ISM statement (ISO27001)

Information security management statement.

This policy statement outlines my endorsement and intent for Information Security Management (ISM) within Deeson Group Ltd.

Its purpose is to communicate our ISM expectations to all those delivering services upon our behalf or working on our premises.

Some aspects of our operations, including handling client source code and having privileged access to systems, present clear information security requirements, however it is expected that we treat all our client and internal hard copy and electronic information in a secure manner, throughout all our processes.

Our overall ISM objective is to protect the organisation from incidents that might have an adverse effect on the people we work with, our business operations and our professional standing. Information Security issues can include Confidentiality (people obtaining or disclosing information inappropriately), Integrity (information being altered or erroneously validated, whether deliberate or accidental) and Availability (information not being assessable when it is required).

Many types of incident can pose a threat to our effective use of information. This includes performance, consistency, reliability, accuracy and timeliness. More detailed ISM objectives and monitoring will be defined separately to this policy, either within a stand-alone document or within management review.

Our information security management system is based upon the requirements of the international standard BS ISO/IEC 27001:2013 and using this framework, we will assess and manage ISM risk. We shall also understand and comply with any applicable ISM or related legal/regulatory requirements.

This statement has been prepared to demonstrate my commitment to continual improvement within our Information Security Management. This message shall be communicated and understood throughout Deeson and I expect that all persons performing work on our behalf share my commitment to these values.

This policy statement is made available to the public in this handbook, and is subject to annual review to ensure its continued suitability.

Sarah Harris

Managing Director

Last updated