Policy Classification: Public
Document Type: Information Security and Data Breach Management Policy
Applicability: Clients, Candidates, Data Subjects, Employees, Contractors, Authorized Users, Service Providers, Verification Partners, and Business Partners
Policy Owner: Data Privacy, Protection, and Security Office
Approving Authority: Circa Logica Group Management
Version: 2.4
Effective Date: 1 February 2024
Last Review Date: 6 January 2026
PART I
GENERAL SECURITY FRAMEWORK
1. POLICY STATEMENT
Talentprobe Due Diligence (“Talentprobe”), operated by Circa Logica Group (“CLG” or the “Group”), recognizes information security as a fundamental requirement of responsible background screening, verification, and due diligence.
Talentprobe processes information that may include personal information, sensitive personal information, identification information, employment and educational records, professional credentials, court and public record information, client information, verification evidence, screening reports, authentication information, and other confidential business or personal data.
Unauthorized access, disclosure, alteration, destruction, loss, misuse, or unavailability of such information may cause material harm to candidates, clients, Talentprobe, Circa Logica Group, and other stakeholders.
Talentprobe therefore maintains an information security framework designed to protect the confidentiality, integrity, and availability of information throughout its lifecycle.
Talentprobe shall implement reasonable and appropriate organizational, physical, and technical safeguards proportionate to the nature of the information processed, the risks associated with processing, the nature and complexity of Talentprobe’s operations, applicable legal requirements, recognized security practices, and the operational requirements of the organization.
Talentprobe further maintains processes for the identification, reporting, escalation, containment, investigation, assessment, remediation, recovery, documentation, and notification of information security incidents and personal data breaches.
Information security is a shared organizational responsibility and shall be integrated into Talentprobe’s people, processes, systems, technology, vendor relationships, and business continuity arrangements.
2. PURPOSE
This Policy establishes Talentprobe’s framework for:
a. protecting information and information systems;
b. preserving confidentiality, integrity, and availability;
c. preventing unauthorized access, use, disclosure, alteration, destruction, or loss;
d. managing access to personal and confidential information;
e. protecting systems, networks, applications, endpoints, and cloud environments;
f. securing data transmission and storage;
g. managing authentication and user access;
h. managing security vulnerabilities;
i. monitoring for potential security events;
j. managing third-party information security risks;
k. maintaining appropriate backup and recovery capabilities;
l. supporting business continuity;
m. identifying and reporting information security incidents;
n. responding to suspected and confirmed personal data breaches;
o. assessing potential harm to affected individuals;
p. determining applicable client, regulatory, and data subject notification requirements;
q. documenting security incidents;
r. implementing corrective and preventive action; and
s. continuously improving Talentprobe’s information security posture.
3. SCOPE
This Policy applies to information and information systems owned, operated, managed, accessed, or used by Talentprobe or on its behalf.
It applies to:
a. personal data;
b. sensitive personal information;
c. privileged information;
d. confidential client information;
e. candidate information;
f. background screening reports;
g. verification evidence;
h. corporate records;
i. employee information;
j. authentication information;
k. system and security logs;
l. source information;
m. contractual information;
n. intellectual property;
o. business information;
p. physical records; and
q. other information requiring protection.
The Policy applies regardless of whether information is stored or processed:
a. electronically;
b. physically;
c. locally;
d. remotely;
e. through cloud infrastructure;
f. through authorized third-party systems;
g. on mobile or endpoint devices; or
h. through another authorized environment.
4. PERSONS COVERED
This Policy applies to all persons who are authorized to access Talentprobe information or systems, including:
a. employees;
b. officers;
c. directors;
d. consultants;
e. contractors;
f. temporary personnel;
g. authorized client users;
h. researchers;
i. verifiers;
j. service providers;
k. technology providers;
l. verification partners; and
m. other authorized persons.
Access to Talentprobe information constitutes an obligation to comply with applicable security and confidentiality requirements.
5. REGULATORY AND GOVERNANCE FRAMEWORK
Talentprobe shall maintain its information security framework in accordance with applicable requirements, including where relevant:
a. Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012;
b. its Implementing Rules and Regulations;
c. applicable National Privacy Commission circulars, advisories, orders, decisions, and other issuances;
d. contractual information security obligations;
e. applicable client Data Processing Agreements;
f. applicable laws concerning information systems and electronic records; and
g. other security requirements applicable to Talentprobe’s processing activities.
Where a client or applicable foreign jurisdiction imposes additional lawful security requirements, Talentprobe may implement such requirements through contractual or operational controls appropriate to the relevant engagement.
PART II
INFORMATION SECURITY PRINCIPLES
6. CONFIDENTIALITY
Information shall be accessible only to persons, systems, and organizations appropriately authorized to access it.
Talentprobe shall seek to prevent unauthorized disclosure, access, extraction, copying, sharing, or use of information.
7. INTEGRITY
Talentprobe shall maintain reasonable safeguards intended to protect information against unauthorized or accidental alteration, manipulation, corruption, deletion, or destruction.
Information used for background screening shall be protected against unauthorized modification that could affect the accuracy or integrity of screening results.
8. AVAILABILITY
Talentprobe shall maintain reasonable measures designed to ensure that information and systems necessary for legitimate operations remain available to authorized users when reasonably required.
