1. Purpose
The Employee Security Conduct Guidelines define the expected security behavior of employees, contractors, interns, temporary personnel, and other authorized personnel when using organizational information, systems, devices, applications, networks, cloud services, and physical facilities.
The objective is to establish clear and practical expectations for protecting:
- Organizational information
- Customer information
- Personal data
- Confidential information
- Credentials and authentication information
- Source code
- Cloud environments
- Business systems
- Devices and equipment
- Intellectual property
- Security infrastructure
Core Principle
Protect Information → Use Access Responsibly → Follow Security Requirements → Report Problems → Prevent Harm
These guidelines are intended to make secure behavior easy to understand and apply in day-to-day work.
2. Who Must Follow These Guidelines
These guidelines apply to:
☐ Employees
☐ Contractors
☐ Interns
☐ Temporary workers
☐ Consultants
☐ Remote workers
☐ Third-party personnel with organizational access
☐ Other authorized users
Requirements should be applied according to the person’s role, access level, information handled, and risk.
3. Employee Security Responsibilities
Every person with organizational access is responsible for:
- Protecting information entrusted to them.
- Using systems only for authorized purposes.
- Protecting their credentials.
- Following security policies and procedures.
- Using approved applications and services.
- Reporting suspected security problems promptly.
- Protecting customer and personal information.
- Keeping devices secure.
- Following information-classification requirements.
- Completing required security training.
- Cooperating with security investigations.
- Returning organizational assets when required.
- Reporting accidental disclosure or loss of information.
Remember
You are responsible for the security of the information and access entrusted to you.
4. Access and Authorization
Employees must use only the access assigned to them.
Employees Should
☐ Use their own accounts
☐ Use only authorized systems
☐ Access only information required for their role
☐ Follow least-privilege principles
☐ Request additional access through the approved process
☐ Report unnecessary or excessive access
☐ Protect privileged access carefully
☐ Use temporary access only for the approved purpose
Employees Must Not
☐ Use another person’s account
☐ Share accounts
☐ Bypass access controls
☐ Attempt unauthorized access
☐ Use another person’s privileges
☐ Access information merely because technically available
☐ Attempt to escalate privileges without authorization
5. Passwords and Authentication
Employees must protect authentication information.
Do
☐ Use strong, unique passwords
☐ Use the organization’s approved password manager where provided
☐ Use MFA where required
☐ Approve authentication requests only when personally initiated
☐ Report suspicious authentication activity
☐ Change credentials when compromise is suspected
Do Not
☐ Share passwords
☐ Write passwords where others can see them
☐ Reuse organizational passwords for unrelated services
☐ Store passwords in plain-text files
☐ Share MFA codes
☐ Approve unexpected MFA prompts
☐ Allow another person to use your authenticated session
Important
Security teams will never legitimately require you to disclose your password or MFA code.
6. Phishing and Social Engineering
Employees should treat unexpected communications carefully.
Be cautious of:
- Urgent requests
- Unexpected password-reset messages
- Requests for payment
- Requests for confidential information
- Unexpected attachments
- Suspicious links
- Fake login pages
- Executive impersonation
- Supplier impersonation
- MFA fatigue attacks
- QR-code phishing
- Phone-based social engineering
Before Acting
Stop → Check → Verify → Report
☐ Verify the sender
☐ Check the destination of links
☐ Confirm unusual requests through another trusted channel
☐ Avoid opening unexpected attachments
☐ Report suspected phishing
7. Email Security
Employees should:
☐ Verify recipients before sending sensitive information
☐ Check attachments before sending
☐ Use approved secure-transfer mechanisms
☐ Use BCC appropriately when necessary
☐ Report suspicious emails
☐ Avoid forwarding suspicious messages except through approved reporting mechanisms
Employees must not intentionally send confidential or restricted information to unauthorized recipients.
8. Information Classification
Employees must understand and follow organizational information-classification requirements.
Typical classifications may include:
☐ Public
☐ Internal
☐ Confidential
☐ Restricted
Employee Responsibilities
- Know the classification of information being handled.
- Use approved storage locations.
- Share information only with authorized recipients.
- Apply appropriate protection based on classification.
- Avoid unnecessary duplication.
- Secure information when working remotely.
Principle
The more sensitive the information, the greater the protection required.
