Purpose
To state Craftsmen Ltd’s commitment to protecting the confidentiality, integrity and availability of information within its operational boundary, and to satisfying applicable security and privacy requirements.
Scope
Applies to all information and personal data handled by Craftsmen, all personnel, and all systems and devices under Craftsmen’s control, including remote working.
Policy Statements
- Craftsmen protects the confidentiality, integrity and availability of information it owns or is entrusted with.
- Information security and privacy risks are assessed and treated proportionately to the organisation’s scale and operating model.
- Personnel comply with the information security and privacy policies, the acceptable use undertaking and confidentiality obligations.
- Access to information is granted on a least-privilege, need-to-know basis with strong authentication.
- Security and privacy incidents are reported, managed and learned from.
- Craftsmen complies with applicable legal, regulatory and contractual obligations, including GDPR where applicable.
- The integrated ISMS/PIMS is continually improved through audit, review and corrective action.
Roles and Responsibilities
| Role | Responsibility |
|---|---|
| CEO | Accountable for information security and privacy; approves policies and the SoA. |
| Management Representative | Coordinates the ISMS/PIMS, risk, audit and review. |
| General & Admin (G&A) | Operates access, asset, personnel and physical-security controls. |
| All Personnel | Comply with policies and report incidents. |
Related Documents
- Integrated ISMS/PIMS Manual (CML-IMS-MAN-01)
- Statement of Applicability (CML-IMS-SOA-01)
- All IMS procedures
Compliance and Review
Compliance with this policy is mandatory for all personnel within scope. Non-compliance may be addressed through the disciplinary process. This policy is reviewed at least annually and whenever significant changes occur, and is approved by top management.
Revision History
| Version | Date | Description | Approved By |
|---|---|---|---|
| 1.0 | 23 May 2026 | Initial issue. | Mahmudul Haque Azad |
If you need further information about our security, privacy, or quality practices, we are here to help.