Information Security Policy
AF-MEDIA SERVICES SRL
ID: 44745059 | EUID: ROONRCJ12/3872/2021
RO93BTRLRONCRT0618644001 | RO43BTRLEURCRT0618644001 | RO18TREZ2165069XXX044884
Address: Str. A Little No. 2, Ap. 14, Cluj-Napoca
Phone: +4 0364 630165 | Email: help@aftech.ro
Website: https://aftech.ro
Introduction
This Information Security Policy (“PSI”) defines the firm's commitments AF-MEDIA SERVICES SRL to ensure the confidentiality, integrity and availability of information in the context of the provision of managed services (Managed Services Provider - MSP). PSI is developed to comply with the requirements of the ISO/IEC 27001:2022 standard and other relevant regulations.
This applies to all processes, employees, collaborators, partners and systems involved in the operation of the company.
The purpose of the Policy
The purpose of PSI is to:
- Ensure the protection of company and customer information.
- Minimize risks associated with information security.
- Comply with applicable laws and regulations.
- Support obtaining and maintaining ISO/IEC 27001 certification.
Field of Application
This policy applies:
- IT infrastructures used in the provision of MSP services.
- Company and customer data stored, processed or transmitted.
- Employees, collaborators and third parties involved in company processes.
- The company's operational and contractual processes.
Management Commitment
The management of AF-MEDIA SERVICES SRL is committed to:
- It provides the resources necessary to implement and maintain an Information Security Management System (ISMS).
- Ensure compliance with legal, contractual requirements and relevant international standards.
- Promote an organizational culture of awareness and responsibility towards information security.
Fundamental Principles
- Privacy: Access to information is allowed only to authorized persons.
- Integrity: Information is protected against unauthorized changes.
- Availability: Systems and information are accessible appropriately and at the right time.
- Compliance: Compliance with legal and contractual regulations.
Obligations of Employees and Contributors
- Each employee has the responsibility to comply with the PSI and associated procedures.
- Access to information is granted on a "need to know" basis.
- Any security or vulnerability incident must be reported immediately to superiors.
- Using company resources in a way that compromises information security is prohibited.
Risk Assessment
AF-MEDIA SERVICES SRL will implement a continuous risk assessment process that:
- Identify and classify information assets.
- Assess threats and associated vulnerabilities.
- Determines the potential impact of security incidents.
- Defines and implements appropriate controls for risk management.
Access Control
- The access control policy ensures that only authorized users can access information and systems.
- Access is granted based on the user's role and responsibilities.
- Passwords must meet strict complexity rules and be changed regularly.
Security Incident Management
- All security incidents are handled according to a documented process.
- Rapid identification, containment and remediation of incidents is ensured.
- Lessons learned from incidents are used for continuous process improvement.
Business Continuity
- A Business Continuity Plan (BCP) is implemented and periodically tested.
- Redundancy of critical data and systems is ensured.
- Backups are made regularly and are tested for integrity.
Legal and Contractual Compliance
- The Company complies with all relevant laws, including GDPR and other national and international regulations.
- Contract clauses include clear provisions on information security.
PSI Audits and Review
- PSI and SMSI are periodically audited to ensure compliance with ISO/IEC 27001.
- The policy is reviewed annually or whenever there are significant changes in the company's activity.
Responsibilities
- Director General: Responsible for PSI approval and allocation of necessary resources.
- Information Security Manager: Monitors PSI implementation and compliance.
- Employees: Comply with policy and report security incidents.
Conclusion
By implementing this Information Security Policy, AF-MEDIA SERVICES SRL is committed to protecting company and customer information while ensuring compliance with international information security standards and best practices.
This policy comes into force on the date of approval by the company's management.