
ISMS Policy
The information security policy governing IT Security C&T's own Information Security Management System, aligned to ISO/IEC 27001.
Scope
- This policy applies to all information created or received in IT Security C&T.
- It forms the basis of the IT Security C&T Information Security Management System (ISMS) and the related policies and procedures beneath it.
Purpose
This policy defines the information security requirements, based on best practice and the relevant standards, for managing information security incidents and threats within IT Security C&T. The goal is to reduce risk and protect the organization from internal and external threats, with a focus on the core security objectives: confidentiality, integrity, and availability of information.
It also exists to ensure compliance with ISO/IEC 27001 and to establish a security environment that supports the organization's operations, mission, and strategic objectives.
Policy Statement
All IT Security C&T information assets, people, intellectual property, computer systems, data, and equipment are to be adequately protected from all threats, whether internal or external, deliberate or accidental, on a cost-effective basis.
- IT Security C&T protects information assets from unauthorized access.
- IT Security C&T commits to comply with regulatory and legislative requirements.
- IT Security C&T commits to maintain a high level of competence for its staff.
- Information security risks are managed under the IT Security C&T Risk Management Methodology.
- IT Security C&T commits to continually improve its ISMS and its information security.
- Access to information assets is controlled and restricted on need-to-know and least-privilege principles.
- Information security posture is improved continually by measuring ISMS performance and acting on what the measurements show.
- Security incidents and suspected vulnerabilities are treated and resolved according to their nature.
Responsibilities
- All managers are directly responsible for implementing the ISMS Policy and for monitoring their staff's adherence to it.
- Compliance with this policy, and with all supporting policies, standards, and procedures, is mandatory for all staff and third parties.
- Violation of this policy, or of any other information security policy, standard, or procedure, results in corrective action by management. Disciplinary action is consistent with the severity of the violation, as determined by investigation and as deemed appropriate by management.
Questions
Direct questions about this policy to Info@itsecurityct.com.