to all software on the organization’s network and there should be a complete record of which patches have been applied and when.
- Requests for software installation should only be accepted when there is technical confirmation from the IS Manager.
- Appropriate and updated anti-malware software must be installed at appropriate points on the network (fixed and mobile equipment) and on visitor equipment that may be connected to the company’s network.
-
Backups
General Points
- At PRIMER, regular backups of the information processed by the company are taken, to ensure that the operation can recover effectively after a disaster, media failure or error.
- Backups are taken based on a defined frequency and full documentation of taking backup copies is ensured, which are kept in a safe place and off-site.
- Any 3rd party storing business information must also be required to ensure that the information is stored in backups.
Compliance Actions
- A file of all written documentation of taking backups, a copy of the recovery procedure as well as a full record of the information of the entire system on a backup hard disk is kept at all times in a secure location off PRIMER’s premises with an additional copy on the main premises.
- Ensuring that the remote location is far enough away to avoid being affected by any disaster occurring in the main premises.
- Execution of regular recovery exercises of stored information from the backup media to ensure the reliability of the media and the storage process (at least annually and whenever else deemed necessary by the IS Manager, e.g. after a significant change in the system or after a security incident, keeping a record where the result of the exercise is mentioned).
5. Storage Media Handling (electronic and printed)
General Points
- The electronic storage media allowed to be connected to the PRIMER network are:
- Computer hard disks (internal and external)
- CD
- DVD
- Optical Disks
- Digital Cameras
- Removable computer storage media (e.g. disks) are protected to prevent damage, theft or unauthorized access.
- Electronic storage media that are transported are protected from unauthorized access, misuse or interruption.
- System documentation (documents and files) is protected from unauthorized access. Examples of protected documents include, but are not limited to:
- Files and documentation relating to the applications and programs installed on the network
- Standard operating Procedures / Instructions and their accompanying documents / forms
- Processes
- Files and documentation relating to the network structure and the organization of databases, folders and other network elements
- Files and documentation relating to authorization details and access rights
Compliance Actions
- Access to electronic storage media and Management System documents is strictly controlled only for appropriately authorized persons.
- Irreversible deletion of any information from electronic storage media that is transported outside the Company for repair and keeping a file showing the date and time of dispatch / receipt, the persons responsible for dispatch / receipt, the destination and the reason for the transfer. If this is not possible, the storage media are not transported outside the Company for repair and are replaced with others after being destroyed mechanically (drill) and a destruction protocol is kept.
- A file of all written documentation of taking backups, a copy of the recovery procedure as well as a full record of the information of the entire system on a backup hard disk is kept at all times in a secure location off PRIMER’s premises with an additional copy on the main premises.
- For the disposal of useless / withdrawn documents, PRIMER’s recycling bin is used after prior destruction with a shredding machine (shredder) of each document that is discarded and a destruction protocol is kept.
6. Monitoring
General Points
- At PRIMER, monitoring techniques are applied to achieve security and to facilitate the investigation of incidents. In this case, the audit logs contain at least the following information:
- System identity.
- Username.
- Successful/Unsuccessful login.
- Successful/Unsuccessful logout.
- Unauthorized access.
- Changes to system configurations.
- Use of privileged accounts (e.g. account management, policy changes).
Compliance Actions
- Maintaining audit logs for at least 6 months that record exceptions and other security-related incidents.
- Protecting audit logs from unauthorized access.
- Removing the ability of system administrators to disable audit logs.
- Keeping an activity log for operational staff and system administrators that includes:
- Back-up timings and details (date / time / user) of the exchange of backup tapes.
- System event start and System finish times and details of involved users.
- System errors (description, date, time) and corrective actions taken.
- Regular checking of the proper maintenance of audit logs by an authorized person (at least monthly, keeping a record where the results of the check are mentioned as well as whether there were incidents or near-miss information security incidents).
- Annual synchronization of all computer clocks with the GSI time source to ensure the accuracy of all system audit logs and the investigation of any security incidents.
7. Network Management
General Points
- At PRIMER, network management is considered a critical factor for smooth and secure operation.
- Connections to the PRIMER network are made in a controlled manner.
- Wireless networks that may affect PRIMER’s performance in Information Security operate with increased access control only for PRIMER staff and appropriately authorized external associates.
