Information Security Policy
Pupose an scope
This policy sets oot how RODMENA LIMITED pertects the confidentiality, integrity an availability o information — oor ain, an information lippened tae us by customers. It applies tae iverybody that wirks for or wi the company, an tae aw systems we operate. It is deliberately proportionate tae a smaa specialist supplier: few controls, applied rigorously, raither nor mony applied on paper.
Commitments
- Information is classifee'd by sensitivity an haunled accoardin; customer data is aye treatit as confidential.
- Access tae systems an data follaes least privilege an is reviewe't whan roles or ingagements chynge.
- Key accoonts (code hostin, infrastructure, email) uise multi-factor authentication an strang unique credentials in a password manager.
- Aa services uses encryption in transit (TLS); portable devices uses full-disk encryption.
- Operatin systems an dependencies is patched swith, pit first by severity.
- We haud the minimum personal data needit tae operate (see oor Privacy Policy) an follae UK GDPR.
- Security incidents are triaged immediately, contained, documented, and reported tae affectit pairties withoot undue delay (see security whitepaper).
- Backups fur engagement systems is scheduled, encryptit an tested agin agreed recovery objectives.
Responsibilities
The Director awns this policy, its implementation an its review. Onybody engaged bi the company maun follow it an report suspected waiknesses or incidents at once tae security@rodmena.co.uk — reportin in guid faith will never be penalised.
Certification
RODMENA LIMITED is certified under the Cyber Essentials scheme for the hale organisation, an this policy hauds the control set that certification needs. The certificate nummer, its dates an ivery ither certification status is publisht on the Trust Centre.