Information Security Policy
PT Divistant Teknologi Indonesia (trading as "Divistant")
Last Updated: February 24, 2026
1. Introduction & Commitment
PT Divistant Teknologi Indonesia ("Divistant") recognizes that information security is fundamental to our business and to the trust our clients place in us. As a full-stack IT company providing consulting, SaaS products, system integration, and managed services, we are committed to protecting the confidentiality, integrity, and availability of all information assets — ours, our clients', and our partners'.
This policy outlines our approach to information security and the measures we implement to safeguard data and systems.
2. Scope
This Information Security Policy applies to:
- All information assets owned, managed, or processed by Divistant
- All IT systems, networks, applications, and infrastructure
- All employees, contractors, and third parties with access to Divistant's systems
- All client data processed through our services
- Physical and virtual environments
3. Security Principles
Our information security program is built on the following principles:
- Confidentiality: Ensuring that information is accessible only to authorized individuals
- Integrity: Safeguarding the accuracy and completeness of information and processing methods
- Availability: Ensuring that authorized users have access to information and systems when needed
- Defense in Depth: Implementing multiple layers of security controls
- Least Privilege: Granting only the minimum access necessary for each role
- Continuous Improvement: Regularly assessing and improving our security posture
4. Access Control
- Role-Based Access Control (RBAC): Access to systems and data is granted based on job roles and responsibilities
- Multi-Factor Authentication (MFA): Required for access to all critical systems and administrative functions
- Password Policy: Strong password requirements with regular rotation for privileged accounts
- Access Reviews: Regular reviews of user access rights to ensure appropriateness
- Offboarding: Immediate revocation of access upon termination of employment or contract
5. Data Protection
- Encryption in Transit: All data transmitted over networks is encrypted using TLS 1.2 or higher
- Encryption at Rest: Sensitive data stored in databases and file systems is encrypted using AES-256
- Data Classification: Information is classified based on sensitivity (Public, Internal, Confidential, Restricted) with appropriate controls for each level
- Data Loss Prevention: Controls are in place to prevent unauthorized data exfiltration
- Secure Disposal: Data is securely deleted or destroyed when no longer needed
For details on personal data protection, see our Privacy Policy, GDPR Compliance, and UU PDP Compliance pages.
6. Network & Infrastructure Security
- Firewalls & Network Segmentation: Network perimeters are protected by firewalls with segmentation to isolate critical systems
- Intrusion Detection & Prevention: IDS/IPS systems monitor network traffic for suspicious activity
- DDoS Protection: Distributed denial-of-service mitigation is in place for public-facing services
- VPN: Secure VPN connections are required for remote access to internal systems
- Logging & Monitoring: Comprehensive logging of system and network events with centralized monitoring and alerting
7. Application Security
- Secure SDLC: Security is integrated into every phase of our software development lifecycle
- Code Review: All code changes undergo peer review with security considerations
- Vulnerability Scanning: Regular automated scanning of applications for security vulnerabilities
- Dependency Management: Third-party libraries and dependencies are regularly updated and scanned for known vulnerabilities
- OWASP Compliance: Development practices align with OWASP Top 10 guidelines to prevent common web application vulnerabilities
8. Endpoint Security
- Device Management: All company devices are managed centrally with security policies enforced
- Anti-Malware: Endpoint protection software is deployed on all devices
- Patch Management: Operating systems and software are kept up-to-date with security patches
- Disk Encryption: Full disk encryption is enabled on all company laptops and mobile devices
- BYOD: Personal devices accessing company resources must comply with our security requirements
9. Incident Response
Divistant maintains a formal incident response plan:
- Detection: Continuous monitoring to identify security incidents promptly
- Containment: Rapid containment to minimize the impact of security incidents
- Investigation: Thorough root cause analysis of all security incidents
- Notification: Timely notification to affected parties as required by law (72 hours under GDPR, 3x24 hours under UU PDP)
- Recovery: Restoration of affected systems and data
- Post-Incident Review: Lessons learned are documented and controls are improved
10. Vendor & Third-Party Security
- Due Diligence: Security assessments are conducted before engaging third-party vendors
- Contractual Requirements: Security and data protection obligations are included in all vendor agreements
- Ongoing Monitoring: Vendor security practices are reviewed periodically
- Data Processing Agreements: DPAs are in place with all vendors who process personal data on our behalf
11. Security Awareness & Training
- All employees receive security awareness training during onboarding and annually thereafter
- Specialized training is provided for technical roles (secure coding, incident response)
- Regular phishing simulations are conducted to test and improve awareness
- Security policies and best practices are communicated regularly
12. Compliance & Standards
Our information security practices are aligned with:
- ISO 27001: Information Security Management System framework
- NIST Cybersecurity Framework: Risk-based approach to managing cybersecurity
- OWASP: Application security guidelines
- PP 71/2019: Indonesian regulation on Electronic Systems and Transactions
We are continuously working toward formal certifications to demonstrate our commitment to security excellence.
13. Contact Information
For questions about our information security practices or to report a security concern:
- Security Team: divistant.com/contacts
- Report Security Incidents: divistant.com/contacts
- Company: PT Divistant Teknologi Indonesia, Jakarta, Indonesia