1. Cybersecurity
System and data security regulations
1.1. Passwords: Use strong passwords (minimum 12 characters, including uppercase, lowercase, numbers and special characters), do not share, do not reuse across systems.
1.2. Multi-factor Authentication (MFA): Mandatory 2FA for all critical systems (email, VPN, cloud, source control).
1.3. System Access: Apply the Least Privilege principle - only grant access necessary for the job.
1.4. Incident Reporting: Any suspected security incident must be reported immediately through designated security channels.
1.5. Software Updates: Ensure operating systems, software, and browsers are always updated with the latest security patches.
2. Responsible AI Use
Ethical guidelines for AI usage
2.1. Transparency: Must clearly disclose when AI is used in products/services that make decisions affecting users.
2.2. Data Privacy: Do not input customer data, confidential information into public AI tools (ChatGPT, Claude, Gemini...) without approval.
2.3. Output Review: Code and content generated by AI must be thoroughly reviewed before being incorporated into products.
2.4. Bias Avoidance: Evaluate and minimize bias in AI systems being developed.
2.5. Copyright Compliance: Do not use AI to create content that infringes on third-party copyrights or trademarks.
3. Intellectual Property (IP)
Protecting company intellectual assets
3.1. Source Code Security: Source code is company property, not to be shared or copied externally without approval.
3.2. Non-Disclosure Agreement (NDA): Sign NDA before accessing company or customer confidential information.
3.3. Invention Ownership: Inventions and patents created during employment belong to the company (per employment contract).
3.4. Software Use: Only use legally licensed software or open source with appropriate licenses.
3.5. Return Upon Departure: Return all documents, code, equipment upon contract termination. Do not retain copies.
4. Data Management
Data collection, storage, processing policies
4.1. Data Collection: Only collect necessary data with clear consent from data subjects.
4.2. Secure Storage: Sensitive data must be encrypted at-rest and in-transit.
4.3. Data Classification: Apply classification system (Public, Internal, Confidential, Restricted) to apply appropriate protective measures.
4.4. Processing and Deletion: Have procedures to handle access, modification, deletion requests of personal data as required by law.
4.5. Regulatory Compliance: Ensure compliance with regulations such as Decree 13/2023/ND-CP (Vietnam), GDPR (EU), CCPA (California) if applicable.
