Information Security and Data Breach Management Policy

Policy Classification: Public
Document Type: Information Security and Data Breach Management Policy
Applicability: Clients, Candidates, Data Subjects, Employees, Contractors, Authorized Users, Service Providers, Verification Partners, and Business Partners
Policy Owner: Data Privacy, Protection, and Security Office
Approving Authority: Circa Logica Group Management
Version: 2.4
Effective Date: 1 February 2024
Last Review Date: 6 January 2026

PART I

GENERAL SECURITY FRAMEWORK

1. POLICY STATEMENT

Talentprobe Due Diligence (“Talentprobe”), operated by Circa Logica Group (“CLG” or the “Group”), recognizes information security as a fundamental requirement of responsible background screening, verification, and due diligence.

Talentprobe processes information that may include personal information, sensitive personal information, identification information, employment and educational records, professional credentials, court and public record information, client information, verification evidence, screening reports, authentication information, and other confidential business or personal data.

Unauthorized access, disclosure, alteration, destruction, loss, misuse, or unavailability of such information may cause material harm to candidates, clients, Talentprobe, Circa Logica Group, and other stakeholders.

Talentprobe therefore maintains an information security framework designed to protect the confidentiality, integrity, and availability of information throughout its lifecycle.

Talentprobe shall implement reasonable and appropriate organizational, physical, and technical safeguards proportionate to the nature of the information processed, the risks associated with processing, the nature and complexity of Talentprobe’s operations, applicable legal requirements, recognized security practices, and the operational requirements of the organization.

Talentprobe further maintains processes for the identification, reporting, escalation, containment, investigation, assessment, remediation, recovery, documentation, and notification of information security incidents and personal data breaches.

Information security is a shared organizational responsibility and shall be integrated into Talentprobe’s people, processes, systems, technology, vendor relationships, and business continuity arrangements.

2. PURPOSE

This Policy establishes Talentprobe’s framework for:

a. protecting information and information systems;

b. preserving confidentiality, integrity, and availability;

c. preventing unauthorized access, use, disclosure, alteration, destruction, or loss;

d. managing access to personal and confidential information;

e. protecting systems, networks, applications, endpoints, and cloud environments;

f. securing data transmission and storage;

g. managing authentication and user access;

h. managing security vulnerabilities;

i. monitoring for potential security events;

j. managing third-party information security risks;

k. maintaining appropriate backup and recovery capabilities;

l. supporting business continuity;

m. identifying and reporting information security incidents;

n. responding to suspected and confirmed personal data breaches;

o. assessing potential harm to affected individuals;

p. determining applicable client, regulatory, and data subject notification requirements;

q. documenting security incidents;

r. implementing corrective and preventive action; and

s. continuously improving Talentprobe’s information security posture.

3. SCOPE

This Policy applies to information and information systems owned, operated, managed, accessed, or used by Talentprobe or on its behalf.

It applies to:

a. personal data;

b. sensitive personal information;

c. privileged information;

d. confidential client information;

e. candidate information;

f. background screening reports;

g. verification evidence;

h. corporate records;

i. employee information;

j. authentication information;

k. system and security logs;

l. source information;

m. contractual information;

n. intellectual property;

o. business information;

p. physical records; and

q. other information requiring protection.

The Policy applies regardless of whether information is stored or processed:

a. electronically;

b. physically;

c. locally;

d. remotely;

e. through cloud infrastructure;

f. through authorized third-party systems;

g. on mobile or endpoint devices; or

h. through another authorized environment.

4. PERSONS COVERED

This Policy applies to all persons who are authorized to access Talentprobe information or systems, including:

a. employees;

b. officers;

c. directors;

d. consultants;

e. contractors;

f. temporary personnel;

g. authorized client users;

h. researchers;

i. verifiers;

j. service providers;

k. technology providers;

l. verification partners; and

m. other authorized persons.

Access to Talentprobe information constitutes an obligation to comply with applicable security and confidentiality requirements.

5. REGULATORY AND GOVERNANCE FRAMEWORK

Talentprobe shall maintain its information security framework in accordance with applicable requirements, including where relevant:

a. Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012;

b. its Implementing Rules and Regulations;

c. applicable National Privacy Commission circulars, advisories, orders, decisions, and other issuances;

d. contractual information security obligations;

e. applicable client Data Processing Agreements;

f. applicable laws concerning information systems and electronic records; and

g. other security requirements applicable to Talentprobe’s processing activities.

Where a client or applicable foreign jurisdiction imposes additional lawful security requirements, Talentprobe may implement such requirements through contractual or operational controls appropriate to the relevant engagement.

PART II

INFORMATION SECURITY PRINCIPLES

6. CONFIDENTIALITY

Information shall be accessible only to persons, systems, and organizations appropriately authorized to access it.

Talentprobe shall seek to prevent unauthorized disclosure, access, extraction, copying, sharing, or use of information.

7. INTEGRITY

Talentprobe shall maintain reasonable safeguards intended to protect information against unauthorized or accidental alteration, manipulation, corruption, deletion, or destruction.

Information used for background screening shall be protected against unauthorized modification that could affect the accuracy or integrity of screening results.

8. AVAILABILITY

Talentprobe shall maintain reasonable measures designed to ensure that information and systems necessary for legitimate operations remain available to authorized users when reasonably required.

