The purpose of this policy is to define information security requirements for information assets (physical, logical or intangible). This policy acts as a compass to provide direction to protect information assets from both internal and external threats that compromise confidentiality, integrity or availability
The scope of this policy applies to people, process, and technology systems that interact with information and information assets
- 01Management of Secure.com shall demonstrate the due commitment to enable required resources for establishing information security objectives in line with policy.
- 02Management of Secure.com shall ensure that adequate resources are provided, roles and responsibilities are clearly defined and documented, training and awareness program is established.
- 03All internal staff, outsourced staff, suppliers and third-party service providers share the commitment to the provision of appropriate levels of security across all functions that hold Secure.com and its customer information.
- 04All internal staff, outsourced staff, suppliers and third-party service providers share the obligation to protect information, assure customer privacy, and remain vigilant in preventing unauthorized or fraudulent activity.
- 05Precautions and measures shall be taken at all the times, to ensure Confidentiality, Integrity and Availability of all information systems as per the importance (value) for business activities.
- 06Information Security objectives shall be established based on organizational information security requirements, best practices and ISO 27001.
- 07Information Assets shall be identified & their associated risks assessed, evaluated and appropriate measures shall be implemented in risk treatment planning.
- 08Access to Information assets shall be controlled and access rights shall be reviewed on regular basis to align with changing business needs.
- 09Backup shall be maintained for critical data as per classification to allow continuity of business without disruption.
- 10Mechanism for reporting information security incidents shall be established for timely resolution of information security incidents.
- 11Internal audits shall be conducted for establishing the effectiveness of the implemented ISMS.
- 12Management of Secure.com shall ensure continual improvement through the periodic external assessments, established process of internal audit and risk management.
- 13Management of Secure.com shall ensure compliance with all applicable legislative and regulatory requirements.
- 14Appropriate disciplinary actions shall be taken in case of any information security breach.


For enquiries contact: support@secure.com