Compliance Actions
- Issuance and application of procedures / instructions with clear responsibilities and actions for the management and proper use of fixed and mobile equipment.
- Documentation of the architecture and all parts of the network and the equipment elements that make up the IT system and storage of the documentation with configuration settings of all hardware and software parts that make up the network (list that is updated when assets are added or removed).
- The IT system is protected by a UPS to reduce the risk of damage or loss of information from power supply voltage disturbances of the electricity network.
- Cables that carry data or support important information services are protected from interception or damage.
- Power cables are separated during routing from network cables to avoid interference.
- Network cables are protected by a routing channel and routes through areas where there is free access are avoided.
- Use of encryption methods and techniques to protect data transmitted over the network.
- Ensuring that all hosts have a satisfactory level of security.
- Re-evaluation on a 6-monthly basis of the network services of the operating systems and deactivation of all services that are not needed.
- Use of encryption in wireless networks to avoid information interruption (WPA2 minimum).
8. Information Security in relation to external providers
General Points
- PRIMER may turn to external providers to cover needs for equipment, goods or services that may affect the security of the information it manages (e.g. IT support, legal support, IT and telecommunications equipment, security, postal services, space rental).
- Before any collaboration of this type, PRIMER defines the requirements so that the risk to information security from the external provider’s access to the information is mitigated.
- These requirements are agreed with the external provider and their satisfaction is monitored within the framework of collaboration agreements through which the following are defined:
- The concept of security (availability, accessibility, integrity, confidentiality), the security requirements and the level of security that must be ensured (classification)
- The exact characteristics of the equipment / software / services and the acceptance criteria
- The information to which the external provider will have access and the type, methodology, duration of access including requirements for remote access
- The obligation of the external provider to protect PRIMER’s information to which they have access and to comply with the provisions of this Policy and the security requirements arising from it
- The rules of acceptable and unacceptable use of information
- The risk management measures that the external provider must take and how the taking of these measures is enforced
- The checks that must be carried out to verify at any time the maintenance of information security, including PRIMER’s right to conduct inspections of the processes and control measures applied for the procurement / collaboration
- The procedures for handling incidents of loss of information security and provisions for dealing with emergencies, with emphasis on the requirements of the legislation regarding notifications / information and cooperation between company and supplier in emergency situations or handling of information security incidents
- The procedure for handling the case of delivery by the external provider of a product or service not complying with the agreed requirements
- The requirements for the infrastructures and facilities of PRIMER that should be utilized during the procurement / collaboration as well as the training, knowledge and experience requirements that the PRIMER personnel involved in the implementation must meet
- The identity details of the external provider’s personnel who are authorized to have access to information or the personnel authorization requirements and any requirements for verifying studies, knowledge, previous work experience, conduct
- Provisions regarding the possibility of the external provider to subcontract to another party a part or the whole of the procurement / provision of the service and the conditions that will apply for this.
- The requirements for information exchange and provisions for maintaining information security during transport
- Legislative and regulatory requirements (data protection, intellectual property protection) and description of how the requirements are met
- The acceptance of the external provider to submit, if required, periodic reports regarding the effectiveness of the measures
Compliance Actions
- Conclusion of collaboration agreements with suppliers of products and services that affect PRIMER’s performance regarding information security.
9. Annual Status Audit
General Points
- During the activity of PRIMER, the IT system, the adequacy of resources and technical and organizational measures to deal with risks and generally the adequacy and efficiency of the system to support the company’s activities, are regularly checked and adjusted accordingly.
Compliance Actions
- On an annual basis, an internal audit of the status of all IT systems and infrastructures of the organization is conducted under the responsibility of the IS Manager, which includes, but is not limited to, the following:
- A full penetration test
- A network summary that will identify all IP-addressed devices.
- A network analysis, including exploitable switches and gateways.
- Vulnerability analysis, including patch levels, insecure passwords and services used.
- Exploitation analysis.
- A detailed report with suggestions for improvement.
10. Secure Areas
General Points
- The Management of PRIMER takes special care for the security of the premises housing the company’s activities. The appropriate level of protection for the security of the premises is determined through extensive risk assessment.
- The care for protection against unauthorized access of individuals to the premises starts from the offices housing PRIMER and extends to the entire building by assessing the vulnerability of the building and the perimeter as well as the location of the building.
