EZBudget™
Security Awareness Training Policy
Ongoing security awareness for a sole-operator organization (no employees or contractors).
1. Policy Statement
Deseo Developers LLC is a sole-operator business with no employees or contractors. The sole operator maintains security awareness from the start of production system access and on a recurring basis thereafter through documented self-study, secure-coding review, and annual attestation.
2. Scope
- The sole operator / authorized representative of Deseo Developers LLC
- If employees or contractors are later engaged with system or data access, they will be brought under this policy before receiving access
3. Training Cadence
| Event | Requirement |
|---|---|
| Initial / onboarding equivalent | Complete security awareness and secure-coding review before or at the time production access is established |
| Recurring | Complete refresher review and self-attestation at least annually |
| After incidents | Targeted refresher following any security incident or near miss |
4. Training Content
Awareness and secure-development review covers, at minimum:
- Phishing and social engineering recognition
- Password / passkey hygiene and MFA use on all production consoles
- Safe handling of customer and financial data
- Incident recognition and response steps (EZB-IR-001)
- Workstation / endpoint hygiene (EZB-END-001)
- OWASP-aligned common web risks (injection, broken auth, XSS, insecure design, misconfiguration)
- Secrets management and avoiding credential commits
- Secure handling of Plaid, Stripe, and authentication integrations
- Repository security documentation (
SECURITY.mdand related guides)
5. Delivery and Attestation
- For the sole-operator model, training is delivered via documented reading of this policy packet and security docs, plus continuous application of secure development practices.
- Annual self-attestation is recorded (date, materials version) and retained for audit support.
- If headcount expands, formal onboarding modules and completion records will be required before production access is granted.
6. Current Operating Model
As a solopreneur organization, Deseo Developers LLC does not run a multi-employee LMS. Security awareness is continuous and owner-operated: the same individual who builds and deploys Finducation / EZBudget is responsible for staying current on threats, MFA, phishing, and secure coding.
7. Periodic Review
- This policy is reviewed at least annually.
- Materials are updated when major threats, platforms, or regulatory expectations change.
8. Related Documents
- Information Security and Governance Policy (EZB-ISG-001)
- Change Management and Secure SDLC Policy (EZB-CHG-001)
- Incident Response Policy (EZB-IR-001)
- Endpoint Security Policy (EZB-END-001)
9. Approval
Approved By: Deseo Developers LLC — Sole Operator / Authorized Representative
Date: July 22, 2026
Contact: contact@deseodevelopers.com