1. Purpose

The principal aim of the system is to demonstrate that information security is maintained within the organisation, to ensure that risk management is applied continuously, to measure the performance of information security processes, and to govern relations with third parties on matters concerning information security.

2. Scope

Practices relating to information security concern all our business processes, our employees, our customers, our solution partners, our suppliers and all interested parties affected by the results of our work.

Information security practices are an indispensable dimension of every activity carried out.

3. Fundamental Principles

The continuity of the three fundamental elements of the information security management system is ensured in all activities conducted:

  • Confidentiality: preventing unauthorised access to information of significance
  • Integrity: demonstrating that the accuracy and integrity of information is maintained
  • Availability: demonstrating that those authorised can reach information when required

The relevant system standards concern the security not only of data held electronically, but of all data in written, printed, verbal and similar form. The standard is applicable to all organisations irrespective of company size, sector or differences in business processes.