1. Purpose
This policy establishes Hozit Domain Hosting (Pty) Ltd’s general approach to protecting information, infrastructure, applications, services and customer environments.
Security controls are applied according to service scope, identified risk, technical feasibility and contractual requirements.
2. Scope
This policy applies to Hozit personnel, contractors, systems, networks, devices and services used to provide or support customer services.
3. Security governance
Security responsibilities are assigned according to role and operational function.
- Security risks should be identified and assessed.
- Controls should be proportionate to identified risks.
- Security responsibilities should be communicated.
- Material incidents should be escalated appropriately.
- Policies and controls should be reviewed periodically.
4. Access control
- Access should be granted according to legitimate business need.
- Administrative access should be restricted to authorised personnel.
- Shared administrative credentials should be avoided where reasonably possible.
- Passwords should be strong, confidential and unique.
- Multi-factor authentication should be used where supported and appropriate.
- Access should be removed or amended when roles change or access is no longer required.
5. Infrastructure security
Relevant infrastructure safeguards may include:
- network firewalls and access restrictions;
- secure service configuration;
- segmentation or isolation where appropriate;
- malware protection;
- software updates and security patches;
- encrypted transmission protocols;
- logging and monitoring; and
- controlled remote administration.
6. Vulnerability management
Hozit aims to identify and address relevant vulnerabilities according to risk, severity, exploitability, service impact and available remediation.
Customers and security researchers may report suspected vulnerabilities under the Responsible Disclosure Policy .
7. Change management
Material production changes should be planned, authorised, documented and tested to a level appropriate to the change.
Emergency changes may be performed where necessary to protect security, stability or service availability.
8. Logging and monitoring
Hozit may collect and review operational and security logs for:
- service monitoring;
- fault diagnosis;
- security-event investigation;
- fraud and abuse prevention;
- capacity management; and
- legal and contractual compliance.
9. Backup and recovery
Backup controls depend on the purchased service. Where backup services are included, Hozit may apply scheduled backups, retention controls and restoration procedures.
Customers remain responsible for understanding the backup scope of their service and maintaining independent backups of critical information where appropriate.
10. Third-party suppliers
Hozit may use data centres, cloud platforms, software vendors, connectivity providers, registrars and other suppliers.
Supplier selection and management should consider service suitability, security, privacy, availability and contractual requirements.
11. Security incident response
Security incidents may be managed through the following stages:
- identification and initial assessment;
- classification and escalation;
- containment;
- investigation and evidence preservation;
- eradication or corrective action;
- service recovery;
- notification where required; and
- post-incident review.
12. Personal information
Personal information involved in security monitoring or incident response will be handled according to applicable privacy requirements and the Hozit Privacy Policy.
13. Business continuity
Hozit seeks to maintain continuity and recovery procedures appropriate to its services, infrastructure and operational risks.
Recovery commitments are governed by the relevant quotation, service agreement and Service Level Agreement .
14. Customer responsibilities
Customers are responsible for:
- protecting account credentials;
- using strong passwords;
- managing authorised users;
- keeping customer-managed software updated;
- maintaining secure local devices and networks;
- reporting suspected compromise promptly;
- maintaining suitable independent backups; and
- complying with the Acceptable Use Policy .
15. Policy review
This policy may be reviewed and updated as risks, services, technologies and legal requirements change.
16. Security contact
Security-related concerns may be submitted to security@hozit.co.za .