Information Security Policy
The Policy of Stat Solutions Ltd is on a continuing basis to exercise due care and due diligence to protect Information Systems from unauthorised access, use, disclosure, destruction, modification, disruption or distribution. This will ensure that our reputation with our clients, and all related interested parties are maintained through confidentiality, integrity and availability.
Management will ensure business, legal, regulatory requirements and contractual security obligations are taken into account, this includes the handling of Department of Education data. Risk Assessments against agreed criteria is continually undertaken.
The company will ensure it is compliant with all legal requirements including ensuring the company is General Data Protection Regulation (GDPR) compliant.
The Management Team bears the responsibility for establishing and maintaining the system and undertakes to ensure its integrity is maintained through instruction, policies and training of its staff and that each employee has a proper understanding of what is required of them.
Equally every employee has a personal responsibility to maintain this integrity.
Further, the Management will ensure any subcontractor employed for a particular function will meet the requirements specified and accept responsibility for their actions.
The company has a Policy of Continual Improvement and Objective setting in line with the ISO 27001:2017 Standard requirements.
Objectives and Targets are set to meet the requirements of this policy and are reviewed regularly at management reviews. The policy will be made available to interested parties as appropriate.
The Information Security Management System will be monitored regularly under the Management Team's ultimate responsibility with regular reporting of the status and effectiveness at all levels.