9. Customer Information
Customer information must be handled only for legitimate business purposes.
Employees must:
☐ Access customer information only when required
☐ Follow customer-specific requirements
☐ Use approved systems
☐ Protect customer confidentiality
☐ Avoid unnecessary downloads
☐ Avoid storing customer information on personal devices
☐ Report accidental disclosure immediately
Employees must not:
☐ Browse customer records without a business need
☐ Copy customer information for personal use
☐ Share customer information through unauthorized applications
☐ Use customer information for unauthorized testing
10. Personal Data and Privacy
Employees must protect personal data handled by the organization.
Examples include:
- Names
- Contact information
- Identification information
- Employee records
- Customer information
- Financial information
- Account information
- Other information that can identify an individual
Employees should:
☐ Collect only required information
☐ Use personal data only for authorized purposes
☐ Share it only with authorized recipients
☐ Store it in approved systems
☐ Follow retention requirements
☐ Report accidental disclosure
☐ Follow applicable privacy requirements
11. Data Sharing
Before sharing sensitive information, verify:
Who is receiving it?
Why do they need it?
Are they authorized?
Is the transfer method approved?
Is the information appropriately protected?
Do Not
☐ Send confidential information to personal email
☐ Upload sensitive information to unauthorized websites
☐ Use unapproved file-sharing services
☐ Share information through personal messaging applications without authorization
☐ Transfer data to unauthorized countries/locations where restrictions apply
12. Use of Company Devices
Organizational devices must be protected.
Employees should:
☐ Lock screens when away
☐ Install approved security updates
☐ Use organizational security software
☐ Protect devices from theft
☐ Use approved storage
☐ Report lost or stolen devices immediately
☐ Avoid disabling security controls
Employees must not:
☐ Disable endpoint protection without authorization
☐ Install unauthorized security software
☐ Modify security configurations unnecessarily
☐ Allow unauthorized users to use company devices
13. Personal Devices
Where personal devices are permitted:
☐ Follow the organization’s BYOD requirements
☐ Use approved security controls
☐ Enable device locking
☐ Keep software updated
☐ Use MFA
☐ Protect organizational information
☐ Report loss or compromise
Organizational information should not be stored on personal devices unless explicitly authorized.
14. Remote Working
When working remotely:
☐ Use approved devices
☐ Use secure networks
☐ Use VPN or other approved secure access where required
☐ Protect screens from unauthorized viewing
☐ Avoid discussing confidential information in public areas
☐ Lock devices when unattended
☐ Use approved collaboration tools
☐ Report lost equipment immediately
Avoid using public computers for organizational work unless specifically authorized.
15. Public Wi-Fi
When using public networks:
☐ Use approved secure access mechanisms
☐ Avoid accessing sensitive information when adequate protection is unavailable
☐ Verify the network before connecting
☐ Use organizational VPN where required
☐ Keep device security controls enabled
Do not assume that a network named “Free Wi-Fi” is legitimate.
16. Cloud Services and SaaS
Employees must use only approved cloud services for organizational information.
Do
☐ Use approved SaaS applications
☐ Follow access-control requirements
☐ Enable MFA where available
☐ Share files only with authorized people
☐ Review sharing permissions
☐ Report accidental public exposure
Do Not
☐ Create unauthorized business accounts
☐ Upload restricted information to personal cloud storage
☐ Make sensitive files publicly accessible
☐ Share organizational credentials
☐ Use unapproved cloud services to bypass organizational controls
17. Shadow IT
Employees must not introduce technology into the organization without appropriate approval where the technology creates security, privacy, operational, or compliance risk.
Examples:
- Unapproved SaaS
- Personal cloud storage
- Unauthorized browser extensions
- Personal automation tools
- Unapproved AI services
- Unapproved file-sharing platforms
- Unapproved software
If a tool would make work significantly easier, request it through the appropriate process rather than bypassing security controls.
18. Generative AI and AI Tools
Employees must use AI tools responsibly.
Before entering organizational information into an AI service, verify that the service is approved for that type of information.
Do Not Enter Without Authorization
☐ Customer confidential information
☐ Personal data
☐ Passwords
☐ API keys
☐ Private keys
☐ Security credentials
☐ Source code
☐ Confidential contracts
☐ Restricted business information
☐ Security incident information
☐ Proprietary intellectual property
AI Usage Principles
Check → Classify → Authorize → Use → Review
AI-generated content should be reviewed before being used for business, security, legal, customer, or compliance decisions.