Availability measures may include appropriate redundancy, backup, recovery, monitoring, business continuity, and disaster recovery arrangements.
9. LEAST PRIVILEGE
Access shall be limited to the minimum level reasonably necessary for the performance of authorized responsibilities.
Access to information shall not be granted merely because an individual is employed by or associated with Talentprobe or Circa Logica Group.
10. NEED-TO-KNOW
Personal, confidential, or sensitive information shall be made available only where access serves a legitimate and authorized business purpose.
11. DEFENSE IN DEPTH
Talentprobe shall seek to maintain multiple layers of organizational, physical, and technical controls so that the failure of a single safeguard does not necessarily result in unrestricted compromise.
12. SECURITY BY DESIGN
Information security shall be considered when designing, selecting, developing, implementing, configuring, or materially modifying systems and processes involving sensitive or confidential information.
13. RISK-BASED SECURITY
Security controls shall be proportionate to the risks associated with the relevant information, system, processing activity, and threat environment.
Talentprobe may apply stronger controls to systems or information presenting greater confidentiality, integrity, availability, or privacy risks.
PART III
SECURITY GOVERNANCE
14. MANAGEMENT RESPONSIBILITY
Talentprobe management is responsible for supporting an appropriate information security environment.
Management responsibilities may include:
a. approving security policies;
b. allocating appropriate resources;
c. assigning responsibilities;
d. reviewing material security risks;
e. supporting incident response;
f. ensuring appropriate remediation; and
g. promoting security accountability.
15. DATA PRIVACY, PROTECTION, AND SECURITY OFFICE
Talentprobe operates within Circa Logica Group’s privacy and security governance framework.
The Data Privacy, Protection, and Security Office shall provide appropriate oversight of privacy and security matters.
Responsibilities may include:
a. security policy coordination;
b. privacy and security risk oversight;
c. incident management coordination;
d. breach assessment;
e. regulatory coordination;
f. security awareness;
g. review of material security incidents;
h. support for privacy impact assessments;
i. coordination with technology and operations personnel; and
j. continuous improvement.
16. DATA PROTECTION OFFICER
The Data Protection Officer shall perform responsibilities required by applicable privacy law and may participate in the assessment and management of incidents involving personal data.
The DPO shall be appropriately informed of suspected personal data breaches requiring privacy assessment.
17. SECURITY RESPONSIBILITIES
Security responsibilities may be distributed among appropriate technology, privacy, compliance, risk, operations, management, and other authorized functions.
Talentprobe shall seek to ensure that responsibilities are sufficiently defined to enable timely decision-making during security incidents.
PART IV
INFORMATION CLASSIFICATION AND HANDLING
18. INFORMATION CLASSIFICATION
Talentprobe may classify information according to sensitivity, business importance, legal requirements, and potential consequences of unauthorized disclosure or alteration.
Information may be subject to different controls according to its classification.
19. PERSONAL AND SENSITIVE INFORMATION
Personal information and sensitive personal information shall be handled in accordance with Talentprobe’s Data Privacy and Protection Policy and applicable privacy requirements.
Access shall be limited according to legitimate business need.
20. CONFIDENTIAL CLIENT INFORMATION
Client information, screening reports, commercial arrangements, credentials, correspondence, and other non-public client information shall be treated as confidential unless otherwise authorized.
21. SCREENING REPORTS
Background screening reports shall be treated as confidential.
Reports shall be made accessible only to authorized recipients and shall not knowingly be disclosed to unrelated third parties without an appropriate legal basis or authorization.
22. VERIFICATION EVIDENCE
Supporting evidence used to prepare screening findings may contain personal information, sensitive information, confidential source information, or other restricted information.
Such evidence shall be subject to appropriate access and security controls.
PART V
ACCESS CONTROL
23. ACCESS AUTHORIZATION
Access to Talentprobe systems shall require appropriate authorization.
Access rights should correspond to the individual’s role, responsibilities, and legitimate business requirements.
24. ROLE-BASED ACCESS
Where appropriate, Talentprobe may implement role-based access controls to restrict access according to job function or system responsibility.
Different roles may receive different levels of access.
25. USER IDENTIFICATION
Users of Talentprobe systems should, where appropriate, be assigned identifiable accounts or other mechanisms capable of associating system activity with the authorized user.
Shared access credentials should be avoided where individual accountability is reasonably required.
26. AUTHENTICATION
Talentprobe shall maintain authentication mechanisms appropriate to the sensitivity and risk of relevant systems.
Authentication controls may include:
a. passwords;
b. multi-factor authentication;
c. one-time verification mechanisms;
d. device verification;
e. identity federation;
f. session controls; and
g. other secure authentication mechanisms.
27. CREDENTIAL CONFIDENTIALITY
Users shall protect passwords, authentication codes, tokens, and other credentials against unauthorized disclosure.
Credentials shall not knowingly be shared with unauthorized persons.
Talentprobe personnel shall not request another user’s password except where an authorized technical process expressly requires credential reset or replacement without disclosure of the existing password.
28. PRIVILEGED ACCESS
Administrative, elevated, or privileged access shall be restricted to appropriately authorized personnel.
Privileged access may be subject to additional authentication, monitoring, review, or other controls.
29. ACCESS REVIEW
Access rights may be periodically reviewed to determine whether they remain appropriate.
