Skip to content

Information Security Policy (Clause 5.2 / A.5.1)

1. Executive Intent

Information is a vital corporate asset. The objective of this policy is to safeguard all digital, physical, and intellectual assets against internal, external, accidental, or deliberate threats.

2. Policy Principles

  • Confidentiality: Access is granted strictly on a need-to-know, least-privilege basis.
  • Integrity: Systems and data are protected against unauthorized modification, corruption, or tampering.
  • Availability: Resilient infrastructure and tested recovery procedures ensure business continuity.
  • Compliance: The organization complies with all statutory obligations (UK GDPR, Computer Misuse Act) and client contractual requirements.

3. Violations & Enforcement

Non-compliance with this policy may result in disciplinary action up to and including summary dismissal, termination of contract, and where applicable, civil or criminal proceedings.