INFORMATION SECURITY POLICY
Senior Management at Six & Flow understands the information security needs and expectations of its interested parties both within the organisation and from external parties including, amongst others, clients, suppliers, regulatory and Governmental departments. The Company has recognised that the disciplines of confidentiality, integrity and availability of information in Information Security Management are integral parts of its management function and view these as their primary responsibility and fundamental to best business practice. To this end Six & Flow has produced this Information Security Policy aligned to the requirements of ISO/IEC 27001:2013 to ensure that the Company:
- Complies to all applicable laws and regulations and contractual obligations
- Implements Information Security Objectives that take into account information security requirements following the results of applicable risk assessments
- Communicates these Objectives and performance against them to all interested parties
- Adopts an Information Security Management System comprising a Security Manual and Procedures which provide direction and guidance on information security matters relating to employees, customers, suppliers and other interested parties who come into contact with its work
- Works closely with customers, business partners and suppliers in seeking to establish appropriate information security standards
- Adopts a forward-thinking approach on future business decisions, including the continual review of risk evaluation criteria, which may impact on information security
- Instructs all members of staff in the needs and responsibilities of Information Security Management
- Constantly strives to meet, and where possible exceed, its customer’s expectations
- Implements continual improvement initiatives, including risk assessment and risk treatment strategies, while making best use of its management resources to better meet information security requirements
Responsibility for upholding this policy is company-wide under the authority of the Managing Director (Richard Wood) who encourages the personal commitment of all staff to address information security as part of their skills.