Access should be modified or removed where:
a. responsibilities change;
b. access is no longer required;
c. employment or engagement ends;
d. a security risk exists;
e. access has been improperly used; or
f. another legitimate reason requires restriction.
30. TERMINATION OF ACCESS
Access shall be revoked or appropriately restricted following termination of employment or engagement, subject to established offboarding procedures.
Where circumstances present elevated security risk, access may be suspended immediately.
PART VI
ENCRYPTION AND DATA PROTECTION
31. ENCRYPTION
Talentprobe shall use appropriate encryption or comparable security controls where warranted by the sensitivity of information, method of transmission, storage environment, and associated risk.
32. DATA IN TRANSIT
Sensitive or confidential information transmitted through public or otherwise untrusted networks should be protected using appropriate secure transmission mechanisms.
33. DATA AT REST
Where appropriate, sensitive information stored electronically shall be protected through encryption, access controls, infrastructure security, or other appropriate safeguards.
34. CRYPTOGRAPHIC STANDARDS
Talentprobe shall seek to use cryptographic mechanisms consistent with reasonable security practices appropriate to the relevant technology environment.
Specific cryptographic technologies, algorithms, key lengths, configurations, or providers may change as security practices and technology evolve.
Such technical details may be maintained through internal standards rather than permanently prescribed in this public Policy.
PART VII
INFRASTRUCTURE AND NETWORK SECURITY
35. SECURE INFRASTRUCTURE
Talentprobe shall maintain or use infrastructure with security safeguards appropriate to the nature and sensitivity of information processed.
Infrastructure may be operated directly by Talentprobe, Circa Logica Group, or authorized cloud and technology providers.
36. NETWORK SECURITY
Reasonable controls shall be maintained to protect networks and systems against unauthorized access and malicious activity.
Such controls may include:
a. network filtering;
b. firewall technologies;
c. intrusion detection or prevention capabilities;
d. secure network configuration;
e. segmentation;
f. traffic monitoring;
g. access restrictions;
h. anti-malware protections; and
i. other appropriate safeguards.
37. EXTERNAL THREATS
Talentprobe shall maintain reasonable measures designed to address threats including:
a. malware;
b. ransomware;
c. phishing;
d. credential attacks;
e. unauthorized scanning;
f. malicious network traffic;
g. denial-of-service activity;
h. exploitation of vulnerabilities;
i. unauthorized remote access; and
j. other reasonably foreseeable cyber threats.
38. REMOTE ACCESS
Remote access to Talentprobe systems shall be authorized and appropriately secured.
Additional controls may be applied based on the sensitivity of systems or information being accessed.
39. CLOUD SECURITY
Where cloud infrastructure is used, Talentprobe shall seek to use reputable providers and configure services according to appropriate security requirements.
The use of cloud infrastructure does not eliminate Talentprobe’s responsibility to maintain appropriate security governance over information under its control.
PART VIII
ENDPOINT AND WORKPLACE SECURITY
40. AUTHORIZED DEVICES
Access to sensitive systems may be restricted to authorized or appropriately secured devices where warranted by risk.
41. DEVICE SECURITY
Reasonable endpoint security measures may include:
a. device authentication;
b. operating system updates;
c. anti-malware controls;
d. encryption;
e. endpoint monitoring;
f. automatic locking;
g. remote management;
h. controlled software installation; and
i. other appropriate measures.
42. MOBILE DEVICES
Where mobile devices are authorized to access Talentprobe information, appropriate safeguards shall be applied according to the sensitivity of the information and associated risk.
43. REMOVABLE MEDIA
Use of removable media for sensitive or confidential information may be restricted, controlled, encrypted, or prohibited according to risk.
44. CLEAR DESK AND SCREEN PROTECTION
Personnel shall take reasonable precautions to prevent unauthorized viewing or access to confidential information.
Screens displaying sensitive information should not be left unnecessarily exposed to unauthorized persons.
Physical records should be appropriately secured when unattended.
PART IX
APPLICATION AND SYSTEM SECURITY
45. SECURE DEVELOPMENT
Where Talentprobe develops or materially modifies systems, reasonable security considerations shall be incorporated into the development and deployment lifecycle.
This may include:
a. security requirements;
b. code review;
c. testing;
d. access control;
e. change management;
f. vulnerability assessment;
g. secure configuration; and
h. remediation of identified security issues.
46. CHANGE MANAGEMENT
Material changes to production systems should be appropriately authorized, tested, documented, or reviewed according to the nature and risk of the change.
47. ENVIRONMENT SEPARATION
Where appropriate, development, testing, and production environments may be logically or physically separated to reduce the risk of unauthorized changes or exposure.
48. TEST DATA
Use of live personal information for testing should be minimized where reasonably practicable.
Where personal information is required for legitimate testing, appropriate safeguards shall apply.
PART X
VULNERABILITY AND SECURITY TESTING
49. VULNERABILITY MANAGEMENT
Talentprobe shall maintain reasonable processes for identifying, assessing, prioritizing, and addressing vulnerabilities affecting relevant systems.
50. VULNERABILITY SCANNING
Systems may be subject to periodic or risk-based vulnerability scanning or comparable security assessment.
The frequency and scope of such assessments may vary according to system criticality, threat environment, technology changes, and identified risk.
