LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Human Resources Security Policy

Public security and assurance reference

POL-14: Human Resources Security Policy

Purpose

This policy establishes the security requirements for human resources processes to protect LNC Nexus systems and data. It ensures that personnel are vetted, trained, and managed securely.

Scope

This policy applies to all employees, contractors, consultants, temporary staff, and third-party vendors who interact with LNC Nexus hosted, private, or self-managed deployments.

Policy Statements

Personnel shall be vetted before access is granted. Security training must be provided regularly. In self-managed deployments, customers are responsible for their own personnel security; LNC Nexus provides the framework but not the enforcement. Regulated data handling requires additional personnel controls. No personnel shall have access without proper vetting and training.

Roles and Responsibilities

The Security Team defines personnel security standards and monitors compliance. Human Resources implements vetting and training procedures. Department heads ensure compliance in their areas. Users follow security training requirements.

Evidence and Review

Vetting records, training logs, and audit reports serve as evidence of compliance. The Security Team conducts periodic reviews of personnel security practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Access may be suspended immediately upon detection of a violation.

POL-1 (Access Control Policy), POL-2 (Authentication and Password Policy), POL-13 (Acceptable Use Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft