Legal

Information Security Policy

Information Security Policy

Public principles for protecting information, systems and communications relevant to Azari Capital.

01

Risk-based security

Controls should reflect the sensitivity of information, the importance of the system and the consequences of compromise.

02

Access control

Access should be limited to authorised people and removed when it is no longer required.

03

Authentication

Strong authentication should be used for systems handling sensitive or privileged information where supported.

04

Data handling

Confidential or sensitive information should be stored, transmitted and disposed of using controls appropriate to its classification.

05

Third parties

Operating knowledge from elsewhere in the Azari group can sharpen diligence, but it does not replace independent underwriting. Any relationship with another Azari company is assessed on its own economics, risks, governance and conflicts.

06

Vulnerability management

Systems should be maintained, patched and reviewed for known weaknesses based on risk and operational context.

07

Incident response

Suspected security events should be reported, contained, investigated and documented promptly.

08

Business continuity

Important systems and records should have recovery arrangements proportionate to their role.

09

Human factors

Phishing, social engineering and accidental disclosure remain material risks. Security awareness should reflect real working practices.

10

Public reporting

Suspicious communications or website security concerns can be reported to hello@azaricapital.com without sending unnecessary sensitive data.

Continue

Go deeper into the investment framework.