51. PENETRATION AND SECURITY TESTING
Talentprobe may conduct or commission penetration testing, security assessments, configuration reviews, or other forms of technical testing appropriate to relevant systems.
Testing may be conducted internally or through qualified third parties.
52. REMEDIATION
Identified vulnerabilities shall be evaluated according to risk.
Remediation priority may consider:
a. severity;
b. exploitability;
c. exposure;
d. affected information;
e. system criticality;
f. available mitigations; and
g. potential business or data subject impact.
53. SECURITY TEST CONFIDENTIALITY
Detailed vulnerability findings, penetration test reports, network diagrams, configurations, exploit information, credentials, and remediation details are confidential security information.
Talentprobe may provide appropriate clients with high-level security assurance information without disclosing information that could create additional security risk.
PART XI
LOGGING, MONITORING, AND DETECTION
54. SECURITY MONITORING
Talentprobe shall maintain reasonable capabilities designed to identify unauthorized, anomalous, suspicious, or potentially harmful activity affecting relevant systems.
55. SYSTEM LOGGING
Relevant systems may generate logs concerning:
a. authentication;
b. user access;
c. administrative actions;
d. security events;
e. system activity;
f. changes;
g. errors; and
h. other events relevant to security and accountability.
56. LOG PROTECTION
Security and audit logs shall be protected against inappropriate access, alteration, or deletion according to their sensitivity and purpose.
57. MONITORING LIMITATIONS
Security monitoring is intended to identify and manage risk but does not constitute a guarantee that every malicious or unauthorized activity will be prevented or detected immediately.
PART XII
BACKUP, RECOVERY, AND BUSINESS CONTINUITY
58. BACKUP
Talentprobe shall maintain backup arrangements appropriate to the nature and criticality of relevant information and systems.
59. BACKUP PROTECTION
Backups containing personal or confidential information shall be subject to appropriate security and access controls.
60. RESTORATION
Talentprobe shall maintain reasonable processes for restoring relevant systems or information following disruption, corruption, loss, or other incidents.
61. BUSINESS CONTINUITY
Talentprobe shall maintain business continuity arrangements designed to support critical operations during material disruptions.
Planning may consider:
a. system outages;
b. infrastructure failures;
c. cybersecurity incidents;
d. natural disasters;
e. power or telecommunications disruption;
f. loss of facilities;
g. unavailability of critical providers;
h. workforce disruption; and
i. other material operational events.
62. DISASTER RECOVERY
Where appropriate, disaster recovery arrangements shall establish processes for restoring critical technology and information services following significant disruption.
63. TESTING AND REVIEW
Business continuity, backup, and recovery arrangements may be periodically reviewed, tested, or exercised according to risk and operational requirements.
PART XIII
PERSONNEL SECURITY
64. CONFIDENTIALITY OBLIGATIONS
Personnel with access to confidential or personal information shall be subject to appropriate confidentiality obligations.
65. SECURITY AWARENESS
Talentprobe shall provide personnel with appropriate information security and privacy awareness or training relevant to their responsibilities.
Topics may include:
a. password and authentication security;
b. phishing;
c. social engineering;
d. handling personal information;
e. confidentiality;
f. incident reporting;
g. remote work;
h. device security;
i. acceptable use; and
j. other relevant security risks.
66. ACCEPTABLE USE
Talentprobe systems and information shall be used for authorized purposes.
Personnel shall not knowingly:
a. bypass security controls;
b. share credentials improperly;
c. access information without authorization;
d. install unauthorized malicious software;
e. disclose confidential information without authority;
f. disable required security controls;
g. use Talentprobe systems for unlawful activity; or
h. otherwise intentionally compromise information security.
67. SECURITY VIOLATIONS
Violations of security requirements may result in:
a. suspension of access;
b. investigation;
c. corrective action;
d. disciplinary action;
e. termination of employment or engagement;
f. contractual remedies;
g. legal action; or
h. regulatory referral where appropriate.
PART XIV
THIRD-PARTY SECURITY
68. SERVICE PROVIDERS
Talentprobe may use third-party technology, infrastructure, communications, verification, support, and other service providers.
Third parties that process Talentprobe information shall be subject to security requirements appropriate to the nature of the service and information involved.
69. THIRD-PARTY DUE DILIGENCE
Where appropriate, Talentprobe may assess third-party security based on factors including:
a. nature of information processed;
b. service criticality;
c. security practices;
d. privacy controls;
e. certifications or independent assessments where relevant;
f. incident history where available;
g. business continuity;
h. subcontracting arrangements;
i. location of processing; and
j. contractual safeguards.
70. SECURITY CONTRACT TERMS
Appropriate third-party agreements may contain requirements concerning:
a. confidentiality;
b. authorized use;
c. information security;
d. access restrictions;
e. incident reporting;
f. breach notification;
g. subcontracting;
h. data return or deletion;
i. audit or assurance information; and
j. compliance with applicable law.
71. THIRD-PARTY INCIDENTS
A security incident involving a third-party provider shall be assessed according to its potential effect upon Talentprobe information, systems, clients, and data subjects.
Third-party involvement does not automatically eliminate applicable Talentprobe obligations.
PART XV
SECURITY INCIDENT MANAGEMENT
72. SECURITY INCIDENT
A security incident is an event or series of events that may compromise, or indicate an attempt to compromise, the confidentiality, integrity, availability, or lawful processing of information or information systems.
