← TPN pack
Download .txt
Security Policy Templates
Ready-to-adopt written policies for MPA / TPN readiness, pre-filled with your studio
name. The MPA Best Practices expect these in writing. Review, edit to your studio, and adopt - then
they cover the policy controls in your assessment.
Information Security Management Policy
OR-1.0
Acceptable Use Policy
OR-1.1
Access Control Policy
TS-1.7
Incident Response Policy
OR-4.0
Data Classification & Handling Policy
OR-1.4
Business Continuity & Disaster Recovery Policy
OR-1.2 / OR-1.3
AI / Machine Learning Use Policy
OR-5.0
Vulnerability & Patch Management Policy
TS-4.0
Access Control Policy
MPA TS-1.7
Studio - Access Control Policy Effective: 21 July 2026 1. Access is granted on a least-privilege, need-to-know, per-project basis. 2. Each user has a unique account; shared/default accounts are prohibited. 3. Roles and permissions are reviewed regularly and on any role change. 4. Access is revoked immediately on off-boarding or role change (see Off-boarding). 5. Privileged/admin access is restricted, logged and reviewed. 6. Authentication enforces strong passwords and step-up/MFA for sensitive actions.