19. Source Code and Development Security
Developers and technical personnel must:
☐ Use approved repositories
☐ Protect source code
☐ Use individual accounts
☐ Protect secrets
☐ Follow secure-development practices
☐ Review code appropriately
☐ Use approved dependencies
☐ Report vulnerabilities
☐ Follow production-access requirements
Never commit:
- Passwords
- API keys
- Tokens
- Private keys
- Cloud credentials
- Database credentials
into source-code repositories.
20. Production Systems
Production systems require heightened care.
Employees must:
☐ Use approved access
☐ Follow change-management procedures
☐ Use individual accounts
☐ Use MFA where required
☐ Limit access to necessary activities
☐ Record significant changes
☐ Avoid unnecessary production-data access
☐ Report unexpected production behavior
Do not use production systems for experimentation unless specifically authorized.
21. Privileged Access
Privileged users have additional responsibilities.
They must:
☐ Use privileged access only when required
☐ Use approved privileged accounts
☐ Protect administrator credentials
☐ Use MFA
☐ Follow change procedures
☐ Avoid unnecessary privilege
☐ Maintain accountability
☐ Report suspected compromise
Privileged access should never be treated as unrestricted permission to browse organizational information.
22. Information Security Incidents
Employees must report suspected security incidents promptly.
Examples:
- Lost device
- Stolen device
- Phishing
- Malware
- Ransomware
- Unauthorized access
- Accidental data disclosure
- Wrong recipient
- Suspicious login
- Credential compromise
- Unexpected MFA prompt
- Data leakage
- Cloud misconfiguration
- Security weakness
Do Not
☐ Hide an incident
☐ Delete evidence
☐ Attempt unauthorized investigation
☐ Delay reporting because the issue seems small
Principle
Report early. The security team can determine the severity.
23. Security Weakness Reporting
Employees should report security weaknesses even when they have not caused an incident.
Examples:
- Open cloud storage
- Unlocked server room
- Shared account
- Excessive permissions
- Missing MFA
- Exposed password
- Outdated software
- Suspicious application
- Unprotected sensitive document
Early reporting can prevent an incident.
24. Physical Security
Employees must protect physical areas and equipment.
☐ Wear/access identification where required
☐ Do not allow unauthorized people to follow you through secure doors
☐ Challenge or report suspicious access appropriately
☐ Protect laptops and devices
☐ Secure documents
☐ Follow visitor procedures
☐ Report lost access cards
Do not prop open security-controlled doors.
25. Clean Desk and Clear Screen
Employees should:
☐ Lock screens when away
☐ Secure sensitive documents
☐ Avoid leaving confidential information unattended
☐ Dispose of sensitive documents through approved methods
☐ Remove sensitive information from meeting rooms and whiteboards when no longer required
26. Printing and Physical Documents
When printing sensitive information:
☐ Use secure printers where available
☐ Collect documents promptly
☐ Avoid unnecessary printing
☐ Store documents securely
☐ Dispose of documents securely
Do not leave confidential documents unattended in shared areas.
27. Removable Media
Use removable media only when authorized.
Before using removable media:
☐ Confirm business need
☐ Use approved media
☐ Apply encryption where required
☐ Scan for malware where required
☐ Protect the media
☐ Securely dispose of it when no longer required
Do not copy restricted information to personal USB devices.
28. Software Installation
Employees must install only approved software.
Before installing software:
☐ Confirm business need
☐ Use approved sources
☐ Obtain required approval
☐ Check licensing requirements
☐ Consider security implications
Do not install pirated or unauthorized software.
29. Browser Extensions and Online Tools
Browser extensions and online services can access organizational information.
Employees should:
☐ Use approved extensions
☐ Review requested permissions
☐ Avoid extensions from unknown sources
☐ Avoid uploading confidential information to online tools
☐ Report suspicious extensions
30. Security Monitoring
Employees should understand that organizational systems may generate security logs for legitimate purposes such as:
- Security monitoring
- Incident investigation
- Troubleshooting
- Compliance
- Access review
- Fraud/security detection
Monitoring should be performed according to applicable organizational, legal, privacy, and employment requirements.
