This policy applies to all organizational aspects of Smiota and all parties, its affiliated partners or subsidiaries, including data processing and process control systems, that are in possession of, or using information and/or facilities owned by Smiota.
This policy applies to all staff/ users that are directly or indirectly employed by Smiota, its subsidiaries or any entity conducting work on behalf of Smiota that involves the use of information assets owned by Smiota.
Compliance with this policy is mandatory and organizational managers shall ensure continuous compliance monitoring within their departments. Compliance with the statements in this policy is a matter of annual review by the management. Any violation will result in disciplinary action by the ISMS Steering Committee.
Disciplinary action taken will depend on the severity of the violation which will be determined by the investigation. Actions such as termination or others as deemed appropriate by Smiota’s Management and can escalate to the ISMS Steering Committee.
Technological advances and changes in business requirements will necessitate periodic revisions to policies. Therefore, this policy may be updated to reflect changes or define new or improved requirements.
Deficiencies within this policy shall be immediately communicated to the ISMR. Policy changes will require the approval of the Management during Management Review Meetings. The Change Log shall be kept current and will be updated as soon as any change has been made.
Management of Smiota is committed to protect its information assets by deploying information security controls that minimize the impact of any security incidents.
To create, maintain and continually improve the Information Security Management System and to achieve this objective, Smiota ensure the following: