Studio - Information Security Management Policy Effective: 21 July 2026 1. Purpose. This policy establishes Studio's framework for protecting the confidentiality, integrity and availability of client content and company information. 2. Scope. Applies to all staff, freelancers, contractors and systems that store, process or transmit content or sensitive data. 3. Principles. Least privilege; defence in depth; secure by design; auditability; data minimisation. 4. Roles. A designated Security Lead owns this policy and reviews it at least annually and after any major change or incident. 5. Controls. Access control, content watermarking, encryption, logging/monitoring, secure delivery, vulnerability management and incident response are maintained per the supporting policies and the platform configuration. 6. Compliance. Non-compliance may result in disciplinary action. This policy aligns with the MPA Content Security Best Practices.