Compliance Actions
- Issuance and application of procedures / instructions with clear responsibilities and actions for the security of PRIMER’s premises and for the management of access to the premises.
- The building has suitable access control mechanisms that include the following:
- Locked doors and windows outside working hours
- Installation of an intrusion detection and alarm system that is activated outside working hours
- Installation of a closed-circuit television (CCTV) system in all common areas of PRIMER except the corridors leading to toilets / changing rooms / staff rest areas.
- Installation of a disaster protection system (e.g. fire, flood, vandalism)
- Coverage with Private Insurance for damage from incidents of unauthorized access of individuals to the premises
- Keeping an entry – exit log for each person in protected areas (e.g. server room)
- Every visitor to protected areas of PRIMER is recorded in the visitor’s book, from arrival to departure and throughout the duration of their visit is supervised by an employee of the organization who is mentioned in the visitor’s book.
- The keys to all protected areas and areas that have IT system equipment are kept centrally by the IS Manager.
- Staying of staff, external associates or visitors in PRIMER’s premises outside working hours is prohibited without the approval of the IS Manager or the head of the department where the employee belongs or with which the external associate collaborates.
11. Document and Equipment Security
General Points
- The Management of PRIMER takes special care for the security of documents and equipment through which information is processed. The appropriate level of protection for the security of documents and equipment is determined through extensive risk assessment.
- To allow access to documents or equipment used for processing information, granting appropriate authorization and/or classifying the level of protection that information should enjoy (classification) is required.
Compliance Actions
- Documents in an open office are protected depending on the protection provided by the building and through appropriate measures including:
- Filing cabinets that are locked with keys kept away from the cabinets.
- Locked safes.
- Storage in a Secure Area with access control.
- For the disposal of useless / withdrawn documents, PRIMER’s recycling bin is used after prior destruction with a shredding machine (shredder) of each document that is discarded and a destruction protocol is kept.
- The surfaces of desks and other furniture of the staff’s workstations are kept absolutely free of any document when not in use by the authorized employee for each workstation (clean desk).
- The screens of the electronic computers of the staff’s workstations are deactivated within a maximum of 3 min when not in use (screen saver setting: 3 min with a request to enter username / password).
- All general computer equipment is located in suitable positions / spaces that provide protection from:
- environmental hazards (e.g. heat, fire, smoke, water and dust)
- risk of theft
- risk from visual contact or access by unauthorized persons.
- All information is stored in folders on the network server as designed so that it is easy to retrieve in case of loss due to failure, error, malfunction or failure etc. through the backup process.
- Documentation of the architecture and all parts of the network and the equipment elements that make up the IT system and storage of the documentation with configuration settings of all hardware and software parts that make up the network (list that is updated when assets are added or removed).
- The IT system is protected by a UPS to reduce the risk of damage or loss of information from power supply voltage disturbances of the electricity network.
- Cables that carry data or support important information services are protected from interception or damage.
- Power cables are separated during their routing from network cables to avoid interference.
- Network cables are protected by a routing channel and routes through areas where there is free access are avoided.
-
Equipment Lifecycle Management
General Points
- The Management of PRIMER in collaboration with the IS Manager and equipment suppliers ensure that all PRIMER equipment is maintained in accordance with the manufacturer’s instructions and any internal procedures to ensure it remains in excellent condition.
Compliance Actions
- Keeping a file with the history of the equipment so that when the equipment ages, decisions can be made regarding the appropriate time it should be replaced. Under the responsibility of the IS Manager, it is ensured that:
- The requirements for providing a warranty of good operation and technical support are defined in the equipment and software procurement agreements.
- The frequency of checks / maintenance is defined, the necessary related tasks are described and implemented consistently.
- A copy of the manufacturers’ instructions for each equipment is kept (available to support staff for use when repairs are scheduled and executed)
- A detailed record of check / maintenance / restoration actions is kept and details of interruption errors and required / implemented actions are recorded.
- An appropriate call out procedure is applied in case of failure, malfunction, breakdown, based on which only authorized technicians perform tasks related to the IT system.
- There is complete and adequate licensing for the software installed on PRIMER’s IT system equipment.
- The use of PRIMER’s IT system equipment outside PRIMER’s premises is prohibited without the approval of the IS Manager.
