Internal Policies
Anaza Advisory Inc. · We practice what we advise
As a privacy, security, and compliance advisory firm, we hold ourselves to the same standard of governance we build for our clients. Anaza Advisory maintains an internal policy framework aligned with recognized standards including ISO 27001, SOC 2, PIPEDA, PHIPA, GDPR, and HIPAA safeguard requirements. Policies are reviewed at least annually, approved by leadership, and reinforced through role based training.
Our Policy Framework
Information Security Policy
Defines our overall security objectives, governance structure, risk appetite, and the administrative, technical, and physical safeguards protecting our systems and client information.
Data Protection & Privacy Policy
Governs the collection, use, retention, and disposal of personal information in line with PIPEDA, PHIPA, GDPR, and applicable jurisdictional requirements, embedding privacy by design in how we work.
Access Control & Acceptable Use Policy
Enforces least privilege access, multi-factor authentication, and clear rules for acceptable use of systems, devices, and collaboration tools used in client engagements.
Client Confidentiality & Data Handling Policy
Establishes classification, encryption, secure transfer, and segregation requirements for client materials, including regulated data such as PHI and PII, throughout the engagement lifecycle.
Incident Response & Breach Notification Policy
Defines our structured process for detecting, containing, investigating, and reporting security incidents, including notification obligations to affected clients and regulators.
Vendor & Third Party Risk Management Policy
Requires due diligence, contractual safeguards, and periodic review of the tools and service providers in our own supply chain, including GRC platforms and cloud infrastructure.
Business Continuity & Resilience Policy
Ensures continuity of client service through backup, recovery, and contingency arrangements proportionate to the criticality of engagement commitments.
Records Retention & Disposal Policy
Sets defined retention periods for engagement records and mandates secure, verifiable disposal of information that no longer serves a business or legal purpose.
Code of Conduct, Ethics & Independence Policy
Commits our team to professional integrity, objectivity, conflict of interest disclosure, and independence in every advisory relationship.
Security Awareness & Training Policy
Requires ongoing, role based privacy and security training for all personnel, reflecting the same programs we design for clients.
Requesting Policy Information
Summaries of specific policies, or evidence of our internal practices relevant to a due diligence or vendor assessment process, are available to clients and prospective clients under NDA. Contact hasan@anazaadvisory.com to request documentation.