A security incident does not necessarily constitute a personal data breach.
73. EXAMPLES OF SECURITY INCIDENTS
Security incidents may include:
a. unauthorized access;
b. suspected account compromise;
c. phishing;
d. malware;
e. ransomware;
f. lost or stolen equipment;
g. unauthorized disclosure;
h. accidental transmission to an incorrect recipient;
i. inappropriate system access;
j. unauthorized modification;
k. data loss;
l. system intrusion;
m. credential theft;
n. denial-of-service attack;
o. physical security breach;
p. compromised service provider;
q. unauthorized data extraction;
r. suspicious system activity; or
s. other events presenting material information security risk.
74. PERSONAL DATA BREACH
A personal data breach is a security incident involving personal data that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed, consistent with applicable law.
Personal data breaches may involve:
a. confidentiality;
b. integrity;
c. availability; or
d. combinations of these elements.
PART XVI
SECURITY INCIDENT RESPONSE ORGANIZATION
75. SECURITY INCIDENT RESPONSE TEAM
Talentprobe or Circa Logica Group shall maintain an appropriate Security Incident Response Team or equivalent incident response structure.
The composition of the response team may vary depending upon the nature and severity of the incident.
76. RESPONSE TEAM FUNCTIONS
Incident response may involve representatives from:
a. information technology;
b. information security;
c. Data Privacy, Protection, and Security Office;
d. Data Protection Officer;
e. risk and compliance;
f. operations;
g. management;
h. legal counsel;
i. communications;
j. human resources;
k. affected business functions; and
l. relevant third-party specialists.
77. INCIDENT LEADERSHIP
Material incidents shall be assigned appropriate leadership and decision-making authority.
The incident lead shall coordinate activities necessary to investigate, contain, remediate, document, and communicate the incident.
78. ESCALATION
Incidents shall be escalated according to their nature, severity, potential impact, information involved, affected systems, affected individuals, client implications, and applicable legal requirements.
PART XVII
INCIDENT REPORTING
79. INTERNAL REPORTING OBLIGATION
Personnel shall promptly report suspected security incidents through established channels.
Personnel should not delay reporting merely because:
a. the facts are incomplete;
b. the incident appears minor;
c. no harm has yet been confirmed;
d. the individual believes the problem has already been resolved; or
e. responsibility for the incident is uncertain.
Timely escalation allows appropriate personnel to determine the actual significance of the event.
80. GOOD-FAITH REPORTING
Personnel shall not be penalized merely for reporting a security concern in good faith.
Intentional concealment of a known material security incident may result in appropriate corrective or disciplinary action.
81. CLIENT REPORTING
Clients should report suspected unauthorized access, compromised credentials, erroneous report delivery, or other security concerns involving Talentprobe services through designated support, account management, privacy, or security channels.
PART XVIII
INCIDENT RESPONSE LIFECYCLE
82. IDENTIFICATION
Talentprobe shall seek to determine whether a reported or detected event constitutes:
a. a false alarm;
b. a security event;
c. a security incident;
d. a personal data breach;
e. a material operational incident; or
f. another event requiring action.
83. INITIAL ASSESSMENT
Initial assessment may consider:
a. systems affected;
b. information involved;
c. nature of the event;
d. suspected cause;
e. potential unauthorized access;
f. affected individuals;
g. affected clients;
h. continuing threat;
i. operational impact; and
j. immediate containment requirements.
84. CONTAINMENT
Talentprobe shall take reasonable measures to contain an active security incident.
Containment may include:
a. disabling accounts;
b. resetting credentials;
c. isolating systems;
d. blocking malicious activity;
e. restricting access;
f. removing compromised devices;
g. disabling integrations;
h. suspending affected services;
i. preserving relevant evidence; or
j. other appropriate measures.
85. PRESERVATION OF EVIDENCE
Where appropriate, Talentprobe shall preserve information reasonably necessary to investigate the incident.
Evidence may include:
a. logs;
b. system records;
c. communications;
d. access records;
e. affected files;
f. forensic information;
g. screenshots;
h. device information; and
i. other relevant material.
Evidence shall be protected against unauthorized alteration or destruction.
86. INVESTIGATION
Talentprobe shall investigate material incidents to an extent appropriate to their nature and potential impact.
Investigation may seek to determine:
a. what occurred;
b. when it occurred;
c. how it occurred;
d. systems affected;
e. information affected;
f. persons affected;
g. unauthorized persons involved;
h. duration of exposure;
i. whether information was accessed, acquired, altered, deleted, or disclosed;
j. whether the threat remains active; and
k. what corrective action is required.
87. ERADICATION
Where malicious activity or vulnerability is identified, Talentprobe shall take reasonable measures to remove or address the underlying threat.
This may include:
a. removing malware;
b. disabling compromised accounts;
c. correcting vulnerabilities;
d. applying security updates;
e. changing configurations;
f. replacing credentials;
g. blocking malicious infrastructure; and
h. other appropriate remediation.
88. RECOVERY
Affected systems shall be restored to normal operations when reasonably safe to do so.
Recovery may include:
a. system restoration;
b. data restoration;
c. security validation;
d. enhanced monitoring;
e. credential resets;
f. user communication; and
g. verification that remediation has been effective.
