Data Sensitive Policy
- All confidential information for the clients must be strictly protected and must not be disclosed, copied, transmitted, or used outside the scope of employment at ONTI. Such information must not be shared with unauthorized individuals without prior written approval from authorized management.
- All data stored within ONTI systems is considered confidential. It must not be distributed outside authorized users. Additionally, no equipment, storage media, or data may be removed from the institute premises without proper authorization.
- Any information identified as sensitive or vulnerable must be protected using appropriate encryption methods.
- Unused services and applications must be disabled whenever practical. Any exceptions must be documented and approved by the IT Department.
- Authorized users are required to classify information within ONTI Institute systems, in accordance with the institute’s data classification guidelines, as:
- Confidential
- Non-Confidential
- Authorized users are responsible for maintaining the security of their accounts and passwords. Passwords must remain confidential and must not be shared under any circumstances.
- Users must log out of all systems when not in use and must not leave devices or accounts unattended.