Information Security Policy
Information Security Policy
Protecting the management, safeguarding, and transmission of confidential information concerning clients, in a manner consistent with professional, ethical, legal, regulatory, and contractual requirements, is one of Cleva’s key priorities, and is recognized as fundamental to the success of the organization. The loss or theft of confidential information can have serious consequences from a legal, financial, and/or reputational standpoint, and Cleva is committed to protecting the confidentiality, integrity, and availability of clients’ confidential information, whether physical, digital, or intellectual.
Therefore, the principles of the information security policy aim to ensure that:
- Information is protected against unauthorized access;
- The confidentiality of information is guaranteed;
- The integrity of information is maintained;
- All applicable laws and regulations are complied with;
- Appropriate business continuity plans are maintained and regularly tested;
- Any detected or suspected information security breach is investigated by the competent departments responsible for such actions.
Information Security Management System
Cleva maintains an Information Security Management System (ISMS), which includes policies and procedures, and which has been designed to continuously maintain, review, and improve information security at Cleva, based on a risk assessment. The objectives of the ISMS are as follows:
- Include information security as an essential part of business, product planning and operations, ensuring compliance with the standard.
- Continuously raise awareness of information security, ensuring that all employees are familiar with information security policies, understand how information security is part of their role, and their responsibility regarding the protection of the confidentiality, integrity, and availability of information.
- Continuously analyze information security threats, ensuring they are identified and managed based on risk assessment procedures and by applying appropriate controls.
- Promote the appropriate protection of the organization’s information and communication systems infrastructure against loss, misuse, or unauthorized access.
- Promote the effective and efficient detection, recording, reporting, and investigation of security incidents, in order to ensure minimal impact of such incidents on the organization.
- Ensure the implementation and testing of business continuity plans, to guarantee the continuity of operations and minimize the impact of a security incident or emergency situation.
Information Security Management System Responsibilities
Within the ISMS, the highest governing body of Cleva is the executive committee, whose main responsibilities are as follows:
- Ensure that the ISMS is owned by and integrated into the organization’s processes and its overall management structure.
- Approve the roles and responsibilities associated with information security.
- Formally maintain a named CISO (Chief Information Security Officer) and Information Security Manager (ISM), who will be the primary points of contact with other structures within the organization regarding ISMS management activities.
Those responsible for the various business and support areas must be aware of the need to have business and support processes that comply with the organization’s information security policies, as well as their obligation to implement, within their areas, any initiatives that may be required.
All employees, as well as third parties who may in any way have access to Cleva’s clients’ confidential information, are required to comply with and enforce all of the organization’s information security policies, and must promptly report to the CISO or ISM any security incident, meaning any event that has led or may lead to an information security breach.