Availability measures may include appropriate redundancy, backup, recovery, monitoring, business continuity, and disaster recovery arrangements.

9. LEAST PRIVILEGE

Access shall be limited to the minimum level reasonably necessary for the performance of authorized responsibilities.

Access to information shall not be granted merely because an individual is employed by or associated with Talentprobe or Circa Logica Group.

10. NEED-TO-KNOW

Personal, confidential, or sensitive information shall be made available only where access serves a legitimate and authorized business purpose.

11. DEFENSE IN DEPTH

Talentprobe shall seek to maintain multiple layers of organizational, physical, and technical controls so that the failure of a single safeguard does not necessarily result in unrestricted compromise.

12. SECURITY BY DESIGN

Information security shall be considered when designing, selecting, developing, implementing, configuring, or materially modifying systems and processes involving sensitive or confidential information.

13. RISK-BASED SECURITY

Security controls shall be proportionate to the risks associated with the relevant information, system, processing activity, and threat environment.

Talentprobe may apply stronger controls to systems or information presenting greater confidentiality, integrity, availability, or privacy risks.

PART III

SECURITY GOVERNANCE

14. MANAGEMENT RESPONSIBILITY

Talentprobe management is responsible for supporting an appropriate information security environment.

Management responsibilities may include:

a. approving security policies;

b. allocating appropriate resources;

c. assigning responsibilities;

d. reviewing material security risks;

e. supporting incident response;

f. ensuring appropriate remediation; and

g. promoting security accountability.

15. DATA PRIVACY, PROTECTION, AND SECURITY OFFICE

Talentprobe operates within Circa Logica Group’s privacy and security governance framework.

The Data Privacy, Protection, and Security Office shall provide appropriate oversight of privacy and security matters.

Responsibilities may include:

a. security policy coordination;

b. privacy and security risk oversight;

c. incident management coordination;

d. breach assessment;

e. regulatory coordination;

f. security awareness;

g. review of material security incidents;

h. support for privacy impact assessments;

i. coordination with technology and operations personnel; and

j. continuous improvement.

16. DATA PROTECTION OFFICER

The Data Protection Officer shall perform responsibilities required by applicable privacy law and may participate in the assessment and management of incidents involving personal data.

The DPO shall be appropriately informed of suspected personal data breaches requiring privacy assessment.

17. SECURITY RESPONSIBILITIES

Security responsibilities may be distributed among appropriate technology, privacy, compliance, risk, operations, management, and other authorized functions.

Talentprobe shall seek to ensure that responsibilities are sufficiently defined to enable timely decision-making during security incidents.

PART IV

INFORMATION CLASSIFICATION AND HANDLING

18. INFORMATION CLASSIFICATION

Talentprobe may classify information according to sensitivity, business importance, legal requirements, and potential consequences of unauthorized disclosure or alteration.

Information may be subject to different controls according to its classification.

19. PERSONAL AND SENSITIVE INFORMATION

Personal information and sensitive personal information shall be handled in accordance with Talentprobe’s Data Privacy and Protection Policy and applicable privacy requirements.

Access shall be limited according to legitimate business need.

20. CONFIDENTIAL CLIENT INFORMATION

Client information, screening reports, commercial arrangements, credentials, correspondence, and other non-public client information shall be treated as confidential unless otherwise authorized.

21. SCREENING REPORTS

Background screening reports shall be treated as confidential.

Reports shall be made accessible only to authorized recipients and shall not knowingly be disclosed to unrelated third parties without an appropriate legal basis or authorization.

22. VERIFICATION EVIDENCE

Supporting evidence used to prepare screening findings may contain personal information, sensitive information, confidential source information, or other restricted information.

Such evidence shall be subject to appropriate access and security controls.

PART V

ACCESS CONTROL

23. ACCESS AUTHORIZATION

Access to Talentprobe systems shall require appropriate authorization.

Access rights should correspond to the individual’s role, responsibilities, and legitimate business requirements.

24. ROLE-BASED ACCESS

Where appropriate, Talentprobe may implement role-based access controls to restrict access according to job function or system responsibility.

Different roles may receive different levels of access.

25. USER IDENTIFICATION

Users of Talentprobe systems should, where appropriate, be assigned identifiable accounts or other mechanisms capable of associating system activity with the authorized user.

Shared access credentials should be avoided where individual accountability is reasonably required.

26. AUTHENTICATION

Talentprobe shall maintain authentication mechanisms appropriate to the sensitivity and risk of relevant systems.

Authentication controls may include:

a. passwords;

b. multi-factor authentication;

c. one-time verification mechanisms;

d. device verification;

e. identity federation;

f. session controls; and

g. other secure authentication mechanisms.

27. CREDENTIAL CONFIDENTIALITY

Users shall protect passwords, authentication codes, tokens, and other credentials against unauthorized disclosure.

Credentials shall not knowingly be shared with unauthorized persons.

Talentprobe personnel shall not request another user’s password except where an authorized technical process expressly requires credential reset or replacement without disclosure of the existing password.

28. PRIVILEGED ACCESS

Administrative, elevated, or privileged access shall be restricted to appropriately authorized personnel.

Privileged access may be subject to additional authentication, monitoring, review, or other controls.

29. ACCESS REVIEW

Access rights may be periodically reviewed to determine whether they remain appropriate.

