Information Security Policy

Illustration

Issue Date: 26–JUN–2023

Introduction

NVOY Technologies Limited, which provides Scalable IT for fast growing companies helps fast growing companies develop and deploy a cloud first scalable IT strategy and provide a full managed service for IT support. The service is ideal for fast growing companies and gives a flexible per user per month purchasing model for IT support, along with the advantage to add other important services as needed, like project work, IT supply, cloud software billing and consultancy services (e.g. ISO compliance).

NVOY Technologies LTD , is committed to preserving the confidentiality, integrity and availability of all assets, including personally identifiable information (PII), in scope of the information security management system (ISMS) in order to compete in the marketplace and maintain its legal, regulatory and contractual compliance and commercial image.

NVOY Technologies Limited is committed to ensuring compliance with all applicable legislative, regulatory and contract requirements, including all applicable PII protection legislation. To achieve this,

NVOY Technologies Limited has implemented an ISMS in accordance with the international standard ISO/IEC 27001:2013. The ISMS is subject to continual, systematic review and improvement.

Policy objectives

Information is made available to all authorized parties with minimal disruption to the business processes.

Information security and privacy risks are managed.

The integrity of this information is maintained.

Confidentiality of information is preserved.

Regulatory, legislative and other applicable requirements related to information security are met.

Appropriate information security and privacy objectives are defined and measured. Appropriate business continuity arrangements are in place to counteract interruptions to business activities and these take account of information security.

Appropriate information security and privacy education, awareness and training is available to staff and relevant others, e.g. suppliers, working on behalf of NVOY Technologies Limited.

Breaches of information security or privacy and security incidents, actual or suspected, are reported and investigated through appropriate processes.

Appropriate access control is maintained and information is protected against unauthorized access. Continual improvement of the ISMS is made as and when appropriate.

Commitment to achieving, supporting and managing compliance with all applicable PII legislation, including the contractual terms agreed between NVOY Technologies Limited and its clients. Information Security Policy

Roles and responsibilities

Information Security Officer is accountable for the management and maintenance of the risk treatment plan.

Additional risk assessments may, where necessary, be carried out to determine appropriate controls for specific risks. All employees and those working under the scope of the ISMS are expected to comply with this policy and with the ISMS that implements this policy.

The consequences of breaching the Information Security Policy are set out in NVOY Technologies Limited’s disciplinary policy and in contracts and agreements with third parties.

NVOY Technologies Limited has established an Information Security Team chaired by the CEO to support the ISMS framework and to periodically review the Information Security Policy.