Information Security Management Policy

Version: 1.3  Date: November 2024  Approved by: Directors

1. Purpose

This policy defines how we protect all information, systems, and data within our business against unauthorised access, loss, misuse, or corruption. It ensures compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and our obligations as a registered organisation with the Information Commissioner’s Office (ICO).


2. Scope

This policy applies to all staff, contractors, and third parties who access or handle company information or systems, including remote workers. It covers:


3. Responsibilities


4. Data Protection & Privacy


5. System & Network Security


6. Communication & Data Transfer


7. Access Control


8. Incident Management


9. Business Continuity & Backup


10. Training & Awareness


11. Review & Compliance


Revision #2
Created 11 November 2025 12:52:23 by Admin
Updated 11 November 2025 12:53:55 by Admin