Access should be modified or removed where:

a. responsibilities change;

b. access is no longer required;

c. employment or engagement ends;

d. a security risk exists;

e. access has been improperly used; or

f. another legitimate reason requires restriction.

30. TERMINATION OF ACCESS

Access shall be revoked or appropriately restricted following termination of employment or engagement, subject to established offboarding procedures.

Where circumstances present elevated security risk, access may be suspended immediately.

PART VI

ENCRYPTION AND DATA PROTECTION

31. ENCRYPTION

Talentprobe shall use appropriate encryption or comparable security controls where warranted by the sensitivity of information, method of transmission, storage environment, and associated risk.

32. DATA IN TRANSIT

Sensitive or confidential information transmitted through public or otherwise untrusted networks should be protected using appropriate secure transmission mechanisms.

33. DATA AT REST

Where appropriate, sensitive information stored electronically shall be protected through encryption, access controls, infrastructure security, or other appropriate safeguards.

34. CRYPTOGRAPHIC STANDARDS

Talentprobe shall seek to use cryptographic mechanisms consistent with reasonable security practices appropriate to the relevant technology environment.

Specific cryptographic technologies, algorithms, key lengths, configurations, or providers may change as security practices and technology evolve.

Such technical details may be maintained through internal standards rather than permanently prescribed in this public Policy.

PART VII

INFRASTRUCTURE AND NETWORK SECURITY

35. SECURE INFRASTRUCTURE

Talentprobe shall maintain or use infrastructure with security safeguards appropriate to the nature and sensitivity of information processed.

Infrastructure may be operated directly by Talentprobe, Circa Logica Group, or authorized cloud and technology providers.

36. NETWORK SECURITY

Reasonable controls shall be maintained to protect networks and systems against unauthorized access and malicious activity.

Such controls may include:

a. network filtering;

b. firewall technologies;

c. intrusion detection or prevention capabilities;

d. secure network configuration;

e. segmentation;

f. traffic monitoring;

g. access restrictions;

h. anti-malware protections; and

i. other appropriate safeguards.

37. EXTERNAL THREATS

Talentprobe shall maintain reasonable measures designed to address threats including:

a. malware;

b. ransomware;

c. phishing;

d. credential attacks;

e. unauthorized scanning;

f. malicious network traffic;

g. denial-of-service activity;

h. exploitation of vulnerabilities;

i. unauthorized remote access; and

j. other reasonably foreseeable cyber threats.

38. REMOTE ACCESS

Remote access to Talentprobe systems shall be authorized and appropriately secured.

Additional controls may be applied based on the sensitivity of systems or information being accessed.

39. CLOUD SECURITY

Where cloud infrastructure is used, Talentprobe shall seek to use reputable providers and configure services according to appropriate security requirements.

The use of cloud infrastructure does not eliminate Talentprobe’s responsibility to maintain appropriate security governance over information under its control.

PART VIII

ENDPOINT AND WORKPLACE SECURITY

40. AUTHORIZED DEVICES

Access to sensitive systems may be restricted to authorized or appropriately secured devices where warranted by risk.

41. DEVICE SECURITY

Reasonable endpoint security measures may include:

a. device authentication;

b. operating system updates;

c. anti-malware controls;

d. encryption;

e. endpoint monitoring;

f. automatic locking;

g. remote management;

h. controlled software installation; and

i. other appropriate measures.

42. MOBILE DEVICES

Where mobile devices are authorized to access Talentprobe information, appropriate safeguards shall be applied according to the sensitivity of the information and associated risk.

43. REMOVABLE MEDIA

Use of removable media for sensitive or confidential information may be restricted, controlled, encrypted, or prohibited according to risk.

44. CLEAR DESK AND SCREEN PROTECTION

Personnel shall take reasonable precautions to prevent unauthorized viewing or access to confidential information.

Screens displaying sensitive information should not be left unnecessarily exposed to unauthorized persons.

Physical records should be appropriately secured when unattended.

PART IX

APPLICATION AND SYSTEM SECURITY

45. SECURE DEVELOPMENT

Where Talentprobe develops or materially modifies systems, reasonable security considerations shall be incorporated into the development and deployment lifecycle.

This may include:

a. security requirements;

b. code review;

c. testing;

d. access control;

e. change management;

f. vulnerability assessment;

g. secure configuration; and

h. remediation of identified security issues.

46. CHANGE MANAGEMENT

Material changes to production systems should be appropriately authorized, tested, documented, or reviewed according to the nature and risk of the change.

47. ENVIRONMENT SEPARATION

Where appropriate, development, testing, and production environments may be logically or physically separated to reduce the risk of unauthorized changes or exposure.

48. TEST DATA

Use of live personal information for testing should be minimized where reasonably practicable.

Where personal information is required for legitimate testing, appropriate safeguards shall apply.

PART X

VULNERABILITY AND SECURITY TESTING

49. VULNERABILITY MANAGEMENT

Talentprobe shall maintain reasonable processes for identifying, assessing, prioritizing, and addressing vulnerabilities affecting relevant systems.

50. VULNERABILITY SCANNING

Systems may be subject to periodic or risk-based vulnerability scanning or comparable security assessment.

The frequency and scope of such assessments may vary according to system criticality, threat environment, technology changes, and identified risk.

