Information security is a critically important issue for any organization, and especially for companies like Italsicurezza S.r.l., which not only manages vital business information but also frequently comes into contact with its customers’ information and data.
Technological progress and the rapid digital transformations of recent years have impacted the company’s risk landscape, which has had to deal with a significant increase in cyber risks aimed at compromising the company’s information assets.
For this reason, Management has deemed it appropriate to define a policy for managing information to be shared with all internal staff as well as with external parties who, interacting with Italsicurezza S.r.l., may come into possession of it.
The purpose of this policy is to define:

In order to protect Italsicurezza S.r.l.’s information assets, as well as its customers’ information managed throughout the lifecycle of the products and services provided, from all threats—internal or external, intentional or accidental. Management is committed to consistently ensuring information security by implementing a set of processes, procedures, and organizational structures.
The policy applies to the design, marketing, installation, maintenance, and support of intrusion detection systems, video surveillance systems, access management systems, fire detection systems, and fire prevention devices, as well as to the design, marketing, installation, maintenance, and support of security and safety systems.
Aware that its design, installation, and maintenance activities for external parties may involve entrusting critical data and information, Italsicurezza S.r.l. operates in accordance with internationally recognized security standards.

Su tale linea Italsicurezza S.r.l. ha deciso di porre in essere un Sistema di Gestione per la Sicurezza delle Informazioni (SGSI) conforme ai requisiti della norma internazionale ISO/IEC 27001. Il Sistema di Gestione per la Sicurezza delle Informazioni (SGSI) si basa fondamentalmente su tre obiettivi chiave:

Italsicurezza S.r.l., with reference to the services provided and included in its certification scope, identifies the R.I.D. triad as follows:

The Management has established the following objectives for Information Security:

For each of these objectives, specific annual targets are set to support and confirm continuous improvement. To achieve the aforementioned objectives, Italsicurezza S.r.l. has defined the following principles:

In order to ensure compliance with the principles listed above and the achievement of the objectives, the following general guidelines for managing information security risks have been defined:

Italsicurezza S.r.l. has defined, approved, published, and communicated its information security policies to company personnel and other interested parties; these policies are available to interested parties.
Furthermore, Italsicurezza S.r.l. periodically monitors the ISMS and prepares specific documentation highlighting performance and compliance with standards, legislation, regulations, and contractual and operational provisions.
This policy is subject to periodic review and/or in the event of significant changes regarding information security, in order to ensure its suitability, adequacy and efficiency.

Italsicurezza S.r.l.
The Management

POL02 – Information Security Policy

Rev.2 12/02/2024