Hopp til innhold
[ TRUST · INFORMATION SECURITY ]

Information Security Policy

The security and privacy commitments Craftsmen Ltd works to under its integrated ISO/IEC 27001:2022 and ISO/IEC 27701:2019 management system, who is accountable for each of them, and how the document itself is kept current.

DOCUMENT NO.
IMS-PL-01
VERSION
1.0
STANDARD / CLAUSE
ISO/IEC 27001:2022 & ISO/IEC 27701:2019 · A.5.1, Cl. 5.2
EFFECTIVE DATE
23 May 2026
OWNER
CEO
CLASSIFICATION
Internal
APPROVED BY
Mahmudul Haque Azad (CEO)
REVIEW
Annual / on change

Purpose

To state Craftsmen Ltd’s commitment to protecting the confidentiality, integrity and availability of information within its operational boundary, and to satisfying applicable security and privacy requirements.

Scope

Applies to all information and personal data handled by Craftsmen, all personnel, and all systems and devices under Craftsmen’s control, including remote working.

Policy Statements

  • Craftsmen protects the confidentiality, integrity and availability of information it owns or is entrusted with.
  • Information security and privacy risks are assessed and treated proportionately to the organisation’s scale and operating model.
  • Personnel comply with the information security and privacy policies, the acceptable use undertaking and confidentiality obligations.
  • Access to information is granted on a least-privilege, need-to-know basis with strong authentication.
  • Security and privacy incidents are reported, managed and learned from.
  • Craftsmen complies with applicable legal, regulatory and contractual obligations, including GDPR where applicable.
  • The integrated ISMS/PIMS is continually improved through audit, review and corrective action.

Roles and Responsibilities

Role Responsibility
CEO Accountable for information security and privacy; approves policies and the SoA.
Management Representative Coordinates the ISMS/PIMS, risk, audit and review.
General & Admin (G&A) Operates access, asset, personnel and physical-security controls.
All Personnel Comply with policies and report incidents.
  • Integrated ISMS/PIMS Manual (CML-IMS-MAN-01)
  • Statement of Applicability (CML-IMS-SOA-01)
  • All IMS procedures

Compliance and Review

Compliance with this policy is mandatory for all personnel within scope. Non-compliance may be addressed through the disciplinary process. This policy is reviewed at least annually and whenever significant changes occur, and is approved by top management.

Revision History

Version Date Description Approved By
1.0 23 May 2026 Initial issue. Mahmudul Haque Azad
NEED MORE INFORMATION?

If you need further information about our security, privacy, or quality practices, we are here to help.

Email Craftsmen