51. PENETRATION AND SECURITY TESTING

Talentprobe may conduct or commission penetration testing, security assessments, configuration reviews, or other forms of technical testing appropriate to relevant systems.

Testing may be conducted internally or through qualified third parties.

52. REMEDIATION

Identified vulnerabilities shall be evaluated according to risk.

Remediation priority may consider:

a. severity;

b. exploitability;

c. exposure;

d. affected information;

e. system criticality;

f. available mitigations; and

g. potential business or data subject impact.

53. SECURITY TEST CONFIDENTIALITY

Detailed vulnerability findings, penetration test reports, network diagrams, configurations, exploit information, credentials, and remediation details are confidential security information.

Talentprobe may provide appropriate clients with high-level security assurance information without disclosing information that could create additional security risk.

PART XI

LOGGING, MONITORING, AND DETECTION

54. SECURITY MONITORING

Talentprobe shall maintain reasonable capabilities designed to identify unauthorized, anomalous, suspicious, or potentially harmful activity affecting relevant systems.

55. SYSTEM LOGGING

Relevant systems may generate logs concerning:

a. authentication;

b. user access;

c. administrative actions;

d. security events;

e. system activity;

f. changes;

g. errors; and

h. other events relevant to security and accountability.

56. LOG PROTECTION

Security and audit logs shall be protected against inappropriate access, alteration, or deletion according to their sensitivity and purpose.

57. MONITORING LIMITATIONS

Security monitoring is intended to identify and manage risk but does not constitute a guarantee that every malicious or unauthorized activity will be prevented or detected immediately.

PART XII

BACKUP, RECOVERY, AND BUSINESS CONTINUITY

58. BACKUP

Talentprobe shall maintain backup arrangements appropriate to the nature and criticality of relevant information and systems.

59. BACKUP PROTECTION

Backups containing personal or confidential information shall be subject to appropriate security and access controls.

60. RESTORATION

Talentprobe shall maintain reasonable processes for restoring relevant systems or information following disruption, corruption, loss, or other incidents.

61. BUSINESS CONTINUITY

Talentprobe shall maintain business continuity arrangements designed to support critical operations during material disruptions.

Planning may consider:

a. system outages;

b. infrastructure failures;

c. cybersecurity incidents;

d. natural disasters;

e. power or telecommunications disruption;

f. loss of facilities;

g. unavailability of critical providers;

h. workforce disruption; and

i. other material operational events.

62. DISASTER RECOVERY

Where appropriate, disaster recovery arrangements shall establish processes for restoring critical technology and information services following significant disruption.

63. TESTING AND REVIEW

Business continuity, backup, and recovery arrangements may be periodically reviewed, tested, or exercised according to risk and operational requirements.

PART XIII

PERSONNEL SECURITY

64. CONFIDENTIALITY OBLIGATIONS

Personnel with access to confidential or personal information shall be subject to appropriate confidentiality obligations.

65. SECURITY AWARENESS

Talentprobe shall provide personnel with appropriate information security and privacy awareness or training relevant to their responsibilities.

Topics may include:

a. password and authentication security;

b. phishing;

c. social engineering;

d. handling personal information;

e. confidentiality;

f. incident reporting;

g. remote work;

h. device security;

i. acceptable use; and

j. other relevant security risks.

66. ACCEPTABLE USE

Talentprobe systems and information shall be used for authorized purposes.

Personnel shall not knowingly:

a. bypass security controls;

b. share credentials improperly;

c. access information without authorization;

d. install unauthorized malicious software;

e. disclose confidential information without authority;

f. disable required security controls;

g. use Talentprobe systems for unlawful activity; or

h. otherwise intentionally compromise information security.

67. SECURITY VIOLATIONS

Violations of security requirements may result in:

a. suspension of access;

b. investigation;

c. corrective action;

d. disciplinary action;

e. termination of employment or engagement;

f. contractual remedies;

g. legal action; or

h. regulatory referral where appropriate.

PART XIV

THIRD-PARTY SECURITY

68. SERVICE PROVIDERS

Talentprobe may use third-party technology, infrastructure, communications, verification, support, and other service providers.

Third parties that process Talentprobe information shall be subject to security requirements appropriate to the nature of the service and information involved.

69. THIRD-PARTY DUE DILIGENCE

Where appropriate, Talentprobe may assess third-party security based on factors including:

a. nature of information processed;

b. service criticality;

c. security practices;

d. privacy controls;

e. certifications or independent assessments where relevant;

f. incident history where available;

g. business continuity;

h. subcontracting arrangements;

i. location of processing; and

j. contractual safeguards.

70. SECURITY CONTRACT TERMS

Appropriate third-party agreements may contain requirements concerning:

a. confidentiality;

b. authorized use;

c. information security;

d. access restrictions;

e. incident reporting;

f. breach notification;

g. subcontracting;

h. data return or deletion;

i. audit or assurance information; and

j. compliance with applicable law.

71. THIRD-PARTY INCIDENTS

A security incident involving a third-party provider shall be assessed according to its potential effect upon Talentprobe information, systems, clients, and data subjects.

Third-party involvement does not automatically eliminate applicable Talentprobe obligations.

PART XV

SECURITY INCIDENT MANAGEMENT

72. SECURITY INCIDENT

A security incident is an event or series of events that may compromise, or indicate an attempt to compromise, the confidentiality, integrity, availability, or lawful processing of information or information systems.