PART XIX
PERSONAL DATA BREACH ASSESSMENT
89. BREACH ASSESSMENT
Where an incident involves personal data, Talentprobe shall conduct an appropriate assessment to determine applicable privacy and breach obligations.
90. FACTORS FOR ASSESSMENT
Assessment may consider:
a. categories of personal data;
b. sensitivity of information;
c. volume of records;
d. number of affected individuals;
e. whether information was encrypted or otherwise protected;
f. likelihood of unauthorized acquisition;
g. identity of the unauthorized recipient where known;
h. likelihood of misuse;
i. possibility of identity fraud;
j. potential financial harm;
k. reputational harm;
l. discrimination;
m. physical or personal safety risks;
n. contractual obligations;
o. client implications;
p. applicable jurisdiction; and
q. other potential harm to data subjects.
91. MANDATORY NOTIFICATION ASSESSMENT
Talentprobe shall assess whether applicable law requires notification to a regulatory authority, affected data subjects, client, or other party.
The existence of a security incident does not automatically mean that regulatory notification is legally required.
Notification shall be determined based upon applicable legal thresholds, contractual requirements, and the circumstances of the incident.
PART XX
CLIENT AND REGULATORY NOTIFICATION
92. TALENTPROBE AS PERSONAL INFORMATION PROCESSOR
Where Talentprobe acts as a Personal Information Processor and becomes aware of a personal data breach affecting information processed on behalf of a client, Talentprobe shall notify the relevant Personal Information Controller in accordance with applicable law and contractual requirements.
Talentprobe shall provide reasonably available information necessary to enable the client to assess and fulfill its own obligations.
93. TALENTPROBE AS PERSONAL INFORMATION CONTROLLER
Where Talentprobe or Circa Logica Group acts as the Personal Information Controller for affected processing, the organization shall assess and fulfill applicable notification requirements.
94. NATIONAL PRIVACY COMMISSION NOTIFICATION
Where mandatory notification requirements under Philippine law are satisfied, the responsible Personal Information Controller shall notify the National Privacy Commission within the period required by applicable law.
Where the applicable requirements mandate notification within seventy-two (72) hours from knowledge or reasonable belief that a qualifying personal data breach has occurred, Talentprobe or Circa Logica Group shall take reasonable measures to comply with that period.
Notification may initially be based on information reasonably available at the time and may be supplemented as further investigation develops.
95. DATA SUBJECT NOTIFICATION
Where required by applicable law, affected data subjects shall be notified within the applicable period.
Notification should be communicated in a manner reasonably designed to enable affected individuals to understand the incident and take appropriate precautions.
96. CONTENT OF BREACH NOTIFICATION
Where applicable, notification may include:
a. nature of the breach;
b. circumstances surrounding the incident;
c. categories of personal information involved;
d. approximate scope of affected records or individuals where known;
e. likely consequences;
f. measures taken to address the incident;
g. measures taken to mitigate potential harm;
h. actions taken to recover or secure information;
i. recommendations to affected individuals where appropriate;
j. measures intended to prevent recurrence; and
k. contact information for further inquiries.
97. INCOMPLETE INFORMATION
Talentprobe shall not unnecessarily delay legally required initial notification solely because every fact has not yet been established.
Where permitted, initial notification may be supplemented as additional verified information becomes available.
98. CONTRACTUAL CLIENT NOTIFICATION
Client contracts or Data Processing Agreements may establish incident notification requirements that are different from regulatory notification thresholds or periods.
Talentprobe shall seek to comply with applicable contractual obligations in addition to mandatory legal requirements.
99. FOREIGN JURISDICTIONS
Where an incident involves information subject to another jurisdiction’s breach notification requirements, Talentprobe shall assess applicable obligations according to its role in the relevant processing activity.
Where appropriate, Talentprobe may coordinate with affected clients, legal counsel, privacy advisers, or competent regulatory authorities.
PART XXI
DATA SUBJECT PROTECTION AND HARM MITIGATION
100. MITIGATION OF HARM
Where a breach may create risk to individuals, Talentprobe shall consider reasonable measures to reduce potential harm.
Measures may include, where appropriate:
a. credential resets;
b. account protection;
c. access revocation;
d. additional authentication;
e. warnings regarding phishing or fraud;
f. instructions concerning protective measures;
g. correction of exposed information;
h. enhanced monitoring; and
i. other measures appropriate to the nature of the incident.
101. CLEAR COMMUNICATION
Breach communications should avoid unnecessarily technical terminology and should provide information reasonably useful to affected individuals.
Talentprobe shall seek to communicate verified information and distinguish confirmed facts from matters still under investigation.
102. PROTECTION AGAINST FURTHER DISCLOSURE
Talentprobe shall seek to avoid unnecessarily reproducing or further exposing compromised personal information while investigating or communicating about an incident.
PART XXII
INCIDENT DOCUMENTATION
103. SECURITY INCIDENT REGISTER
Talentprobe or Circa Logica Group shall maintain appropriate records of security incidents and personal data breaches.
104. INCIDENT RECORD
Incident documentation may include:
a. date and time identified;
b. date and time reported;
c. nature of the incident;
d. systems affected;
e. information involved;
f. persons or clients affected;
g. containment actions;
h. investigation findings;
i. breach assessment;
j. notifications;
k. remediation;
l. recovery;
m. root cause;
n. corrective action; and
o. closure.
