Boss Key

Governance Document

Boss Key Information Security Policy

This policy defines the minimum security controls Boss Key applies when building, deploying, and supporting software and automation for client environments, including Microsoft 365-connected solutions.

Document ID BK-ISP-001
Version 1.0
Effective Date March 2, 2026
Owner Boss Key
Client Security Review Copy

1. Purpose

This policy defines the minimum security requirements Boss Key follows when designing, developing, deploying, and supporting software and agents for private-sector clients, including Microsoft 365-connected solutions.

2. Scope

3. Security Principles

4. Governance and Responsibility

5. Identity and Access Management

6. Client Tenant Access (M365/Entra)

7. Data Protection

8. Secrets and Key Management

9. Secure Development and Change Management

10. Logging and Monitoring

11. Incident Response

12. Business Continuity

13. Third-Party and Subprocessor Management

14. Personnel Security and Awareness

15. Compliance, Exceptions, and Review

Appendix A: Minimum Engagement Control Checklist

Appendix B: Client Shared Responsibility Statement

Unless otherwise contracted:

Boss Key LLC | Information Security Policy | Version 1.0