A security incident does not necessarily constitute a personal data breach.

73. EXAMPLES OF SECURITY INCIDENTS

Security incidents may include:

a. unauthorized access;

b. suspected account compromise;

c. phishing;

d. malware;

e. ransomware;

f. lost or stolen equipment;

g. unauthorized disclosure;

h. accidental transmission to an incorrect recipient;

i. inappropriate system access;

j. unauthorized modification;

k. data loss;

l. system intrusion;

m. credential theft;

n. denial-of-service attack;

o. physical security breach;

p. compromised service provider;

q. unauthorized data extraction;

r. suspicious system activity; or

s. other events presenting material information security risk.

74. PERSONAL DATA BREACH

A personal data breach is a security incident involving personal data that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed, consistent with applicable law.

Personal data breaches may involve:

a. confidentiality;

b. integrity;

c. availability; or

d. combinations of these elements.

PART XVI

SECURITY INCIDENT RESPONSE ORGANIZATION

75. SECURITY INCIDENT RESPONSE TEAM

Talentprobe or Circa Logica Group shall maintain an appropriate Security Incident Response Team or equivalent incident response structure.

The composition of the response team may vary depending upon the nature and severity of the incident.

76. RESPONSE TEAM FUNCTIONS

Incident response may involve representatives from:

a. information technology;

b. information security;

c. Data Privacy, Protection, and Security Office;

d. Data Protection Officer;

e. risk and compliance;

f. operations;

g. management;

h. legal counsel;

i. communications;

j. human resources;

k. affected business functions; and

l. relevant third-party specialists.

77. INCIDENT LEADERSHIP

Material incidents shall be assigned appropriate leadership and decision-making authority.

The incident lead shall coordinate activities necessary to investigate, contain, remediate, document, and communicate the incident.

78. ESCALATION

Incidents shall be escalated according to their nature, severity, potential impact, information involved, affected systems, affected individuals, client implications, and applicable legal requirements.

PART XVII

INCIDENT REPORTING

79. INTERNAL REPORTING OBLIGATION

Personnel shall promptly report suspected security incidents through established channels.

Personnel should not delay reporting merely because:

a. the facts are incomplete;

b. the incident appears minor;

c. no harm has yet been confirmed;

d. the individual believes the problem has already been resolved; or

e. responsibility for the incident is uncertain.

Timely escalation allows appropriate personnel to determine the actual significance of the event.

80. GOOD-FAITH REPORTING

Personnel shall not be penalized merely for reporting a security concern in good faith.

Intentional concealment of a known material security incident may result in appropriate corrective or disciplinary action.

81. CLIENT REPORTING

Clients should report suspected unauthorized access, compromised credentials, erroneous report delivery, or other security concerns involving Talentprobe services through designated support, account management, privacy, or security channels.

PART XVIII

INCIDENT RESPONSE LIFECYCLE

82. IDENTIFICATION

Talentprobe shall seek to determine whether a reported or detected event constitutes:

a. a false alarm;

b. a security event;

c. a security incident;

d. a personal data breach;

e. a material operational incident; or

f. another event requiring action.

83. INITIAL ASSESSMENT

Initial assessment may consider:

a. systems affected;

b. information involved;

c. nature of the event;

d. suspected cause;

e. potential unauthorized access;

f. affected individuals;

g. affected clients;

h. continuing threat;

i. operational impact; and

j. immediate containment requirements.

84. CONTAINMENT

Talentprobe shall take reasonable measures to contain an active security incident.

Containment may include:

a. disabling accounts;

b. resetting credentials;

c. isolating systems;

d. blocking malicious activity;

e. restricting access;

f. removing compromised devices;

g. disabling integrations;

h. suspending affected services;

i. preserving relevant evidence; or

j. other appropriate measures.

85. PRESERVATION OF EVIDENCE

Where appropriate, Talentprobe shall preserve information reasonably necessary to investigate the incident.

Evidence may include:

a. logs;

b. system records;

c. communications;

d. access records;

e. affected files;

f. forensic information;

g. screenshots;

h. device information; and

i. other relevant material.

Evidence shall be protected against unauthorized alteration or destruction.

86. INVESTIGATION

Talentprobe shall investigate material incidents to an extent appropriate to their nature and potential impact.

Investigation may seek to determine:

a. what occurred;

b. when it occurred;

c. how it occurred;

d. systems affected;

e. information affected;

f. persons affected;

g. unauthorized persons involved;

h. duration of exposure;

i. whether information was accessed, acquired, altered, deleted, or disclosed;

j. whether the threat remains active; and

k. what corrective action is required.

87. ERADICATION

Where malicious activity or vulnerability is identified, Talentprobe shall take reasonable measures to remove or address the underlying threat.

This may include:

a. removing malware;

b. disabling compromised accounts;

c. correcting vulnerabilities;

d. applying security updates;

e. changing configurations;

f. replacing credentials;

g. blocking malicious infrastructure; and

h. other appropriate remediation.

88. RECOVERY

Affected systems shall be restored to normal operations when reasonably safe to do so.

Recovery may include:

a. system restoration;

b. data restoration;

c. security validation;

d. enhanced monitoring;

e. credential resets;

f. user communication; and

g. verification that remediation has been effective.

