Information Security Policy

Christianson Syndrome Association
Information Security Policy Agreement & Commitment

Date: July 24, 2026 (Policy Effective/Review Date)
Organization: Christianson Syndrome Association (CSA)

Formal Statement of Agreement and Commitment

Christianson Syndrome Association hereby formally agrees to and commits to full compliance with the Information Security Policy (PCI) dated July 24, 2026.

As an organization, CSA affirms and adopts the entire policy as our official standard for protecting confidential company information, cardholder data, customer privacy, and all sensitive assets. We commit to implementing, enforcing, and maintaining all measures outlined in the policy to safeguard data, ensure regulatory compliance (including PCI DSS where applicable), and protect the future of the organization.

Key Commitments by Christianson Syndrome Association:

  • We will distribute this policy to all employees and contractors, require them to read and understand it, and obtain signed acknowledgments of compliance.
  • We will review and update this policy annually or as needed to incorporate new security standards.
  • Management is committed to maintaining a secure environment for processing information and respecting the privacy of all customers and partners.
  • We will enforce all sections of the policy, including:
    • Network Security — Maintaining network diagrams, conducting quarterly ASV scans where required, and protecting the cardholder data environment (CDE).
    • Acceptable Use Policy — Promoting a culture of openness, trust, and integrity while preventing illegal or damaging actions.
    • Protect Stored Data — Strictly prohibiting storage of sensitive authentication data (track data, CVV2/CVC2, PINs, etc.) and ensuring proper masking and protection of cardholder data.
    • Information Classification — Properly labeling and handling data according to its sensitivity (Confidential, Internal Use, Public).
    • Access Controls — Restricting access to sensitive data on a need-to-know basis, using least privilege, and maintaining formal user access management processes.
    • Physical Security — Restricting physical access, escorting visitors, inspecting devices for tampering, and securing media.
    • Data in Transit & Disposal — Protecting data during transport with strong encryption and securely disposing of data (physical and electronic) when no longer needed.
    • Security Awareness, Incident Response, and User Access Management — Providing annual training, maintaining an incident response plan, and ensuring strong password and authentication controls.
  • We will maintain required appendices, including lists of approved devices, service providers, and responsibility matrices.
  • We will monitor compliance, conduct regular reviews, and take appropriate disciplinary action (up to and including termination and legal remedies) for any violations.
  • We commit to promptly reporting and addressing any information security incidents.

Organizational Attestation

Christianson Syndrome Association, through its management, officially adopts and agrees to abide by this Information Security Policy in full. We understand our responsibility to protect systems and data from unauthorized access or improper use. We will allocate necessary resources to maintain a strong security posture and support all employees in fulfilling their obligations under this policy.

This document serves as CSA’s official organizational agreement with and commitment to the Information Security Policy. It supplements the individual Appendix A – Agreement to Comply Form that each employee and contractor must sign.

For reference, the full policy is available here:

http://csa-cares.org/wp-content/uploads/2026/07/Information_Security_Policy-PCI.pdf

Questions or concerns regarding this policy should be directed to designated management or the Information Security Officer.