Employees must not attempt to disable or bypass authorized security monitoring.
31. Security Testing
Employees must not perform unauthorized security testing.
Do not:
☐ Scan systems without authorization
☐ Attempt password attacks
☐ Test production systems without approval
☐ Exploit vulnerabilities without authorization
☐ Conduct social-engineering tests independently
☐ Attempt to bypass security controls
Security testing must follow the organization’s approved authorization and testing process.
32. Information Disposal
When information is no longer required:
☐ Follow retention requirements
☐ Delete information through approved methods
☐ Securely dispose of physical records
☐ Follow media-destruction requirements
☐ Do not retain unnecessary copies
Deletion should not be used to hide security incidents or destroy required evidence.
33. Intellectual Property
Employees must protect organizational intellectual property, including:
- Source code
- Designs
- Product information
- Business plans
- Customer information
- Security documentation
- Research
- Proprietary processes
- Internal documentation
Do not copy organizational intellectual property to personal accounts or devices without authorization.
34. Confidentiality
Employees must maintain confidentiality during and after their employment or engagement, subject to applicable agreements and legal requirements.
Employees must:
☐ Access information only for authorized purposes
☐ Share information only with authorized recipients
☐ Protect confidential discussions
☐ Protect documents
☐ Follow confidentiality agreements
☐ Return or delete information when required
35. Conflicts of Interest
Employees should report situations where personal interests could affect security decisions.
Examples:
- Selecting a supplier with a personal relationship
- Using organizational resources for personal business
- Accepting inappropriate benefits from suppliers
- Sharing confidential information for personal advantage
Follow the organization’s applicable conflict-of-interest requirements.
36. Third-Party and Supplier Information
When working with suppliers or customers:
☐ Share only required information
☐ Use approved communication channels
☐ Verify recipients
☐ Follow contractual restrictions
☐ Follow supplier/customer security requirements
☐ Report accidental disclosures
Do not provide third parties with broader access simply because it is technically convenient.
37. Security Training
Employees must complete required security training.
Training may include:
- Information-security awareness
- Phishing
- Passwords and MFA
- Information classification
- Privacy
- Incident reporting
- Remote working
- AI security
- Cloud security
- Role-specific security
- Secure development
Employees are expected to apply training in their daily work.
38. Policy Acknowledgement
Employees may be required to acknowledge applicable security policies.
Acknowledgement means that the employee:
☐ Has received the policy
☐ Has had reasonable opportunity to review it
☐ Understands their responsibilities
☐ Knows where to obtain assistance
☐ Understands reporting requirements
Acknowledgement does not replace training or practical implementation.
39. Security Exceptions
Employees must not create informal security exceptions.
If a business requirement cannot be achieved using the normal process:
Identify → Justify → Assess Risk → Request Exception → Approve → Apply Controls → Review
Employees should seek an approved exception rather than bypassing security requirements.
40. Good-Faith Reporting
Employees should be encouraged to report:
- Mistakes
- Security weaknesses
- Suspicious activity
- Accidental disclosures
- Policy concerns
- Potential violations
Good-faith reporting should not be discouraged by fear of retaliation.
However, deliberate misuse, malicious activity, concealment, or repeated violations may be addressed through the organization’s approved disciplinary process.
41. Prohibited Conduct
Unless explicitly authorized, employees must not:
☐ Access systems without authorization
☐ Share credentials
☐ Circumvent security controls
☐ Disable security software
☐ Introduce malware
☐ Steal or misuse information
☐ Copy confidential information for personal use
☐ Intentionally disclose restricted information
☐ Conduct unauthorized security testing
☐ Install unauthorized software where prohibited
☐ Use organizational systems for unlawful activity
☐ Destroy security evidence
☐ Conceal security incidents
☐ Falsify security records
42. If You Make a Mistake
Security mistakes can happen.
If you accidentally:
- Send information to the wrong person
- Click a suspicious link
- Upload information to an incorrect location
- Lose a device
- Share information incorrectly
- Approve an unexpected MFA request
- Expose a file
- Commit a secret to a repository
Report it immediately.
Do not wait until you know whether it is a serious incident.
Principle
Fast reporting is more important than hiding a mistake.
43. If You Are Unsure
When uncertain:
Stop
Do not proceed with a potentially risky action.
Check
Review the applicable policy or procedure.