PART XIX

PERSONAL DATA BREACH ASSESSMENT

89. BREACH ASSESSMENT

Where an incident involves personal data, Talentprobe shall conduct an appropriate assessment to determine applicable privacy and breach obligations.

90. FACTORS FOR ASSESSMENT

Assessment may consider:

a. categories of personal data;

b. sensitivity of information;

c. volume of records;

d. number of affected individuals;

e. whether information was encrypted or otherwise protected;

f. likelihood of unauthorized acquisition;

g. identity of the unauthorized recipient where known;

h. likelihood of misuse;

i. possibility of identity fraud;

j. potential financial harm;

k. reputational harm;

l. discrimination;

m. physical or personal safety risks;

n. contractual obligations;

o. client implications;

p. applicable jurisdiction; and

q. other potential harm to data subjects.

91. MANDATORY NOTIFICATION ASSESSMENT

Talentprobe shall assess whether applicable law requires notification to a regulatory authority, affected data subjects, client, or other party.

The existence of a security incident does not automatically mean that regulatory notification is legally required.

Notification shall be determined based upon applicable legal thresholds, contractual requirements, and the circumstances of the incident.

PART XX

CLIENT AND REGULATORY NOTIFICATION

92. TALENTPROBE AS PERSONAL INFORMATION PROCESSOR

Where Talentprobe acts as a Personal Information Processor and becomes aware of a personal data breach affecting information processed on behalf of a client, Talentprobe shall notify the relevant Personal Information Controller in accordance with applicable law and contractual requirements.

Talentprobe shall provide reasonably available information necessary to enable the client to assess and fulfill its own obligations.

93. TALENTPROBE AS PERSONAL INFORMATION CONTROLLER

Where Talentprobe or Circa Logica Group acts as the Personal Information Controller for affected processing, the organization shall assess and fulfill applicable notification requirements.

94. NATIONAL PRIVACY COMMISSION NOTIFICATION

Where mandatory notification requirements under Philippine law are satisfied, the responsible Personal Information Controller shall notify the National Privacy Commission within the period required by applicable law.

Where the applicable requirements mandate notification within seventy-two (72) hours from knowledge or reasonable belief that a qualifying personal data breach has occurred, Talentprobe or Circa Logica Group shall take reasonable measures to comply with that period.

Notification may initially be based on information reasonably available at the time and may be supplemented as further investigation develops.

95. DATA SUBJECT NOTIFICATION

Where required by applicable law, affected data subjects shall be notified within the applicable period.

Notification should be communicated in a manner reasonably designed to enable affected individuals to understand the incident and take appropriate precautions.

96. CONTENT OF BREACH NOTIFICATION

Where applicable, notification may include:

a. nature of the breach;

b. circumstances surrounding the incident;

c. categories of personal information involved;

d. approximate scope of affected records or individuals where known;

e. likely consequences;

f. measures taken to address the incident;

g. measures taken to mitigate potential harm;

h. actions taken to recover or secure information;

i. recommendations to affected individuals where appropriate;

j. measures intended to prevent recurrence; and

k. contact information for further inquiries.

97. INCOMPLETE INFORMATION

Talentprobe shall not unnecessarily delay legally required initial notification solely because every fact has not yet been established.

Where permitted, initial notification may be supplemented as additional verified information becomes available.

98. CONTRACTUAL CLIENT NOTIFICATION

Client contracts or Data Processing Agreements may establish incident notification requirements that are different from regulatory notification thresholds or periods.

Talentprobe shall seek to comply with applicable contractual obligations in addition to mandatory legal requirements.

99. FOREIGN JURISDICTIONS

Where an incident involves information subject to another jurisdiction’s breach notification requirements, Talentprobe shall assess applicable obligations according to its role in the relevant processing activity.

Where appropriate, Talentprobe may coordinate with affected clients, legal counsel, privacy advisers, or competent regulatory authorities.

PART XXI

DATA SUBJECT PROTECTION AND HARM MITIGATION

100. MITIGATION OF HARM

Where a breach may create risk to individuals, Talentprobe shall consider reasonable measures to reduce potential harm.

Measures may include, where appropriate:

a. credential resets;

b. account protection;

c. access revocation;

d. additional authentication;

e. warnings regarding phishing or fraud;

f. instructions concerning protective measures;

g. correction of exposed information;

h. enhanced monitoring; and

i. other measures appropriate to the nature of the incident.

101. CLEAR COMMUNICATION

Breach communications should avoid unnecessarily technical terminology and should provide information reasonably useful to affected individuals.

Talentprobe shall seek to communicate verified information and distinguish confirmed facts from matters still under investigation.

102. PROTECTION AGAINST FURTHER DISCLOSURE

Talentprobe shall seek to avoid unnecessarily reproducing or further exposing compromised personal information while investigating or communicating about an incident.

PART XXII

INCIDENT DOCUMENTATION

103. SECURITY INCIDENT REGISTER

Talentprobe or Circa Logica Group shall maintain appropriate records of security incidents and personal data breaches.

104. INCIDENT RECORD

Incident documentation may include:

a. date and time identified;

b. date and time reported;

c. nature of the incident;

d. systems affected;

e. information involved;

f. persons or clients affected;

g. containment actions;

h. investigation findings;

i. breach assessment;

j. notifications;

k. remediation;

l. recovery;

m. root cause;

n. corrective action; and

o. closure.

