Our company is committed to safeguarding the information and data entrusted to us by our clients, partners, and employees. This policy outlines our approach to information security and data protection, ensuring that sensitive information is protected from unauthorized access, disclosure, alteration, and destruction.
This policy applies to all employees, contractors, and third-party partners who have access to the company's information systems and data. It encompasses all forms of data, including digital, physical, and verbal information, across all departments and functions.
All data handled by the company is classified into the following categories:
All security incidents, including data breaches, must be reported immediately to the IT department. Affected systems will be isolated, and an investigation will be conducted to determine the cause and impact. Appropriate measures will be taken to mitigate the damage and prevent future occurrences.
All employees are required to participate in regular training sessions on information security and data protection. This training will cover the importance of data protection, the company's security policies, and best practices for safeguarding information.
Regular audits will be conducted to ensure compliance with this policy. Non-compliance with the policy may result in disciplinary action, up to and including termination of employment.
This policy will be reviewed annually or as required due to changes in legislation, technology, or business practices. Any updates or modifications will be communicated to all employees and relevant parties.
This Information Security & Data Protection Policy is a living document and is subject to change as the company evolves and as new threats and technologies emerge.