Information Security Policy
GENNAKER SLU, which provides services for the design, development, implementation, support and improvement of technological crew management systems for merchant vessels, establishes this Information Security Policy as a reference framework for protecting information within the scope of the Information Security Management System and maintaining the trust of customers, users, suppliers and relevant interested parties.
Management is committed to implementing, maintaining and improving the Information Security Management System in accordance with ISO/IEC 27001:2022, integrating information security into the planning, execution, monitoring and improvement of the activities included within the system’s scope.
2. INFORMATION SECURITY COMMITMENTS
GENNAKER SLU undertakes to:
- Protect the confidentiality, integrity and availability of information processed or accessed during the design, development, implementation, support and improvement of the technological systems included within the scope of the ISMS.
- Apply a risk-based approach to information security management, using defined criteria to identify, assess, treat, review and accept information security risks in a manner proportionate to the organisation’s activities, services, assets and existing technological dependencies.
- Comply with all legal, regulatory, contractual, privacy, confidentiality, intellectual property and information security requirements applicable to the organisation, its services and the information it manages.
- Maintain defined information security responsibilities and authorities, taking into account the functional roles of the ISMS, the organisation’s actual structure and the involvement of suppliers or partners when they participate in activities within the system’s scope.
- Establish a framework for information security objectives aimed at protecting information, reducing risk, ensuring the traceability of changes and deployments, responding to incidents, maintaining proportionate service continuity and improving ISMS performance.
- Promote competence, awareness and compliance with internal information security rules among people who work for the organisation or act on its behalf.
- Apply proportionate criteria for access control, identity management, authentication, least privilege and the revocation or modification of access rights across systems, repositories, cloud/SaaS services, documentation and other information assets for which the organisation is responsible.
- Protect source code, technical documentation, configurations, released versions, development evidence, ISMS records and customer information against unauthorised access, alteration, loss, misuse or unauthorised disclosure.
- Manage information security in relationships with suppliers, cloud/SaaS services, development subcontractors and external partners that may affect the confidentiality, integrity or availability of information and services within the system’s scope.
- Report, record, assess and address events, incidents, defects or nonconformities that may affect information security, using the established procedures and records to preserve traceability, support an effective response, promote learning and enable continual improvement.
3. APPLICATION FRAMEWORK FOR OBJECTIVES, COMMUNICATION AND REVIEW
This policy is implemented through the Integrated Management System Manual, the Internal Information Security Rules, the Statement of Applicability, the risk methodology, the risk treatment plan, the applicable operating procedures and the records defined by the system. The main ISMS records are maintained using authorised systems, including ISOfy where designated for risks, objectives, applicability, training, audits, management reviews, improvement, nonconformities, assets and incidents.
The Information Security Policy is communicated to the people participating in the ISMS, made available to relevant interested parties where appropriate and used as a reference for establishing and reviewing information security objectives.
Management reviews the continued suitability of the policy whenever significant changes occur within the organisation, its services, applicable requirements or information security risks, as well as through the ISMS’s ordinary review cycle.