Information Security Policy
The objective of information security is to ensure business continuity by preventing loss of information. Information takes many forms and includes data stored on computers, transmitted across networks, printed out or written on paper, sent by fax, stored on tapes and diskettes, or spoken in conversations or over the telephone. The protection of information from unauthorised disclosure or intelligible interruption is imperative, as is safeguarding the accuracy and completeness of information by protecting against unauthorised access.
The purpose of the policy is to protect the Company’s information assets from all threats, whether internal or external, deliberate or accidental, and to ensure that information and vital services are available to users when they need them. It is the policy of the Company to use all reasonably practicable measures to ensure that:
We have systems in place to follow the three fundamental principles of information security – confidentiality, integrity and availability. We ensure that information and information systems are protected from unauthorised use, access, modification and removal, whether this is held on our computer systems and server, or in confidential locked file cabinets in our Head Office. This includes but is not limited to:
This statement should be read in conjunction with QS 15 Internet Security Procedure and all managers are directly responsible for implementing the policy within their business areas, and for adherence by their staff. It is the responsibility of each employee to do everything reasonable within their power to ensure that this policy is carried into effect. Controls are already in place which include the requirements of legislation such as the Companies Act, Data Protection Act and General Data Protection Regulations (GDPR).
Information Security Training:
Breaches of Internet Security:
Any breach of information security, actual or suspected, should be reported to, and investigated by, the Head of Digital & Technology, who will report to the appropriate Senior Leadership personnel.
The CEO shall review this policy annually or following significant changes.
Brusk Korkmaz
CEO
Hercules Site Services