105. NON-NOTIFIABLE INCIDENTS
Where a security incident involving personal data does not meet mandatory regulatory notification thresholds, Talentprobe shall nevertheless maintain appropriate documentation where required.
The absence of regulatory notification does not mean that the incident requires no internal review or remediation.
106. REGULATORY REPORTING
Talentprobe or Circa Logica Group shall maintain and submit applicable security incident or breach reports required by competent regulatory authorities.
PART XXIII
POST-INCIDENT REVIEW
107. ROOT CAUSE ANALYSIS
Material security incidents may be subject to root cause analysis.
Root causes may include:
a. technical vulnerabilities;
b. configuration errors;
c. human error;
d. phishing or social engineering;
e. credential compromise;
f. malicious insiders;
g. vendor failures;
h. inadequate processes;
i. physical security failures;
j. software defects; or
k. other contributing factors.
108. CORRECTIVE ACTION
Corrective actions may include:
a. system changes;
b. security updates;
c. configuration changes;
d. additional access restrictions;
e. enhanced monitoring;
f. employee training;
g. procedural changes;
h. vendor remediation;
i. contractual changes;
j. disciplinary action;
k. technology replacement; or
l. other appropriate measures.
109. PREVENTIVE ACTION
Talentprobe shall consider whether lessons from an incident indicate a broader need to improve security controls beyond the directly affected system or process.
110. LESSONS LEARNED
Material incidents may be reviewed to determine:
a. effectiveness of detection;
b. effectiveness of escalation;
c. speed of containment;
d. quality of investigation;
e. effectiveness of communications;
f. regulatory compliance;
g. adequacy of recovery;
h. effectiveness of existing controls; and
i. opportunities for improvement.
PART XXIV
SECURITY ASSURANCE AND CLIENT DUE DILIGENCE
111. CLIENT SECURITY ASSESSMENTS
Talentprobe recognizes that clients may require reasonable information concerning Talentprobe’s security environment as part of vendor accreditation, procurement, risk management, or due diligence.
Talentprobe may provide appropriate information concerning:
a. security governance;
b. privacy controls;
c. access management;
d. encryption;
e. infrastructure security;
f. vulnerability management;
g. backup and recovery;
h. business continuity;
i. incident response;
j. third-party risk management; and
k. other relevant security controls.
112. CONFIDENTIAL SECURITY INFORMATION
Talentprobe reserves the right to restrict disclosure of information that could materially weaken security if publicly released.
This may include:
a. network architecture;
b. IP addresses;
c. firewall configurations;
d. security rules;
e. credentials;
f. cryptographic keys;
g. detailed penetration test findings;
h. unresolved vulnerabilities;
i. detection thresholds;
j. incident response playbooks;
k. security monitoring configurations;
l. infrastructure diagrams; and
m. other information capable of facilitating unauthorized access or attack.
113. CERTIFICATIONS AND ASSURANCE CLAIMS
Talentprobe shall seek to ensure that externally communicated security certifications, attestations, audit results, compliance statuses, or similar assurance claims accurately reflect the relevant scope and current status.
The use of a technology provider that holds a particular certification does not automatically mean that Talentprobe itself holds the same certification.
Talentprobe shall distinguish, where necessary, between:
a. certification held directly by Talentprobe;
b. certification held by Circa Logica Group;
c. certification held by a cloud or service provider;
d. compliance applicable to a particular system or service; and
e. security practices that do not constitute formal certification.
PART XXV
RELATIONSHIP WITH OTHER POLICIES
114. DATA PRIVACY AND PROTECTION POLICY
Personal data processed under this Policy remains subject to Talentprobe’s Data Privacy and Protection Policy.
115. DATA RETENTION AND SECURE DISPOSAL POLICY
Security records, logs, backups, screening information, incident records, and related information shall be retained and disposed of according to Talentprobe’s Data Retention and Secure Disposal Policy and applicable legal requirements.
116. BACKGROUND SCREENING QUALITY AND ACCURACY POLICY
Security measures shall support the integrity and reliability of background screening information in accordance with Talentprobe’s Background Screening Quality and Accuracy Policy.
Unauthorized modification of screening findings shall be treated as both a security and quality concern.
117. CANDIDATE RIGHTS, DISPUTE AND RESOLUTION POLICY
Where a security incident affects candidate rights or screening information, applicable candidate concerns shall also be addressed according to the Candidate Rights, Dispute and Resolution Policy.
118. DATA PROCESSING AGREEMENTS
Where Talentprobe processes personal data on behalf of a client, incident and security responsibilities may be further governed by the applicable Data Processing Agreement or services agreement.
PART XXVI
SECURITY RISK MANAGEMENT
119. SECURITY RISK ASSESSMENT
Talentprobe shall periodically assess information security risks appropriate to its processing activities.
Risk assessments may consider:
a. information sensitivity;
b. threat likelihood;
c. vulnerabilities;
d. potential impact;
e. technology changes;
f. processing volume;
g. access arrangements;
h. third-party dependencies;
i. geographic considerations;
j. regulatory requirements; and
k. other relevant factors.
120. PRIVACY IMPACT ASSESSMENT
Where processing presents material privacy risk, Talentprobe may conduct a Privacy Impact Assessment or comparable assessment in accordance with applicable requirements.
