Information Security Policy Statement.
Our commitment to protecting the confidentiality, integrity and availability of the data and systems entrusted to us.
The management of Greenwich Registrars and Data Solutions Limited (“GRDS”) recognises that its activities and operations require a level of security to be determined and enforced. We are committed to continually improving an Information Security Management System (ISMS) to ensure that data and information systems are adequately protected against the loss of confidentiality, integrity and availability.
We are committed to ensuring that, in business operations and the delivery of our services, the requirements of clients, shareholders, staff members and other stakeholders are determined and met with the aim of enhancing satisfaction.
Information Security Management System
In support of our commitments, the Information Security Management System (“ISMS”) has been developed and is appropriate to the nature, scale and impacts of our activities, products and services.
The Information Security Management System and its associated organisational arrangements, systems and procedures will be reviewed at least annually and revised as necessary to ensure its continuing suitability.
The objectives of implementing and maintaining an Information Security Management System for the benefit of all stakeholders include:
- To ensure 99% protection of GRDS information assets and systems from unauthorised access.
- To ensure 100% compliance with legal and regulatory requirements addressing information security.
- To ensure 99% of information security risks and cyber threats are reduced and are effectively managed.
Information Security Policies
To achieve the information security objectives, GRDS has established the following Information Security Policies:
- Project Management Policy — regulates how projects are planned, executed and delivered based on proven project management methodologies, to ensure projects are completed on time and on budget.
- Mobile Device Policy — establishes rules for how mobile devices are used and secured within the organisation.
- Remote Working Policy — regulates employees that work from a non-office location.
- Acceptable Use Policy — stipulates constraints and practices that a user must agree to for access to a corporate network, the internet or other resources.
- Information Labelling and Classification Policy — categorises the organisation’s stored information based on its sensitivity level, ensuring proper handling and lowering organisational risk.
- Access Control Policy — specifies how access is managed and who may access information under what circumstances.
- Password Policy — establishes standards for the creation of strong passwords, the protection of those passwords, and the management process for all organisation information systems and services.
- Cryptographic Policy — establishes requirements for the use and protection of cryptographic keys throughout their entire lifecycle.
- Clear Desk and Clear Screen Policy — ensures that all sensitive or confidential materials are removed from an end-user workspace and locked away when not in use, or when a user leaves their workstation.
- Change Management Policy — the guiding standard describing the procedures for, and the rules and levels of authorisation required to approve, different types of changes.
- Malware Protection Policy — designed to protect systems from cyberattacks and malware attacks.
- Backup Policy — a set of rules and procedures that describe the organisation’s strategy when making backup copies of data for safekeeping.
- Software Policy — sets out how software is acquired, registered, installed and developed within GRDS, and sets rules to manage versions of software and related documentation.
- Capacity Management Policy — ensures optimal utilisation of capacity in terms of IT infrastructure, resources and capabilities to meet agreed current and future business requirements.
- Network Security Policy — a formal document outlining the principles, procedures and guidelines to enforce, manage, monitor and maintain security on a computer network.
- Solution Delivery Life Cycle Policy — ensures a clear definition of goals and stages of building or purchasing a software solution.
- Managing Third-Party Vendor Policy — establishes guidelines and practices for how the organisation assesses, monitors, remediates and reports on the risk posed by vendors, suppliers and business partners.
- Incident and Problem Management Policy — aims to restore agreed IT services as soon as possible and to minimise disruptions by proactively identifying and analysing the cause of incidents and by managing problems to closure.
- IP, Copyright and Software Licensing Policy — aims to protect GRDS’ intellectual property and minimise the possibility of infringement of the intellectual property rights of the organisation and third parties.
- Records Management and Data Retention Policy — GRDS’ approach to managing personal data as well as all company data or records from the point of collection or creation, through use, storage and retention, to disposal and destruction.
- Records Management and Document Retention Policy — established to deal with issues identified with paper-records storage and to eliminate unnecessary retention of paper records.
- Data Protection Policy — sets out how GRDS collects, processes and stores the personal data of its employees, customers, clients, contractors, vendors and other third parties, and sets rules and guidelines for ongoing compliance with data protection laws.
- Patch Management Policy — a set of guidelines to ensure controlled, efficient and secure patching of GRDS systems.
- Bring Your Own Device (BYOD) Policy — allows employees to use their personally owned devices for work-related activities.
The Information Security Policies will be provided and made available to all relevant stakeholders and will be reviewed periodically to take account of applicable local, statutory, regulatory and customer requirements and any changes in business activity.
The Information Security Policies are applicable to all GRDS’ employees, its contractors, its consultants and other individuals affiliated with third parties who have access to GRDS’ information or business interest.
Our Commitments
Compliance
To comply with all relevant legislation, regulations and other requirements specifically related to our business activities.
Communications
To ensure our policy is brought to the attention of all our people and to seek their co-operation in supporting management in its efforts to establish and maintain our information security objectives. To ensure our policy is available to potential and existing clients and other interested parties through conventional marketing methods and on our website.
Continual Improvement
To the continual improvement of our management systems and our performance to reach our ISMS objectives. This is achieved by consultation with members of staff, clients and other interested parties, and by management review.
Resources
To determine and ensure the provision of the necessary resources to allow us to achieve our objectives for information security.
Competence
To determine the necessary competence of our people and to ensure, through training and experience, that they are competent to undertake their duties. To provide guidance and assistance to enable all our people to understand and carry out their responsibilities regarding the requirements of the ISMS.
Awareness
To promote a workplace culture of increased information security in our people.
Suppliers and Contractors
To satisfy ourselves that any organisation contracted to carry out any work of a critical nature to us can demonstrate that it pays due regard to our information security requirements in relation to the products and services they supply to us.
Contact
For further enquiries on the Information Security Management System, or to report suspected information security incidents or weaknesses, kindly contact the Risk and Control unit: riskandcontrol@gtlregistrars.com.
The responsibility to achieve information security objectives and enjoy the benefits of the ISMS strongly depends on every stakeholder in Greenwich Registrars and Data Solutions Limited. All stakeholders are encouraged to ensure they play their part in delivering GRDS’ information security objectives.
Kayode Falowo
Board Chairman