Security

Information Security Policy

How OZPlug protects sensitive information, customer privacy, payment-related data, and internal security operations.

Last updated: July 7, 2025 · Effective: July 3, 2025

OZPLUG
4030 Wake Forest Road Raleigh, NC 27609

Overview

Introduction

This Policy encompasses all aspects of security surrounding confidential OZPlug information and must be distributed to all OZPlug employees and contractors. All personnel must read this document in its entirety and sign the acknowledgement form confirming they fully understand the policy. Management reviews and updates this document annually, or sooner if new security standards require.

Policy

Information Security Policy

OZPlug handles sensitive information daily. Adequate safeguards must protect account data—including cardholder data and customer privacy—to ensure regulatory compliance and safeguard the future of the organisation.

OZPlug commits to maintaining a secure environment for processing cardholder information. Employees handling sensitive data shall:

  • Handle OZPlug information according to its sensitivity and classification.
  • Limit personal use of company information systems and ensure it does not interfere with job performance.
  • Recognise that OZPlug reserves the right to monitor, access, review, audit, copy, store, or delete any electronic communications, equipment, systems, and network traffic for any purpose.
  • Refrain from using company resources for offensive, discriminatory, defamatory, harassing, or illegal activities.
  • Protect sensitive account data, including cardholder information.
  • Keep passwords and accounts secure.
  • Obtain management approval before installing new software or hardware or establishing third-party connections.
  • Leave desks clear of sensitive data and lock computer screens when unattended.
  • Report information-security incidents without delay to the designated incident-response contact.
  • Attend annual security-awareness training.

1

Network Security

A high-level network diagram of the cardholder-data environment (CDE) is maintained and reviewed annually. Approved Scanning Vendor (ASV) scans are performed quarterly (every 90–92 days) and evidence retained for 18 months. For e-commerce, scans include any redirect/iFrame servers.

2

Acceptable Use Policy

  • Employees must exercise good judgment regarding personal use.
  • Prevent unauthorised access to confidential data, including cardholder data.
  • Keep passwords secure and do not share accounts.
  • All workstations require password-protected screen-savers.
  • Device inventory is maintained and inspected for tampering or substitution.
  • Exercise caution with email attachments from unknown senders.
  • Address: 5540 Centerview Dr Ste 204 #286972, Raleigh, NC 27606, USA.

3

Protect Stored Data

  • OZPlug does not store electronic PAN or sensitive authentication data.
  • Any hard-copy card data is protected and destroyed when no longer needed.
  • If PAN must be displayed, mask to first six and last four digits.
  • Never store magnetic-stripe data, CVV2/CVC2/CID, or PIN/PIN block.

4

Information Classification

Confidential
Legal/financial data, cardholder data.

Internal Use
Proprietary but not confidential.

Public
Freely distributable.

5

Access to Sensitive Cardholder Data

  • Access is limited to those with legitimate business need.
  • Display of PAN is limited to the first six and last four digits.
  • A list of approved third-party service providers is maintained.
  • Due-diligence processes ensure TPSP PCI DSS compliance.

6

Physical Security

  • Media containing sensitive data is physically restricted.
  • Visitors are escorted in secure areas.
  • The device list includes make, model, location, and serial number.
  • POS/POI devices are inspected for tampering.

7

Protect Data in Transit

  • Card data is never sent via clear-text email or chat.
  • Strong encryption (TLS 1.2+, AES, PGP) is required for authorised transmissions.
  • Physical transport of sensitive media must be logged and sent via secure courier.

8

Disposal of Stored Data

  • Data is securely destroyed when no longer required.
  • Electronic media is degaussed or wiped; paper is cross-cut shredded.

9

Security Awareness and Procedures

  • The policy is distributed to all employees and acknowledgement is retained.
  • Background checks are performed within legal limits.
  • Third parties accessing card data must contractually comply with PCI DSS.
  • Policies are reviewed annually.

10

Credit Card (PCI) Security Incident Response Plan

The PCI Response Team includes the CIO, Information Security Officer, Risk Manager, and other designated personnel.

Incidents are reported immediately and investigated; affected parties and card brands are notified in accordance with their requirements.

Detailed response steps for Visa, MasterCard, Discover, and American Express are included in the internal incident-response process.

11

Transfer of Sensitive Information Policy

Third-party companies must have service-level agreements and comply with OZPlug security policies and PCI DSS.

12

User Access Management

A formal user-registration process, unique IDs, and the least-privilege principle are used. Accounts are disabled immediately upon termination.

13

Access Control Policy

Active Directory enforces complex passwords with a minimum of eight characters and password changes every 90 days. Privileged access requires dual authorisation. Remote access follows the approved Remote Access Policy.

Appendices

Appendices

Appendix A – Agreement to Comply Form
Employee acknowledgment form.

Appendix B – List of Devices
To be populated.

Appendix C – List of Third-Party Service Providers

  • Clover (Fiserv) — Payment gateway & merchant processing — PCI DSS compliant: Yes (Level 1) — Validation date: Dec 2024.
  • Hostinger International Ltd. — Managed e-commerce web hosting — Shared hosting; merchant responsible for securing environment — Validation date: N/A.
  • Automattic Inc. – WooPayments — Embedded gateway plugin — PCI DSS compliant: Yes (Level 1) — Validation date: Mar 2025.
  • Apple Inc. (Apple Pay) — Digital wallet & tokenisation — PCI DSS compliant: Yes (Level 1) — Validation date: Nov 2024.

Appendix D – Stand-Alone & P2PE POI Management Policy

  • Maintain an up-to-date inventory of all POI devices, including make, model, location, and serial number.
  • Establish procedures for securely adding, relocating, and decommissioning POI devices.
  • Secure POI devices with tamper-evident seals or locked enclosures.
  • Inspect devices at least quarterly and log inspections.
  • Store unused devices in a locked cabinet or secure room.
  • Configure POI devices according to manufacturer and PCI PTS guidelines.
  • Change default passwords and restrict administrative access.
  • Apply firmware and security patches promptly.
  • Restrict physical and logical access to authorised personnel.
  • Use unique credentials for administrative access and MFA where possible.
  • Segregate duties to prevent unauthorised changes.

Appendix E – eCommerce Configuration & Hardening Policy

  • Remove unnecessary services and default accounts.
  • Enforce TLS 1.2+ for all public-facing services.
  • Implement file-integrity monitoring.
  • Apply operating-system and application patches within 30 days.
  • Deploy anti-malware and endpoint-detection tools.
  • Limit root/administrator access and enforce MFA.
  • Maintain audit logs for all administrative actions.
  • Perform quarterly vulnerability scans and scans after significant changes.
  • Remediate critical findings within 30 days.
  • Maintain daily off-site backups and test restores annually.
  • Enable real-time alerting through WAF and IDS capabilities.
  • Follow the Incident Response Plan for any detected compromise.

Contact

Questions

For questions regarding this Information Security Policy, contact the Security Officer through our Contact Page.

© 2026 OZPLUG. All rights reserved.

Security policy questions?

For questions regarding this Information Security Policy, contact the Security Officer through our Contact Page.

Contact support