vStream Digital Media

Information Security Policy

Last updated: 03/02/25

1. Definitions

Information Security: The protection of information and information systems from unauthorised access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.

Information Assets: Any data, information system, application, hardware, or digital resource owned or managed by vStream Digital Media, including ShineVR application data, source code, customer information, and business records.

ShineVR: vStream's immersive Cognitive Behavioural Therapy (CBT) platform for pain management, delivered as a virtual reality application to healthcare customers.

Personal Data: Any information relating to an identified or identifiable natural person, as defined by the General Data Protection Regulation (GDPR).

Security Incident: Any event that could compromise the confidentiality, integrity, or availability of information assets, including data breaches, system failures, unauthorised access attempts, and security policy violations.

Data Processor: An entity that processes personal data on behalf of a Data Controller. vStream acts as a Data Processor for customer trials, where the customer is the Data Controller.

2. Policy Statement

vStream Digital Media is committed to protecting the confidentiality, integrity, and availability of all information assets, including those related to our ShineVR product and services provided to healthcare customers. This policy establishes the framework for information security across all aspects of our business operations, development activities, and customer service delivery.

All employees, contractors, and third parties with access to vStream systems or information must comply with this policy and all referenced security policies. Non-compliance may result in disciplinary action, including termination of employment or contract, and may be reported to relevant authorities where legally required.

This policy applies to all information systems, applications, data, and infrastructure operated by vStream, including our Google Cloud Platform environment where ShineVR and associated services are hosted.

3. Purpose

The purpose of this policy is to:

4. Scope

This policy applies to all:

5. Information Security Framework

5.1 Infrastructure Security

vStream operates entirely on Google Cloud Platform with no on-premise data hosting. Our infrastructure security strategy relies on:

Related Policies: Cloud Security Policy, Network Security Policy, Physical Security Policy

5.2 Access Control

Access to vStream systems and ShineVR applications is controlled through:

Related Policies: Access Management Policy, Password Policy

5.3 Data Protection and Encryption

All vStream and ShineVR data is protected through:

Related Policies: Encryption Policy, Media Retention and Disposal Policy

5.4 Password Management

vStream enforces strong password requirements:

Related Policies: Password Policy

5.5 Backup and Recovery

Business continuity is ensured through:

Related Policies: Backup and Recovery Policy

5.6 Change Control and System Development

vStream follows a "release early, release often" development philosophy with robust security controls:

Related Policies: Change Control Policy, System Development Methodology

5.7 Incident Response

vStream maintains a comprehensive incident response framework:

Related Policies: Incident Response Plan

5.8 Logging and Monitoring

Comprehensive logging and monitoring provides visibility into security events:

Related Policies: Log Management Policy

5.9 Network Security

vStream's cloud-native architecture provides network security through:

Related Policies: Network Security Policy

5.10 Vendor Management

Third-party vendors are managed through:

Related Policies: Vendor Management Policy

5.11 Personnel Security

Employee and contractor security measures include:

Related Policies: Background Check Policy, BYOD Policy

6. Compliance and Regulatory Requirements

6.1 General Data Protection Regulation (GDPR)

vStream complies with GDPR requirements through:

6.2 Healthcare Regulations

For healthcare customers:

6.3 ISO 27001 Alignment

vStream security practices align with ISO 27001 information security management standards. Google Cloud Security Command Centre monitors compliance with ISO 27001 2022 controls.

Our policies and procedures address all ISO 27001 Annex A control domains including access control, cryptography, operations security, communications security, system development, supplier relationships, incident management, business continuity, and compliance.

7. Roles and Responsibilities

7.1 Chief Technology Officer (CTO) / Data Protection Officer

7.2 Product Manager

7.3 Backend Developers

7.4 All Employees

8. Policy Review and Maintenance

This Information Security Policy is reviewed annually by the CTO to ensure continued relevance and effectiveness. Reviews are also triggered by:

All policy updates require CTO approval and are communicated to all staff within 10 working days of approval.

9. Related Policies and Documents

This policy should be read in conjunction with the following vStream policies:

10. Contact Information

Data Protection Officer / Chief Technology Officer:

Andrés Pitt

Email: andres@vstream.ie

Phone: (086) 788 6570

Available 24/7 for P1 security incidents

Company Address:

vStream Digital Media

37 Leeson Close

Dublin 2, D02 H344

Ireland

Website: vstream.ie