Information Security Policy
The security standards and controls required to safeguard Company information, customer data, distributor records, financial information, and technology infrastructure.
Mojeaga Network ("Company," "we," "our," or "us") is committed to protecting the confidentiality, integrity, and availability of its information assets. This Information Security Policy establishes the security standards and controls required to safeguard Company information, customer data, distributor records, financial information, intellectual property, and technology infrastructure against unauthorized access, disclosure, alteration, destruction, or loss. This Policy applies to all employees, directors, distributors, contractors, consultants, temporary staff, and third-party service providers who access or process Company information.
1. Password Standards
Strong passwords are the first line of defence against unauthorized access. All users with access to Company systems must comply with the following requirements:
Password Requirements
Passwords should:
- Contain at least 12 characters.
- Include uppercase and lowercase letters.
- Include numbers.
- Include special characters where supported.
- Avoid dictionary words or predictable patterns.
- Be unique to each account.
Passwords must not:
- Be shared with another person.
- Be written where unauthorized persons can access them.
- Be reused across multiple business systems.
- Contain easily guessed information such as birthdays or names.
The Company reserves the right to require periodic password changes where appropriate or where security risks have been identified.
2. Multi-Factor Authentication (MFA)
To strengthen account security, Multi-Factor Authentication (MFA) should be enabled wherever technically feasible, particularly for:
- Administrative accounts.
- Distributor Back Office accounts.
- Finance and payment systems.
- Customer databases.
- Cloud services.
- Email accounts.
- Remote access systems.
Accepted second authentication factors may include:
- Authentication applications.
- One-Time Passwords (OTP).
- Hardware security keys.
- Biometric authentication where supported.
Users must immediately report any loss or compromise of authentication devices.
3. Data Encryption
Sensitive information must be protected using appropriate encryption technologies during transmission and, where practical, while stored.
Data in Transit
- HTTPS (TLS/SSL) for websites.
- Secure APIs.
- Encrypted email where appropriate.
- Secure file transfer protocols.
Data at Rest
Sensitive information such as:
- Personal data.
- Financial records.
- Commission information.
- Identity verification documents.
- Passwords (stored only as secure cryptographic hashes).
- Backup files.
should be protected using industry-accepted encryption or hashing methods appropriate to the level of risk.
Encryption keys shall be protected against unauthorized access and managed according to documented security procedures.
4. Backup Policy
Mojeaga Network maintains regular backups to support business continuity and disaster recovery.
Backups may include:
- Customer databases.
- Distributor genealogy.
- Financial records.
- Commission records.
- Product information.
- Website content.
- System configurations.
- Business documents.
Backup procedures should include:
- Scheduled automated backups.
- Secure off-site or cloud storage.
- Encryption of backup media where appropriate.
- Periodic testing of restoration procedures.
- Protection against unauthorized access.
Backup retention periods shall be determined according to operational, legal, and regulatory requirements.
5. Cybersecurity
The Company implements a layered cybersecurity programme to reduce information security risks.
Security measures may include:
- Firewalls.
- Anti-malware protection.
- Endpoint security.
- Intrusion detection and monitoring.
- Security logging.
- Vulnerability assessments.
- Timely software updates and patch management.
- Access controls based on least-privilege principles.
- Network segmentation where appropriate.
- Secure software development practices.
- Security awareness training.
Users must not:
- Install unauthorized software.
- Disable security controls.
- Attempt unauthorized access to systems or data.
- Share confidential Company information without authorization.
- Connect unauthorized devices to Company networks.
Suspected phishing emails, malware infections, or other cybersecurity threats should be reported immediately.
6. Incident Response
All actual or suspected information security incidents must be reported promptly to the Company’s Information Security or Compliance Team.
Examples of security incidents include:
- Unauthorized system access.
- Lost or stolen devices.
- Malware or ransomware infections.
- Data breaches.
- Accidental disclosure of confidential information.
- Password compromise.
- Denial-of-service attacks.
- Insider threats.
- Unauthorized modification or deletion of data.
Upon notification, the Company may:
- Contain the incident.
- Investigate the cause.
- Preserve relevant evidence.
- Assess affected systems and data.
- Notify affected individuals or regulatory authorities where required by law.
- Implement corrective and preventive measures.
- Restore normal operations.
Employees and contractors are expected to cooperate fully with incident investigations.
7. Access Control
Access to Company systems and information shall be granted on the principle of least privilege, meaning users receive only the access necessary to perform their authorized duties.
Access rights shall be:
- Approved by authorized personnel.
- Reviewed periodically.
- Updated when job responsibilities change.
- Revoked promptly upon termination of employment or business relationships.
8. Information Classification
Company information should be classified according to its sensitivity and handled accordingly. Categories may include:
- Public – Information approved for public release.
- Internal – Information intended for internal business use.
- Confidential – Sensitive business or customer information requiring restricted access.
- Highly Confidential – Critical information such as KYC records, financial data, security credentials, and strategic business information requiring enhanced protection.
9. Business Continuity
Mojeaga Network will maintain reasonable business continuity and disaster recovery arrangements to minimize disruption caused by cyber incidents, equipment failures, natural disasters, or other emergencies.
Recovery objectives will be reviewed periodically and tested where practical.
10. Training and Awareness
The Company will provide periodic information security awareness training to employees and other relevant personnel covering topics such as:
- Password security.
- Phishing awareness.
- Data protection.
- Safe internet practices.
- Social engineering.
- Incident reporting.
- Secure handling of confidential information.
Completion of mandatory security training may be required as a condition of continued system access.
11. Policy Compliance
Violations of this Information Security Policy may result in:
- Temporary suspension of system access.
- Disciplinary action.
- Termination of employment or distributorship.
- Civil recovery of losses.
- Referral to law enforcement where appropriate.
12. Policy Review
This Policy will be reviewed periodically to ensure alignment with evolving legal, regulatory, technological, and business requirements.
Revisions become effective upon publication through official Company communication channels.
13. Contact Information
For questions regarding information security or to report a suspected security incident, please contact:
Mojeaga Network
Information Security & Compliance Department
Email: security@mojeaganetwork.com
Website: https://mojeaganetwork.com
Business Hours: Monday – Friday, 9:00 a.m. – 5:00 p.m. (West Africa Time)
Acknowledgement: All employees, distributors, contractors, consultants, and authorized users of Mojeaga Network systems are required to comply with this Information Security Policy. By accessing or using Company systems, you acknowledge that you have read, understood, and agreed to comply with the security requirements set out in this Policy.