105. NON-NOTIFIABLE INCIDENTS

Where a security incident involving personal data does not meet mandatory regulatory notification thresholds, Talentprobe shall nevertheless maintain appropriate documentation where required.

The absence of regulatory notification does not mean that the incident requires no internal review or remediation.

106. REGULATORY REPORTING

Talentprobe or Circa Logica Group shall maintain and submit applicable security incident or breach reports required by competent regulatory authorities.

PART XXIII

POST-INCIDENT REVIEW

107. ROOT CAUSE ANALYSIS

Material security incidents may be subject to root cause analysis.

Root causes may include:

a. technical vulnerabilities;

b. configuration errors;

c. human error;

d. phishing or social engineering;

e. credential compromise;

f. malicious insiders;

g. vendor failures;

h. inadequate processes;

i. physical security failures;

j. software defects; or

k. other contributing factors.

108. CORRECTIVE ACTION

Corrective actions may include:

a. system changes;

b. security updates;

c. configuration changes;

d. additional access restrictions;

e. enhanced monitoring;

f. employee training;

g. procedural changes;

h. vendor remediation;

i. contractual changes;

j. disciplinary action;

k. technology replacement; or

l. other appropriate measures.

109. PREVENTIVE ACTION

Talentprobe shall consider whether lessons from an incident indicate a broader need to improve security controls beyond the directly affected system or process.

110. LESSONS LEARNED

Material incidents may be reviewed to determine:

a. effectiveness of detection;

b. effectiveness of escalation;

c. speed of containment;

d. quality of investigation;

e. effectiveness of communications;

f. regulatory compliance;

g. adequacy of recovery;

h. effectiveness of existing controls; and

i. opportunities for improvement.

PART XXIV

SECURITY ASSURANCE AND CLIENT DUE DILIGENCE

111. CLIENT SECURITY ASSESSMENTS

Talentprobe recognizes that clients may require reasonable information concerning Talentprobe’s security environment as part of vendor accreditation, procurement, risk management, or due diligence.

Talentprobe may provide appropriate information concerning:

a. security governance;

b. privacy controls;

c. access management;

d. encryption;

e. infrastructure security;

f. vulnerability management;

g. backup and recovery;

h. business continuity;

i. incident response;

j. third-party risk management; and

k. other relevant security controls.

112. CONFIDENTIAL SECURITY INFORMATION

Talentprobe reserves the right to restrict disclosure of information that could materially weaken security if publicly released.

This may include:

a. network architecture;

b. IP addresses;

c. firewall configurations;

d. security rules;

e. credentials;

f. cryptographic keys;

g. detailed penetration test findings;

h. unresolved vulnerabilities;

i. detection thresholds;

j. incident response playbooks;

k. security monitoring configurations;

l. infrastructure diagrams; and

m. other information capable of facilitating unauthorized access or attack.

113. CERTIFICATIONS AND ASSURANCE CLAIMS

Talentprobe shall seek to ensure that externally communicated security certifications, attestations, audit results, compliance statuses, or similar assurance claims accurately reflect the relevant scope and current status.

The use of a technology provider that holds a particular certification does not automatically mean that Talentprobe itself holds the same certification.

Talentprobe shall distinguish, where necessary, between:

a. certification held directly by Talentprobe;

b. certification held by Circa Logica Group;

c. certification held by a cloud or service provider;

d. compliance applicable to a particular system or service; and

e. security practices that do not constitute formal certification.

PART XXV

RELATIONSHIP WITH OTHER POLICIES

114. DATA PRIVACY AND PROTECTION POLICY

Personal data processed under this Policy remains subject to Talentprobe’s Data Privacy and Protection Policy.

115. DATA RETENTION AND SECURE DISPOSAL POLICY

Security records, logs, backups, screening information, incident records, and related information shall be retained and disposed of according to Talentprobe’s Data Retention and Secure Disposal Policy and applicable legal requirements.

116. BACKGROUND SCREENING QUALITY AND ACCURACY POLICY

Security measures shall support the integrity and reliability of background screening information in accordance with Talentprobe’s Background Screening Quality and Accuracy Policy.

Unauthorized modification of screening findings shall be treated as both a security and quality concern.

117. CANDIDATE RIGHTS, DISPUTE AND RESOLUTION POLICY

Where a security incident affects candidate rights or screening information, applicable candidate concerns shall also be addressed according to the Candidate Rights, Dispute and Resolution Policy.

118. DATA PROCESSING AGREEMENTS

Where Talentprobe processes personal data on behalf of a client, incident and security responsibilities may be further governed by the applicable Data Processing Agreement or services agreement.

PART XXVI

SECURITY RISK MANAGEMENT

119. SECURITY RISK ASSESSMENT

Talentprobe shall periodically assess information security risks appropriate to its processing activities.

Risk assessments may consider:

a. information sensitivity;

b. threat likelihood;

c. vulnerabilities;

d. potential impact;

e. technology changes;

f. processing volume;

g. access arrangements;

h. third-party dependencies;

i. geographic considerations;

j. regulatory requirements; and

k. other relevant factors.

120. PRIVACY IMPACT ASSESSMENT

Where processing presents material privacy risk, Talentprobe may conduct a Privacy Impact Assessment or comparable assessment in accordance with applicable requirements.

