1. Purpose, Scope and Intended Users
The purpose of this high–level Policy is to define the objectives, direction, principles and fundamental rules for information security management at «SYSTEM TECHNOLOGIES» JLLC.
This Policy applies to the entire Information Security Management System (hereinafter referred to as the “ISMS”), the boundaries of which are defined in the ISMS Scope.
The intended users of this document are all employees, contractors, job applicants and interns of «SYSTEM TECHNOLOGIES» JLLC, as well as relevant external interested parties.
2. Reference Documents
• ISO/IEC 27001, Clause 5.2;
• Information Security Management System Scope;
• Register of Legal, Regulatory, Contractual and Other Requirements;
• Information Security Risk Management Methodology;
• Statement of Applicability;
• Business Continuity Policy.
3. Key Information Security Terms
Information security means the preservation of the confidentiality, integrity and availability of information.
Confidentiality means the property whereby information is not made available or disclosed to unauthorized individuals, entities or processes.
Integrity means the property of safeguarding the accuracy and completeness of information assets.
Availability means the property of information assets being accessible and usable upon demand by an authorized entity.
Information Security Management System (ISMS) means that part of the Company’s overall management system, based on a business risk approach, which is intended to establish, implement, operate, monitor, review, maintain and improve information security.
4. Information Security Management
The core business of «SYSTEM TECHNOLOGIES» JLLC is the development, implementation and support of its proprietary IT solutions comprising methodology, software and related services.
In view of global and domestic economic trends, according to which information and information technologies are valuable and vital assets of modern business that determine its competitiveness, the Company pays particular attention to information security by implementing and continually improving its Information Security Management System.
4.1. Principles, Objectives and System of Measures
To achieve a high level of information security, «SYSTEM TECHNOLOGIES» JLLC follows the principles of ensuring the confidentiality, integrity, availability, authenticity and safekeeping of information. These principles are mandatory and apply to all business processes, all parties involved in the Company’s activities, and all Company information assets.
Based on these principles, the Company has established ISMS objectives aimed at protecting information assets, supporting business processes and ensuring the sustainable development of the Company.
The primary objectives of the ISMS are to:
• reduce information security risks;
• improve personnel competence in information security;
• enhance the Company’s reputation in the market and minimize damage resulting from potential incidents;
• ensure business continuity;
• comply with applicable legislation, standards and contractual obligations relating to information security;
• reduce the number of information security incidents.
The ISMS objectives shall be reviewed by the management of «SYSTEM TECHNOLOGIES» JLLC at least once a year during an ISMS management review meeting. New ISMS objectives may also be established upon the recommendation of the Information Security Manager.
The Information Security Manager is responsible for:
• establishing methods for measuring the achievement of objectives and their measurable annual target values in the “Plan and Report on the Results of Monitoring and Measurement of the Achievement of Information Security Management System Objectives”;
• performing such measurements at least once a year and analysing and evaluating the measurement results;
• presenting the measurement results at a dedicated meeting as input to the Management Review, as well as proposing measurable target values for approval for the upcoming reporting period.
4.2. Information Security Requirements
The Company declares that this Policy and the entire ISMS comply with applicable legal and regulatory requirements relating to information protection, including the protection of trade secrets and personal data, as well as with other applicable requirements and contractual obligations.
A detailed list of such requirements, as well as external and internal interested parties, is provided in the “Context of the Organization”.
The Company owns, including by virtue of intellectual property rights, all business information and computing resources acquired or otherwise obtained and put into operation for the purpose of conducting its activities in accordance with applicable law. Such ownership extends to voice and facsimile messages transmitted or received using Company equipment, licensed and internally developed software, the contents of email accounts, and all business–related paper and electronic documents of the Company’s organizational units and personnel.
4.3. Information Security Controls
• The process for selecting information security controls is defined in the “Information Security Risk Management Methodology”.
• The selected controls and their implementation status are described in the “Statement of Applicability”.
4.4. Business Continuity
Business continuity arrangements are established in the Business Continuity Policy.
4.5. Responsibilities
Responsibilities within the ISMS are allocated as follows:
• The Chief Executive Officer is responsible for ensuring that the ISMS is implemented and maintained in accordance with this Policy and that all necessary resources are made available. Based on recommendations from the Information Security Department and the Legal Department, the Chief Executive Officer also determines what information relating to information security is to be communicated to relevant internal and external interested parties, by whom, and within what time frame.
• The Company’s top management shall review the ISMS at least once a year or whenever a significant change occurs. The purpose of the management review is to determine the continuing suitability, adequacy and effectiveness of the ISMS.
• The Head of the Information Security Department monitors the implementation of measures approved by management and intended to ensure the required level of information security.
• The Information Security Manager is responsible for the operation of the ISMS, the coordination of ISMS activities and the preparation of process documentation.
• The Training Specialist within the Human Resources Department participates in the development and delivery of ISMS training and awareness programmes.
• Responsibility for protecting the confidentiality, integrity and availability of assets rests with the owners of those assets.
• Every Company employee shall report to the Information Security Department any information security incidents or deficiencies that they have caused or become aware of.
4.6. Communication of the Policy
The Human Resources Department shall ensure that all employees, contractors, interns and job applicants of «SYSTEM TECHNOLOGIES» JLLC are made aware of this Policy.
Representatives of relevant external interested parties shall be made aware of this Policy by the owners of the applicable agreements and through publication of the Policy on the Company’s official website.
4.7. Planning of Changes
Where the Company determines that changes to the ISMS are necessary, such changes shall be carried out in a planned manner. Upon completion of the planning stage, the changes shall be implemented with the aim of improving the effectiveness of ISMS processes.
All planned ISMS changes and improvements shall be documented either in a separate document or on a dedicated page within the Company’s wiki workspace.
5. ISMS Commitments
«SYSTEM TECHNOLOGIES» JLLC is committed to continually improving its Information Security Management System, providing sufficient resources to achieve the objectives established by this Policy, applying industry best practices, methodologies and information protection mechanisms, and complying with all applicable legal, regulatory, contractual and other requirements.
6. Validity and Document Control
The owner of this document is the Information Security Manager, who shall review and, where necessary, update the document at least once a year.
When assessing the adequacy and suitability of this document, the following criteria shall be considered:
• the number of employees and representatives of external parties involved in the ISMS who are insufficiently familiar with this document;
• non–compliance of the ISMS with legal, regulatory or contractual obligations, or with the Company’s internal documents;
• ineffective and/or insufficiently defined responsibilities for maintaining the ISMS.