Quality and Information Security Policy
Premessa
Secure Future Group (di seguito “il Gruppo” o “le Aziende del Gruppo”) è un gruppo di aziende specializzato sulla consulenza IT ed in particolare sui temi della Cyber Security e della Governance, Risk e Compliance la cui strategia è ispirata ai temi della qualità e della sicurezza delle informazioni.
Lo sviluppo delle proprie attività di business viene effettuato in linea con le politiche adottate internamente, che hanno effetto su tutte le Aziende del Gruppo.
Il presente documento si intende quindi adottato da tutte le Aziende del Gruppo, anche in aderenza ai principi del Decreto Legislativo 8 giugno 2001 n. 231 – “Disciplina della responsabilità amministrativa delle persone giuridiche, delle società e delle associazioni anche prive di personalità giuridica”, ed in particolare a:
- Secure Future S.r.l.
- Secure Future AI S.r.l.
POLITICA PER LA QUALITA’ E PER LA SICUREZZA DELLE INFORMAZIONI
In order to ensure maximum satisfaction of its customers, and all interested parties, the Management of the Secure Future Group defined the following "Quality and Information Security Policy" by framing it within a broader vision of the Group's overall strategy and the market positioning of its companies:
- guarantee its customers the realisation and delivery of services and solutions that comply not only with the contract but also with current regulations and market standards and best practices;
- pursue the continuous improvement of its products and services necessary for the realisation of the previous point;
- achieve levels of efficiency appropriate to the established mission in order to optimise the company's profitability;
- provide high-level services, promoting quality and encouraging the dissemination of the principles and behaviour underlying the quality policy to all customers;
- operate in the interest of the community, contributing to the protection of the environment, safety of human life, protection of property and social responsibility;
- contribute to the preservation of the environment and sustainable development;
- assess the internal and external context in which it operates, in order to determine business opportunities and related risks;
- improve the level of customer and stakeholder satisfaction through an approach aimed at an ever better understanding of their needs and expectations;
- consolidate its image, good reputation and high professionalism by adopting appropriate programmes, objectives and commitment with regard to the quality of services and the training and qualification of the personnel concerned;
- Continuously verify the effectiveness of the Quality and Information Security Management System and Policy adopted by its companies, through appropriate performance indicators and targets, with particular attention to those related to information security,
- implementing the measures necessary to achieve the set objectives, carrying out periodic reviews and reporting the results for continuous improvement;
- minimise the time to market of its services and solutions;
- continually nurture the staff development process;
- Involve and make all personnel aware of the application and improvement of the Integrated Management System adopted;
- always comply with current legislation and regulations;
- optimise the time taken to implement and deliver services and solutions, while maintaining the same quality levels;
- periodically assess the information security risks of all parties involved in order to reduce them to acceptable levels;
- protect its own information assets and those of its stakeholders in terms of Confidentiality, Integrity and Availability;
- Reduce as much as possible and manage information security incidents;
- meet all applicable and mandatory information security regulatory requirements.
Group Management provides the necessary resources and support to achieve the aforementioned objectives, also with a view to continuous improvement in accordance with the management systems adopted by its companies.
The management systems identify and take into account the requirements arising from the evolution of the business environment. The management of the Group, and that of its companies, are committed to ensuring the appropriate 'commitment' to quality and safety issues, ensuring that the relevant objectives are integrated into the business processes.
To guide people's approach to safety and quality, the Group considers it appropriate to adopt the following principles:
- Risk analysis on the security of the information handled is the main driver of business and project activities;
- Controls are applied to ensure adequate levels of protection against threats considered relevant to data/information;
- The level of protection identified is always in accordance with current regulations (e.g. GDPR, Legislative Decree 231/2001, etc.), as well as with market best practices;
- Information management responsibilities are formally assigned;
- The company operates in such a way as to safeguard confidentiality, integrity and availability of information.
In line with the stated principles, the Secure Future Group is committed to implementing and disseminating its Quality and Information Security Policy, guaranteeing the necessary resources and conditions for its implementation, and periodically reviewing it in order to verify its actual performance and the achievement of the stated objectives.