Information Security Policy

This Information Security Policy covers the security and use of all dsquared’s information and communication technology systems including email, internet, cloud-based systems, voice, and mobile IT. The policy is a condition of employment and engagement for all employees and contractors by dsquared and will be implemented in line with dsquared’s Information Security Management Framework.

Scope

The scope of this information security management system encompasses dsquared’s operations and all employees, locations, technology, data assets and business processes used to deliver dsquared’s sustainability consultancy service in line with dsquared’s Vision and Mission.

Objectives

  • Meet legal, regulatory and contractual obligations for information security
  • Continually monitor our information security risks and opportunities and improving our processes in accordance with ISO 27001.
  • Commit ongoing resources to maintaining secure information systems as part of operational business planning.
  • Reduce exposure to cybersecurity events that may impact business continuity, productivity, and financial performance.
  • Meet stakeholder needs and maintaining the required information security systems and clearances for confidential and secure projects.
  • Reduce information security risks to our own operations through our workplace activities, purchasing and supply chain, and how we behave.
  • Staff and sub-contractors are aware of, understand, and adhere to dsquared’s information security systems and actively contribute to reducing security risks.

Requirements
All staff must:

  • Support the above objectives and assist in the continual improvement of dsquared’s information security management systems.
  • Adhere to dsquared’s Information Security Management Framework.
  • Adhere to the information security requirements captured in the Employee Information and Internal Procedures document

Review

  • This policy will be reviewed at least annually.