Information Security Policy


Purpose


Mapal Group (companies listed in Appendix A) is committed to protecting the confidentiality, integrity and availability of information, including personal data, and of the systems and services that support its business operations and the delivery of its products and services. Information security is essential to maintaining customer trust, delivering secure and reliable software products and services, supporting resilient business operations and enabling sustainable growth.


Policy Statements


Mapal Group shall maintain an Information Security Management System appropriate to the organisation’s business objectives, risk profile and applicable legal, regulatory and contractual obligations. To achieve this, Mapal Group shall:

  • Establish, maintain and continually improve a documented information security framework consisting of this policy, supporting standards, procedures, guidelines and records.
  • Organise information security requirements and controls into defined security domains to support consistent governance, risk management, implementation and continual improvement.
  • Define topic-specific information security requirements through CISO-approved security standards.
  • Identify, assess, treat and monitor information security risks using the approved risk assessment and treatment methodology.
  • Protect information assets through appropriate administrative, technical and physical controls.
  • Integrate information security requirements into business processes, products, services and projects.
  • Meet applicable legal, regulatory and contractual obligations relating to information security, data protection and privacy.
  • Promote security awareness and accountability across the organisation.
  • Monitor, review and continually improve the effectiveness of the information security programme and ISMS.

Authority and Governance


The Chief Executive Officer provides executive sponsorship for information security and approves this policy.

The Chief Information Security Officer is authorised to establish, maintain and approve the information security framework, including security standards, procedures, guidelines and supporting controls necessary to implement this policy and operate the ISMS.

The Information Security Board provides consultation and challenge on new or materially changed information security policies and standards, material exceptions, security risk posture and strategic security governance matters. The Board does not replace the CISO’s delegated approval authority for standards unless a matter is escalated under the approved governance or risk management process.

Standards Governance

Security standards are mandatory topic-specific information security requirements. Each standard shall be approved, published, communicated to relevant audiences, acknowledged where appropriate, reviewed at planned intervals and reviewed following significant change.


Roles and Responsibilities


The Chief Information Security Officer is accountable for establishing and maintaining the information security framework, overseeing and monitoring the effectiveness of information security controls and reporting on the security posture of the organisation.

Managers are responsible for ensuring applicable information security requirements are followed within their areas of responsibility.

System, service and data owners are accountable for the secure management of assets and information under their ownership and for ensuring applicable controls are implemented, operated and maintained.

All personnel and authorised third parties must comply with applicable information security requirements and promptly report suspected security incidents, weaknesses or policy exceptions.


Risk Acceptance


Risk acceptance authorities are defined in the approved Risk Assessment and Treatment Methodology and are not redefined by this policy.


Governance and Review


This policy shall be reviewed at least annually or following significant business, legal, regulatory, technological, organisational or risk changes. Exceptions to this policy and supporting standards must be documented, risk-assessed, approved by the appropriate authority and reviewed periodically.