- Irreversible deletion of any information from electronic storage media that are transported outside the company (e.g. return after a leasing agreement, for repair) and keeping a file showing the date and time of dispatch / receipt, the persons responsible for dispatch / receipt, the destination and the reason for the transfer. If this is not possible, the storage media are not transported outside the company for repair and are replaced with others after being destroyed mechanically (drill) and a destruction protocol is kept.
13. Access to Information Systems
General Points
- The Management of PRIMER in collaboration with the IS Manager ensures that access to the IT system is allowed only to authorized users.
Compliance Actions
- For smooth and secure operation, standard operating procedures / instructions for user access control are issued and applied, which cover all stages of user activity, from the initial registration of new users to the final deletion of users who are no longer required to have access and ensure the following:
- Authentication of individual users (no user groups, no generic accounts)
- Protection regarding password recovery and security details.
- Monitoring of access systems and logging – at user level.
- Role management so that functions are performed without sharing passwords.
- “System administrator” (administrator) accounts and rights are provided only to the IS Manager and company executives.
- Each user has access and rights to use the IT system:
- depending on the tasks they perform
- via a unique username which:
- is not shared with other users
- is not given or has not been given in the past to another user
- via a unique login password which:
- only they know,
- consists of at least 8 characters and includes at least one digit and one symbol,
- is requested by the system to be entered at each login,
- is requested by the system for the user to change it after 30 days
- the user is given the possibility to change it at their discretion whenever there is a suspicion or certainty that it has been leaked to someone else.
- it is impossible to bypass (by hiding or removing its settings by the administrator without logging the bypass and requiring the system to set a new password by the user after any bypass)
- via a login process that provides for the following:
- initial log-in screen that makes it obvious that only authorized users are allowed
- not showing previous login information e.g. username
- hiding with symbols the characters of the login password during typing
- locking the account after 2 unsuccessful attempts.
- Under the responsibility of the IS Manager, after relevant approval of the Head of the respective Directorate / Department to which each employee belongs, the access rights to the company’s computer systems:
- are granted and modified upon request of the user to their direct supervisor, followed by written approval of the direct supervisor after consultation with the Head of the respective Directorate / Department to which the user belongs
- are reviewed at regular intervals (at least every 12 months) to ensure that they always correspond to appropriately authorized users and that they are proportional to the tasks they perform.
- are terminated immediately when PRIMER’s collaboration with an employee or external associate ends (before the end of their last day of work / collaboration with PRIMER).
14. Software
General Points
- At any time, there is complete and adequate licensing for the software installed on PRIMER’s IT system equipment. The Management ensures that information processing is done only on software installed on the company’s IT system equipment.
Compliance
- It is prohibited to process information related to PRIMER’s activity on software that is not installed on its IT system equipment.
- The procurement of software installed on PRIMER’s IT system equipment is approved by the IS Manager.
- The software installed on PRIMER’s IT system equipment is registered in the name of PRIMER and the department for which it will be used (under no circumstances in the name of an individual user so as not to create problems and risks for information security in the event of termination of PRIMER’s collaboration with the user).
- Under the responsibility of the IS Manager, a continuously updated list of all software installed on the company’s IT system equipment is compiled and maintained, which includes:
- software that may have been “downloaded” and/or purchased from the internet, Shareware, Freeware and Public Domain
- the title and publisher of the software.
- The serial number of the software product.
- The date and source of software acquisition.
- The point of the IT system where it is installed, referencing the serial number of the hardware on which each copy is installed.
- The existence and location of backups.
- Details and duration of support arrangements for software upgrades.
- Software on Local Area Networks or on multiple machines is used only in accordance with the granted license.
- Software on PRIMER’s IT system equipment is installed / parameterized / configured / modified / upgraded only under the responsibility or with the approval of the IS Manager once the registration requirements are completed.
It is prohibited to install personal or unwanted software (e.g. games, wallpapers, etc.) on PRIMER’s IT system equipment (it is a high-risk action for information security).
-
- PRIMER’s IT system has a mechanism to control and monitor changes to the software installed on the system components. The IS Manager immediately reports to the IS Manager cases of detection of unauthorized changes which, within the framework of the management system, are treated as information security breach incidents.

Ελληνικά