Policies

Our Information Security Policy

Our Information Security Management System guarantees that activities within our scope are carried out in compliance with the ISO 27001:2022 standard.

Scope

A wide range of services spanning document and digital archive management to restoration.

It covers Document Management System, Digital Archive Management System, Electronic Document Management System, Media Archive Management System, Social Media Archive Management System, Asset Management System, RFID software solutions, custom computer software design and implementation, information systems, software development, corporate scanner and hardware sales-service, physical organisation and digitisation for archives and libraries, library cataloguing services, historical document digitisation, archiving and transcription, document conservation and restoration, and restoration materials sales and service.

Our policy

Our Information Security Management System Policy

  • Managing the Information Security Management System in accordance with TS/ISO 27001:2022,
  • Keeping the storage, transmission, modification, access and processing of assets under control based on current good practice, and ensuring in-process controls are established through the principle of segregation of duties,
  • Protecting the availability, integrity and confidentiality of information,
  • Applying physical security controls for assets stored in secure areas,
  • Assessing and managing risks that may arise concerning information assets,
  • Protecting our company’s reliability and reputation,
  • Applying the necessary sanctions in the event of an information security breach,
  • Ensuring the necessary administrative structure, resources and infrastructure are established so that information security breaches can be reported and acted upon as quickly as possible,
  • Meeting information security requirements arising from the national and international regulations we are subject to, applicable legislation, contractual obligations, and our corporate responsibilities to internal and external stakeholders,
  • Reducing the impact of information security threats on business/service continuity, and ensuring the continuity and sustainability of the business,
  • Conducting audits to oversee compliance with and continual improvement of the Information Security Management System, and taking the results into account in management review meetings,
  • Announcing this policy to all our employees and providing the resources and training needed to implement it,
  • Continuously working to raise awareness of information security among all our stakeholders,
  • Maintaining and improving the level of information security through the established control infrastructure
Document reference

PLT.32 Information Security Policy

Publication date: 26.10.2023 — Revision: 00

Related policy

See our quality policy as well.

Quality policy