121. RISK TREATMENT
Identified security risks may be:
a. mitigated;
b. avoided;
c. transferred through appropriate contractual or insurance arrangements;
d. accepted by appropriate management authority; or
e. otherwise addressed according to established risk management practices.
122. MATERIAL CHANGES
Material changes to technology, processing activities, infrastructure, vendors, or services may trigger additional security or privacy review where appropriate.
PART XXVII
CONTINUOUS SECURITY IMPROVEMENT
123. REVIEW OF SECURITY CONTROLS
Talentprobe shall periodically review the effectiveness and appropriateness of relevant information security measures.
Review may include:
a. risk assessment;
b. vulnerability assessment;
c. incident analysis;
d. security testing;
e. access review;
f. vendor review;
g. policy review;
h. audit findings;
i. training outcomes; and
j. changes in recognized security practices.
124. EVOLVING THREATS
Talentprobe recognizes that cybersecurity threats evolve.
Security measures may therefore be modified without requiring amendment of this Policy where such changes strengthen or appropriately adapt Talentprobe’s security environment.
125. POLICY REVIEW
This Policy shall be reviewed periodically and may be updated in response to:
a. changes in applicable law;
b. National Privacy Commission requirements;
c. cybersecurity developments;
d. material security incidents;
e. technology changes;
f. business changes;
g. audit findings;
h. risk assessments;
i. client requirements; and
j. recognized security practices.
126. POLICY AVAILABILITY
This Policy is classified as a public policy and may be:
a. published on Talentprobe’s official website;
b. shared with clients;
c. provided during vendor accreditation;
d. submitted in procurement exercises;
e. provided during privacy or security due diligence;
f. shared with auditors or authorized reviewers; and
g. otherwise made available to legitimate stakeholders.
Detailed internal security procedures, configurations, architecture, response playbooks, vulnerability information, and other sensitive security materials shall remain confidential.
PART XXVIII
SECURITY CONTACT AND INCIDENT REPORTING
127. SECURITY AND PRIVACY CONTACT
Questions concerning this Policy, information security, suspected personal data breaches, or privacy-related security matters may be directed to:
Data Privacy, Protection, and Security Office
Talentprobe Due Diligence / Circa Logica Group
Email: privacy@circalogicagroup.com
Additional security, client support, candidate support, or emergency escalation channels may be maintained internally or provided directly to clients as appropriate.
128. REPORTING SUSPECTED INCIDENTS
Clients, candidates, employees, partners, and other stakeholders who become aware of suspected unauthorized access, disclosure, loss, alteration, or misuse of Talentprobe information are encouraged to report the matter promptly through the appropriate Talentprobe or Circa Logica Group channel.
Reports should contain sufficient information to enable Talentprobe to identify and investigate the concern, but reporters should avoid unnecessarily transmitting additional sensitive personal information through unsecured channels.
PART XXIX
POLICY INTERPRETATION
129. NO ABSOLUTE SECURITY GUARANTEE
Talentprobe maintains reasonable and appropriate safeguards designed to protect information.
No organization, information system, cloud environment, communication channel, or security technology can reasonably guarantee absolute protection against every possible threat.
Nothing in this Policy should therefore be interpreted as an absolute warranty that a security incident can never occur.
Talentprobe’s commitment is to maintain appropriate preventive controls, detect and respond to incidents responsibly, mitigate harm, comply with applicable notification requirements, and continuously improve its security environment.
130. LEGAL AND CONTRACTUAL REQUIREMENTS
Where applicable law imposes a higher mandatory security or breach-management requirement than this Policy, the applicable legal requirement shall prevail.
Where a binding client agreement establishes additional lawful security requirements, Talentprobe shall comply with those requirements according to the terms of the agreement.
131. INTERPRETATION
Questions concerning the interpretation or application of this Policy shall be referred to the Data Privacy, Protection, and Security Office, Data Protection Officer, authorized management, legal counsel, or another appropriate responsible function.
PART XXX
TALENTPROBE INFORMATION SECURITY COMMITMENT
132. OUR COMMITMENT
Information security is fundamental to the trust placed in Talentprobe.
Candidates entrust Talentprobe with information that may relate to their identity, employment, education, qualifications, professional history, and other aspects of their personal and professional lives.
Clients entrust Talentprobe with screening requests, reports, credentials, business information, and information necessary to support important employment and risk decisions.
Talentprobe accepts the responsibility that accompanies that trust.
We therefore commit to maintaining reasonable and appropriate measures designed to:
protect personal and confidential information against unauthorized access;
preserve the confidentiality, integrity, and availability of information;
restrict access according to legitimate business need;
protect information during storage, transmission, processing, and disposal;
maintain appropriate authentication and access controls;
identify and address security vulnerabilities;
monitor for material security threats;
maintain appropriate backup, recovery, and business continuity arrangements;
manage third-party security risks;
identify and escalate suspected security incidents promptly;
contain and investigate security incidents responsibly;
assess personal data breaches according to applicable legal requirements;
notify clients, regulators, and affected individuals when notification is required;
mitigate potential harm arising from security incidents;
learn from incidents and implement appropriate corrective measures; and
continuously improve the security of Talentprobe’s people, processes, systems, and information.
Security is not treated solely as a technology function.
It is an organizational responsibility and an essential component of responsible due diligence.
