The purpose of this system is to secure sensitive information belonging to our organisation and information entrusted to us by other organisation’s together with the facilities used to process and access this information.
Consistent with the strategic direction of the organisation it is the policy of Better Risk Limited (t/a Better QMS) to ensure that we have:
- Integrated security processes and procedures into our business activities to ensure that the management system achieves it intended outcome;
- Conducted a Risk Assessment in respect of Information Security within our organisation. Where unmitigated risks have been identified, we have implemented a plan to treat them. Where residual risks remain, we accept them and will review them when appropriate;
- Allocated responsibilities to ensure all required resources are identified and provided; • Taken responsibility to ensure that our suppliers discharge their responsibilities in respect to securing any sensitive information that we entrust to them;
- Committed to comply with all applicable legislation, regulations and contractual obligations which will be continuously reviewed to ensure requirements are kept up to date; and
- Committed to continually review and improve our management system through our management review process which will identify areas of improvement and set relevant objectives, ensuring that they continue to remain appropriate to our operations, interested parties and relevant compliance obligations.
All employees have been made aware of their responsibilities in respect of applicable legislation as well as their responsibilities in support of securing information within the organisation.
This policy is communicated to all employees and made available to relevant interested parties as appropriate. Compliance with the requirements of this policy is a condition of employment for our staff and failures in this respect are subject to our disciplinary process.
This policy is reviewed through the Management Review and Internal Audit programme.