Ask
Contact your manager, IT, Information Security, Privacy, or another designated support function.
Report
If something may already have gone wrong, report it promptly.
When in doubt, ask before acting.
44. Security Decision Guide
Before performing a potentially sensitive action, ask:
- Am I authorized to do this?
- Do I actually need this information or access?
- Is the information appropriately classified?
- Am I using an approved system or tool?
- Could this expose information or create security risk?
- Do I need approval?
- Should I report or document this activity?
If the answer is unclear, stop and seek guidance.
45. Employee Security Quick Reference
| Situation | Expected Action |
|---|---|
| Suspicious email | Report it |
| Lost laptop | Report immediately |
| Unexpected MFA prompt | Deny/report |
| Password compromised | Reset/report |
| Wrong recipient | Report immediately |
| Sensitive data request | Verify authorization |
| New SaaS tool | Check approval |
| AI tool request | Check data restrictions |
| Security weakness | Report it |
| Excessive access | Report/request correction |
| Unusual system behavior | Report it |
| Unauthorized software | Stop/use approved process |
| Production change | Follow change process |
| Unsure about security | Ask before acting |
46. Manager Responsibilities
Managers should:
☐ Ensure employees understand their security responsibilities
☐ Ensure access matches job requirements
☐ Approve access appropriately
☐ Support security training
☐ Encourage reporting
☐ Escalate security concerns
☐ Support investigations
☐ Review role changes promptly
☐ Ensure departing personnel are reported to the appropriate teams
☐ Avoid pressuring employees to bypass security controls
Managers should not instruct employees to bypass security requirements simply to meet business deadlines.
47. Information Security Responsibilities
Information Security should:
- Define security requirements.
- Provide guidance.
- Monitor relevant security risks.
- Investigate reported security matters.
- Support incident response.
- Provide security awareness.
- Maintain security procedures.
- Track significant violations.
- Recommend corrective actions.
- Escalate significant risks.
Information Security should work with HR, Legal, Privacy, IT, Engineering, and management as appropriate.
48. Reporting Channels
Employees should know where to report security concerns.
Security Contact: __________________________
Email: ____________________________________
Incident Reporting Tool: ____________________
Emergency Contact: ________________________
Manager: __________________________________
Privacy Contact: ___________________________
Employees should use the fastest approved channel appropriate to the severity of the issue.
49. Employee Security Conduct Checklist
Every employee should be able to confirm:
☐ I protect my credentials.
☐ I use MFA where required.
☐ I do not share accounts or passwords.
☐ I access only information required for my work.
☐ I protect customer and personal information.
☐ I use approved applications and cloud services.
☐ I follow information-classification requirements.
☐ I protect company devices.
☐ I follow secure remote-working practices.
☐ I use AI tools responsibly.
☐ I do not upload confidential information to unauthorized services.
☐ I follow production and privileged-access requirements.
☐ I report phishing and suspicious activity.
☐ I report security mistakes quickly.
☐ I do not disable security controls.
☐ I follow security testing requirements.
☐ I complete required security training.
☐ I cooperate with legitimate security investigations.
☐ I ask for help when unsure.
☐ I understand that security is part of my job responsibility.
50. AWS SaaS Startup Example
Scenario
A developer working on an AWS SaaS platform receives a request to urgently troubleshoot a customer issue.
The developer considers:
- Downloading production customer data
- Using a personal laptop
- Uploading the data to an AI service
- Sharing AWS credentials with another developer
Correct Conduct
The developer should:
- Verify the business requirement.
- Use approved company equipment.
- Access production only through authorized accounts.
- Use the minimum required data.
- Prefer masked/test data where possible.
- Use an approved troubleshooting environment.
- Check whether the AI service is approved.
- Never share AWS credentials.
- Follow the production-access and change-management process.
- Report any accidental disclosure immediately.
Security Principle
Business urgency does not automatically authorize bypassing security controls.
51. Startup-Friendly Security Culture
For a startup, security conduct should be practical rather than bureaucratic.
The organization should encourage employees to:
- Ask questions.
- Report mistakes quickly.
- Use approved tools.
- Protect customer information.
- Avoid unnecessary access.
- Follow simple security rules consistently.
- Suggest better security controls.
- Treat security as part of normal engineering and business operations.
Startup Principle
Make the secure way the easy way.