121. RISK TREATMENT

Identified security risks may be:

a. mitigated;

b. avoided;

c. transferred through appropriate contractual or insurance arrangements;

d. accepted by appropriate management authority; or

e. otherwise addressed according to established risk management practices.

122. MATERIAL CHANGES

Material changes to technology, processing activities, infrastructure, vendors, or services may trigger additional security or privacy review where appropriate.

PART XXVII

CONTINUOUS SECURITY IMPROVEMENT

123. REVIEW OF SECURITY CONTROLS

Talentprobe shall periodically review the effectiveness and appropriateness of relevant information security measures.

Review may include:

a. risk assessment;

b. vulnerability assessment;

c. incident analysis;

d. security testing;

e. access review;

f. vendor review;

g. policy review;

h. audit findings;

i. training outcomes; and

j. changes in recognized security practices.

124. EVOLVING THREATS

Talentprobe recognizes that cybersecurity threats evolve.

Security measures may therefore be modified without requiring amendment of this Policy where such changes strengthen or appropriately adapt Talentprobe’s security environment.

125. POLICY REVIEW

This Policy shall be reviewed periodically and may be updated in response to:

a. changes in applicable law;

b. National Privacy Commission requirements;

c. cybersecurity developments;

d. material security incidents;

e. technology changes;

f. business changes;

g. audit findings;

h. risk assessments;

i. client requirements; and

j. recognized security practices.

126. POLICY AVAILABILITY

This Policy is classified as a public policy and may be:

a. published on Talentprobe’s official website;

b. shared with clients;

c. provided during vendor accreditation;

d. submitted in procurement exercises;

e. provided during privacy or security due diligence;

f. shared with auditors or authorized reviewers; and

g. otherwise made available to legitimate stakeholders.

Detailed internal security procedures, configurations, architecture, response playbooks, vulnerability information, and other sensitive security materials shall remain confidential.

PART XXVIII

SECURITY CONTACT AND INCIDENT REPORTING

127. SECURITY AND PRIVACY CONTACT

Questions concerning this Policy, information security, suspected personal data breaches, or privacy-related security matters may be directed to:

Data Privacy, Protection, and Security Office
Talentprobe Due Diligence / Circa Logica Group

Email: privacy@circalogicagroup.com

Additional security, client support, candidate support, or emergency escalation channels may be maintained internally or provided directly to clients as appropriate.

128. REPORTING SUSPECTED INCIDENTS

Clients, candidates, employees, partners, and other stakeholders who become aware of suspected unauthorized access, disclosure, loss, alteration, or misuse of Talentprobe information are encouraged to report the matter promptly through the appropriate Talentprobe or Circa Logica Group channel.

Reports should contain sufficient information to enable Talentprobe to identify and investigate the concern, but reporters should avoid unnecessarily transmitting additional sensitive personal information through unsecured channels.

PART XXIX

POLICY INTERPRETATION

129. NO ABSOLUTE SECURITY GUARANTEE

Talentprobe maintains reasonable and appropriate safeguards designed to protect information.

No organization, information system, cloud environment, communication channel, or security technology can reasonably guarantee absolute protection against every possible threat.

Nothing in this Policy should therefore be interpreted as an absolute warranty that a security incident can never occur.

Talentprobe’s commitment is to maintain appropriate preventive controls, detect and respond to incidents responsibly, mitigate harm, comply with applicable notification requirements, and continuously improve its security environment.

130. LEGAL AND CONTRACTUAL REQUIREMENTS

Where applicable law imposes a higher mandatory security or breach-management requirement than this Policy, the applicable legal requirement shall prevail.

Where a binding client agreement establishes additional lawful security requirements, Talentprobe shall comply with those requirements according to the terms of the agreement.

131. INTERPRETATION

Questions concerning the interpretation or application of this Policy shall be referred to the Data Privacy, Protection, and Security Office, Data Protection Officer, authorized management, legal counsel, or another appropriate responsible function.

PART XXX

TALENTPROBE INFORMATION SECURITY COMMITMENT

132. OUR COMMITMENT

Information security is fundamental to the trust placed in Talentprobe.

Candidates entrust Talentprobe with information that may relate to their identity, employment, education, qualifications, professional history, and other aspects of their personal and professional lives.

Clients entrust Talentprobe with screening requests, reports, credentials, business information, and information necessary to support important employment and risk decisions.

Talentprobe accepts the responsibility that accompanies that trust.

We therefore commit to maintaining reasonable and appropriate measures designed to:

protect personal and confidential information against unauthorized access;

preserve the confidentiality, integrity, and availability of information;

restrict access according to legitimate business need;

protect information during storage, transmission, processing, and disposal;

maintain appropriate authentication and access controls;

identify and address security vulnerabilities;

monitor for material security threats;

maintain appropriate backup, recovery, and business continuity arrangements;

manage third-party security risks;

identify and escalate suspected security incidents promptly;

contain and investigate security incidents responsibly;

assess personal data breaches according to applicable legal requirements;

notify clients, regulators, and affected individuals when notification is required;

mitigate potential harm arising from security incidents;

learn from incidents and implement appropriate corrective measures; and

continuously improve the security of Talentprobe’s people, processes, systems, and information.

Security is not treated solely as a technology function.

It is an organizational responsibility and an essential component of responsible due diligence.