Legal
Terms, policies and information.
Policies
Information Security
Version 1.0 - 25/07/2024
Solarvista Software Ltd considers information security of the utmost importance, not only to protect our own information assets but also so that we remain a trusted partner to our clients and comply with the requirements of ISO 27001:2022.
The CEOs of Solarvista Software Ltd are committed to meeting all applicable requirements relating to information security and expect all persons working on behalf of the business to follow the information security controls set out in our Information Security Management System (ISMS), and thereby act within the spirit of this Information Security Policy. All persons working on behalf of Solarvista Software Ltd are held responsible for the information assets of the company and accountable for the information assets they are a named owner of. Ownership does not infer property rights.
The objective of Information Security is to ensure the business continuity of Solarvista Software Ltd and minimise the risk of commercial or reputational damage by preventing information security incidents and reducing their potential impact. Further objectives, pursuant of this overall one, are held elsewhere within the ISMS.
Solarvista Software Ltd’s Information Security Policy goal is to protect the organisation’s information assets, including client information we have been entrusted with, from all internal, external, deliberate or accidental threats.
The Information Security Policy requires that:
- Information will be appropriately and reasonably protected against unauthorised access;
- Confidentiality of proprietary, client and confidential information will be assured;
- Integrity of all business-critical information will be maintained;
- Availability of information for business processes and activity will be maintained;
- Legislative and regulatory requirements will be met;
- Appropriate controls will be defined in the ISMS including business continuity policies and procedures where appropriate;
- Information security training will be available for all persons working on behalf of Solarvista Software Ltd;
- Information security risks will be comprehensively reviewed on at least a bi-annual basis;
- All actual or suspected information security breaches will be reported to the responsible manager and will be thoroughly investigated;
- Business requirement for availability of information and systems will be met;
- The named individuals in the ISMS are responsible for maintaining the policy and providing support and advice during its implementation;
- Information asset owners (as defined in the asset and risk registers) are accountable for information security relating to those assets;
- All managers are responsible for implementing the policy and ensuring staff in their area comply with it;
- Compliance with the Information Security Policy is mandatory.
Through the application of this policy, Solarvista Software Ltd strives to achieve continual improvement of its information security management system, for the benefit of its clients, the organisation and other third parties affected by our activities.
Andrew Pyott - CEO
25th July 2024