52. Common Mistakes
Avoid:
- Assuming employees know security requirements without training.
- Giving broad access because it is convenient.
- Allowing account sharing.
- Treating security as only the IT team’s responsibility.
- Discouraging employees from reporting mistakes.
- Allowing unapproved SaaS or AI tools.
- Ignoring excessive privileges.
- Allowing production data to be copied unnecessarily.
- Assuming remote work is automatically secure.
- Ignoring security responsibilities during role changes.
- Failing to revoke access during offboarding.
- Treating security violations only as disciplinary matters instead of identifying root causes.
53. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Defines overall security expectations |
| Acceptable Use Policy | Defines acceptable use of systems and resources |
| Security Awareness Policy | Defines awareness requirements |
| Security Awareness Training Procedure | Defines training process |
| Employee Security Responsibilities | Defines individual responsibilities |
| Access Management Procedure | Controls user access |
| Joiner-Mover-Leaver Procedure | Manages access during personnel changes |
| Incident Response Procedure | Handles security incidents |
| Security Policy Violation Register | Tracks policy violations |
| Security Violation Investigation Procedure | Investigates suspected violations |
| Disciplinary Policy | Defines disciplinary principles |
| Confidentiality Agreement | Supports confidentiality obligations |
| Remote Working Policy | Defines secure remote work |
| AI Security Policy | Defines responsible AI use |
| Asset Management Procedure | Controls organizational assets |
| Corrective Action Tracker | Tracks remediation |
| Security Awareness Training Register | Records security training |
| Personnel Security Procedure | Supports personnel-security lifecycle |
54. ISO 27001 Connection
Employee security conduct supports the organization’s broader information-security management system by translating policies and security requirements into practical day-to-day behavior.
The exact format of these guidelines is not a universally prescribed ISO/IEC 27001 document. The organization should determine appropriate employee responsibilities, awareness, training, access, confidentiality, acceptable-use, incident-reporting, and other personnel-security requirements based on its ISMS scope, risks, applicable controls, legal/regulatory requirements, contractual commitments, and business needs.
The guidelines can support areas including:
- Information-security responsibilities
- Security awareness
- Access control
- Authentication
- Information protection
- Incident reporting
- Personnel security
- Remote working
- Cloud security
- Secure development
- Privacy
- Supplier interactions
- Continual improvement
55. Employee Acknowledgement
I confirm that I have received and reviewed the Employee Security Conduct Guidelines.
I understand that I am responsible for:
- Protecting organizational information.
- Using systems and access appropriately.
- Following applicable security requirements.
- Protecting credentials.
- Reporting suspected security incidents and weaknesses.
- Completing required security training.
- Cooperating with authorized security investigations.
Employee Name: ___________________________
Employee ID: ______________________________
Role: _____________________________________
Department: _______________________________
Signature/Confirmation: ____________________
Date: _____________________________________
56. Final Audit Checklist
☐ Guidelines approved
☐ Applicable personnel identified
☐ Security responsibilities defined
☐ Access responsibilities defined
☐ Password/MFA requirements communicated
☐ Phishing guidance provided
☐ Information classification addressed
☐ Customer data addressed
☐ Privacy requirements addressed
☐ Device security addressed
☐ Remote-working security addressed
☐ Cloud/SaaS usage addressed
☐ AI usage addressed
☐ Production access addressed
☐ Privileged access addressed
☐ Incident reporting addressed
☐ Security weakness reporting addressed
☐ Physical security addressed
☐ Software installation addressed
☐ Security testing restrictions addressed
☐ Confidentiality addressed
☐ Training requirements addressed
☐ Exception process addressed
☐ Reporting contacts defined
☐ Employee acknowledgement recorded
☐ Periodic review defined
57. Final Audit Trail
The organization should be able to demonstrate:
What security behavior is expected?
Who must follow it?
How were employees informed?
What training was provided?
How are responsibilities communicated?
How are violations reported?
How are security mistakes handled?
How are serious violations investigated?
How are corrective actions tracked?
How are recurring weaknesses identified?
How is employee security behavior improved over time?
Final Principle
Security conduct is not simply a list of rules. It is the practical behavior expected from every person who handles organizational information or uses organizational systems. The objective is to make secure behavior clear, practical, repeatable, and part of everyday business operations.
