Information Security Policy (ISP)
This ISP is an updated summary of the technical and organizational information security measures implemented by PragmaCharge
1. GENERAL INFORMATION
1.1. PragmaCharge has established and implements a formal Information Security Policy (ISP) that is kept up to date to protect the confidentiality, integrity, authenticity, and availability of data and information systems, and to ensure the effectiveness of security controls over such data and information systems that support operations.
1.2. The ISP includes: (a) a risk management framework; (b) access control; (c) security of facilities, the cloud, the network, and devices; (d) third-party vendor management; (e) incident response and remediation; (f) training and awareness; (g) compliance and auditing; and (h) continuous improvement.
1.3. User privileges are actively managed and reviewed periodically.
1.4. PragmaCharge employs monitoring and logging technology to help detect and prevent attempts at unauthorized access to its network and equipment.
2. STAFF
2.1. PragmaCharge staff undergo reasonable and appropriate background checks for their role prior to hiring (as permitted by local law).
2.2. PragmaCharge staff are subject to contractual provisions covering confidentiality, personal data protection, and information security, and must comply with the ISP (including the underlying processes and procedures).
2.3. PragmaCharge employees who violate the ISP may be subject to disciplinary action, including warnings, suspension, and even termination.
2.4. PragmaCharge restricts access to information solely to those who need to know it to perform their duties.
2.5. PragmaCharge revokes access for individuals who no longer require it (including upon termination).
3. FACILITIES
3.1. PragmaCharge facilities require visitors to register and wear a visitor badge.
3.2. PragmaCharge escorts all visitors as they move through the facilities.
3.3. PragmaCharge facilities have physical entry points with electronic access doors, which allow entry only to authorized individuals.
3.4. Wi-Fi networks are password-protected.
4. GOOGLE CLOUD PLATFORM
4.1. PragmaCharge uses https://cloud.google.com (GCP).
4.2. The GCP Trust Center is available here: https://cloud.google.com/trust-center?hl=en (GCP Trust Center).
4.3. PragmaCharge periodically reviews the GCP Trust Center.
5. SOFTWARE DEVELOPMENT
5.1. PragmaCharge maintains and enforces a formal Platform Development Lifecycle Policy (PDLP), which is kept up to date.
5.2. The PDLP includes: (a) security requirements analysis, (b) secure design principles, (c) secure coding practices, (d) security testing, (e) third-party component management, (f) secure deployment practices, (g) incident response and resolution, (h) training and awareness, (i) compliance and auditing, (j) continuous improvement.
6. ETAAS ELECTRIC TRUCKS
6.1. Battery Electric Trucks (BETs) are manufactured by Original Equipment Manufacturers (OEMs).
6.2. Battery Electric Trucks (BETs) are subject to any security configuration (physical, software, connectivity, etc.) established by the corresponding OEM.
7. ETAAS CHARGING STATIONS
7.1. The chargers at Charging Stations (CS) are manufactured by OEMs and are connected to a local electricity provider (Electricity Provider).
7.2. The chargers are subject to any security configurations (physical, software, connectivity, etc.) established by the OEMs and/or the corresponding Electricity Provider.
8. RESILIENCE AND RECOVERY
8.1. PragmaCharge has implemented a Disaster Recovery Plan (DRP) that is kept up to date.
8.2. The DRP includes: (a) an asset inventory, (b) critical functions and prioritization, (c) a recovery plan, (d) a communication plan (internal and with customers), (e) arrangements for alternative sites or working from home, and (f) compliance and insurance.
8.3. PragmaCharge conducts an annual desk-top exercise on the DRP.