← TPN pack
Download .txt
Security Policy Templates
Ready-to-adopt written policies for MPA / TPN readiness, pre-filled with your studio
name. The MPA Best Practices expect these in writing. Review, edit to your studio, and adopt - then
they cover the policy controls in your assessment.
Information Security Management Policy
OR-1.0
Acceptable Use Policy
OR-1.1
Access Control Policy
TS-1.7
Incident Response Policy
OR-4.0
Data Classification & Handling Policy
OR-1.4
Business Continuity & Disaster Recovery Policy
OR-1.2 / OR-1.3
AI / Machine Learning Use Policy
OR-5.0
Vulnerability & Patch Management Policy
TS-4.0
Data Classification & Handling Policy
MPA OR-1.4
Studio - Data Classification & Handling Policy Effective: 21 July 2026 1. Classes: Client Content (highest), Confidential (HR/finance), Internal, Public. 2. Client Content: encrypted in transit, watermarked, access-logged, delivered via approved secure channels only; never on personal devices/storage. 3. Confidential: access restricted to authorised roles; sensitive identifiers (PAN/Aadhaar/bank) encrypted at rest. 4. Retention: content is retained only as long as the project requires, then securely destroyed per client agreement. 5. All handling follows the Acceptable Use and Access Control policies.