Information Security Policy Statement
The organization recognizes that information security is the responsibility of each organization member. We are committed to creating an information security management system that protects our intellectual properties and assets, fulfills contractual security obligations, and establishes a robust risk assessment/treatment framework by implementing the ‘Information Security Management System’.
We will achieve this by ensuring:
- Information is maintained confidentially by being accessible only to authorized users through proper authentication and access control.
- Information integrity is maintained by safeguarding its accuracy and completeness and by protecting the processing methods from unauthorized modification.
- Availability of information to authorized users as and when needed, and as required by the business processes.
- All regulatory, Legislative, and other requirements regarding Intellectual property rights, data protection, and privacy of personal information are met.
- The confidentiality of corporate, client, and customer information will be assured.
- Business continuity plans for mission-critical activities will be produced, maintained, and tested.
- Information security awareness training will be made available to all staff.
- Information stored in the cloud computing environment is subject to access and management by the cloud service provider.
- Assets are maintained in the cloud computing environment, e.g., application programs; Processes can run on a multi-tenant, virtualized cloud service.
- The cloud service administrators of the customer with privileged access will follow all security guidelines.
- The geographical locations of the cloud service provider’s organization and the countries where the cloud service provider can store the cloud service customer data shall be shared in client contracts.
- Ensure compliance with applicable PII protection legislation and the contractual terms agreed between the public cloud PII processor and its clients.
The Policy will be communicated to all employees, stakeholders, and third parties and reviewed annually.
Employees will abide by the Security policy and will at all times act in a responsible, professional, and security-aware way. The Policy Statement is approved by the Chief Information Security Officer (CISO) and displayed strategically in the organization.