At TVO, we sign Non-Disclosure Agreements with all our Employees to safeguard our clients' data. This practice provides a structured and legally enforceable framework for maintaining confidentiality. By signing a NDA, Employees are legally bound to handle all sensitive information provided by clients in a manner that prevents unauthorized access and disclosure. To ensure compliance, our NDAs include a clause stating that any unauthorized disclosure or misuse of confidential information will result in stringent legal action, including criminal charges under the Sri Lankan Computer Crime Act No. 24 of 2007 and civil action for damages. This clause not only underscores the seriousness with which we treat data breaches but also provides a clear and immediate recourse in the event of a breach.
To enhance data security, we have implemented a strict policy prohibiting the storage of files locally on the devices used by our VAs. Instead of local storage, we require that files be stored on secure cloud-based platforms such as Microsoft Teams. These platforms offer built-in encryption and access controls that safeguard stored data from unauthorized access or tampering. In cases where a document needs to be downloaded and worked on locally, our policy requires that the document be deleted from the device at the end of the working day. This ensures that sensitive information is not inadvertently exposed or compromised by remaining on the device beyond the necessary timeframe.
We implement strict access controls to ensure that only authorized personnel have access to your data. Our access management protocols include multi-factor authentication and regular access reviews.
We ensure that only licensed versions of software are installed on the devices used by our employees. This includes operating systems, productivity suites, and any other software necessary for performing their duties. To bolster the security of our systems, we enforce multi-factor authentication (MFA) for accessing company email accounts and collaboration platforms such as Microsoft Teams. MFA requires the employees to provide a one-time password (OTP) sent to their mobile phones every time they log in. This significantly reduces the risk of unauthorized access, even if login credentials are compromised.
The TVO IT team ensures that every device used by our employees is equipped with updated anti-virus and anti-ransomware software which are configured to conduct real-time scanning of all files, programs, and processes on each device. Additionally, we schedule full scans of each device at regular intervals to comprehensively examine the entire system for any hidden or dormant threats.