Information security is a critically important issue for any organization, and especially for companies like Italsicurezza S.r.l., which not only manages vital business information but also frequently comes into contact with its customers’ information and data.
Technological progress and the rapid digital transformations of recent years have impacted the company’s risk landscape, which has had to deal with a significant increase in cyber risks aimed at compromising the company’s information assets.
For this reason, Management has deemed it appropriate to define a policy for managing information to be shared with all internal staff as well as with external parties who, interacting with Italsicurezza S.r.l., may come into possession of it.
The purpose of this policy is to define:
- the general objectives;
- the principles of action;
In order to protect Italsicurezza S.r.l.’s information assets, as well as its customers’ information managed throughout the lifecycle of the products and services provided, from all threats—internal or external, intentional or accidental. Management is committed to consistently ensuring information security by implementing a set of processes, procedures, and organizational structures.
The policy applies to the design, marketing, installation, maintenance, and support of intrusion detection systems, video surveillance systems, access management systems, fire detection systems, and fire prevention devices, as well as to the design, marketing, installation, maintenance, and support of security and safety systems.
Aware that its design, installation, and maintenance activities for external parties may involve entrusting critical data and information, Italsicurezza S.r.l. operates in accordance with internationally recognized security standards.
Su tale linea Italsicurezza S.r.l. ha deciso di porre in essere un Sistema di Gestione per la Sicurezza delle Informazioni (SGSI) conforme ai requisiti della norma internazionale ISO/IEC 27001. Il Sistema di Gestione per la Sicurezza delle Informazioni (SGSI) si basa fondamentalmente su tre obiettivi chiave:
- Confidentiality
- Integrity
- Availability
Italsicurezza S.r.l., with reference to the services provided and included in its certification scope, identifies the R.I.D. triad as follows:
- Confidentiality = ensuring that information is protected from possible use or access by unauthorized parties; it is the ability of information to be available at any given time only to authorized users/processes. Management uses tools such as encryption, usernames and passwords, and specific authentication procedures to ensure information confidentiality.
- Integrity = ensuring that information cannot be modified or deleted by unauthorized, voluntary, or involuntary actions (including system damage or malfunctions); it is the ability to maintain the accuracy of information. To ensure the integrity of information and its control, Management uses activity logging systems and recovery procedures from encrypted backups where necessary.
- Availability = ensuring that information is immediately accessible and usable, for a specified period of time and uninterruptedly, by authorized users; it is the ability to maintain access to information for a defined period of time. To ensure information availability, Management uses disaster recovery and business continuity tools. It also performs ongoing monitoring and maintenance of the IT infrastructure.
The Management has established the following objectives for Information Security:
- establish and implement an Information Security Management System based on the ISO/IEC 27001 standard;
- ensure an appropriate level of information security for the entire duration of commercial relationships with its customers, through the identification, evaluation and treatment of the risks to which the information is subject;
- ensure the continuity of the company’s business processes and the services provided to its customers;
- prevent information security incidents and minimize their impacts, safeguarding the interests of the company and other stakeholders;
- ensure compliance with applicable mandatory legislation;
- increase the level of awareness and competence on information security issues among its staff;
- safeguard the company image perceived by customers as a reliable and competent supplier;
- identify improvement opportunities aimed at increasing the effectiveness and efficiency of the management system and its processes.
For each of these objectives, specific annual targets are set to support and confirm continuous improvement. To achieve the aforementioned objectives, Italsicurezza S.r.l. has defined the following principles:
- information is a vital asset for the organization and must be protected through effective means of protection and control that guarantee its confidentiality, integrity and availability;
- Customer information entrusted to Italsicurezza S.r.l. for any reason must be protected as if it were their own and in any case in compliance with any contractual agreements established;
- mandatory laws and regulations on information protection established by the competent authorities are the highest priority requirements in the creation of products and services and in day-to-day operations;
- the controls put in place to ensure information security must be determined through a rigorous and continuous risk management process;
- training/information on information security issues and the company processes implemented to ensure it must be provided to company personnel;
- The information security management system must be based on internationally recognized models and best practices and be oriented towards continuous improvement.
In order to ensure compliance with the principles listed above and the achievement of the objectives, the following general guidelines for managing information security risks have been defined:
- information protection must be ensured by a systematic application of controls appropriate to the importance
- of the information to be protected;
- controls must be determined through a risk management process designed and implemented on the basis of international standards (ISO 31000 and ISO/IEC 27005);
- the effectiveness of controls must be constantly monitored in order to identify opportunities for improvement;
- internal and external stakeholders must be made aware of the effectiveness of the overall risk management process and consulted when necessary at decision-making stages;
- decisions regarding risk treatments must be entrusted to personnel with appropriate authority, competence and responsibility who must decide on the basis of an accurate risk assessment;
- the residual risks resulting from the risk weighting phase must comply with the risk criteria defined by Management and, in any case, be in full compliance with applicable laws and regulations;
- any information security incidents must be resolved promptly and must feed into a risk reassessment process;
- The identification and analysis of potential risks must be based on historical data within the organization, information from specific organizations in the information security field, and specialized industry literature.
Italsicurezza S.r.l. has defined, approved, published, and communicated its information security policies to company personnel and other interested parties; these policies are available to interested parties.
Furthermore, Italsicurezza S.r.l. periodically monitors the ISMS and prepares specific documentation highlighting performance and compliance with standards, legislation, regulations, and contractual and operational provisions.
This policy is subject to periodic review and/or in the event of significant changes regarding information security, in order to ensure its suitability, adequacy and efficiency.
Italsicurezza S.r.l.
The Management
POL02 – Information Security Policy
Rev.2 12/02/2024