Skip to content

Latest commit

 

History

History
executable file
·
115 lines (90 loc) · 5.22 KB

README.md

File metadata and controls

executable file
·
115 lines (90 loc) · 5.22 KB

Infinity Works - Information Security Management System

Overview

OK, now before you panic about the sheer volume of reading that lays ahead of you we do actually want you to take this a little seriously. As Ron would say "it's kind of a big deal!"

So grab a cuppa, sit comfortably and start reading.

Why are we implementing ISO27001?

For one it'll make sure we don't get into any unnecessary trouble and perhaps do something accidental that might implicate a person, our company or a client.

Also, by having these policies we will demonstrate to our clients that we take security seriously and won't let ourselves or them down. Plus, it will unlock more doors to more clients in the future who count on this level of security from us.

So once you've read and understood these policies we'd really like you to accept them which you can do by clicking on the link at the very bottom of this page

Sound good? OK let's get started!!

Information Security Management System

This contains all of the policies which make up the Information Management System.

  • It defines the scope of our company's approach to ISMS
  • It defines how the scope is applied
  • It provides suitable reason for permissible exclusion from this scope
  • It contains or makes reference to documented procedures
  • It ensures a cycle of feedback exists to allow improvements


A summarised Security Policy document is available here

Schedule

  • Bi-Annual reviews - end of every Apr & Oct
  • Risk Assessment reviews 1mth prior to bi-annual review - end of Mar & Sept

The Process

  • The ISMS Committee are responsible for maintaining and updating the policies.
  • This committee meets at least quarterly and reviews all policies annually.
  • The ISMS Committee requires one Director and two Principal Consultants to be actively engaged to approve any matters affecting Security policies and personnel

The ISMS Committee

Group Members:

  • Directors - Paul Henshaw, Matt Gaffney, Dan Rathbone, Tom Walton
  • ISMS Manager (acting) - Steve Anderson
  • Legal Counsel - Clare Mackintosh
  • Board Members (nominated):
    • Leeds - Steve Anderson, Neil Dunlop, Natalie Lovett, Pete Cotton
    • Manchester - David Postle & Adrian Hesketh
    • London - Neil Jennings, Richard Allen, Lara Longhurst
    • Edinburgh - Ed Marshall

Contact Email: [email protected]

Information Security Roles and Responsibilities view here

Raising Incidents

In the event of an incident please:

Raising Policy Issues

Feel free to raise issues for the ISMS Committee to discuss via (in order of preference):

A-Z Policies

Acceptance Form

(Please register the completion your Induction or Annual ISO27001 Policy Review by clicking an applicable link below)




Back to the top