Information Security Policy
Pupose an scope
This policy sets oot how RODMENA LIMITED protects the confidentiality, integrity and availability o information — oor ain, and information entrustit tae us by customers. It applies tae awbody that wirks for or wi the company, and tae aw systems we operate. It is deliberately proportionate tae a smaw specialist supplier: few controls, applied rigorously, rather than mony applied on paper.
Commitments
- Information is clessifee'd bi sensitivity an haundelt accordinly; customer data is ayeweys treatit as confidential.
- Access tae systems an data follows least privilege an is reviewed whan roles or engagements chynge.
- Key accoonts (code hostin, infrastructure, email) uise multi-factor authentication and strang unique credentials in a password manager.
- Aw services uise encryption in transit (TLS); portable devices uise full-disk encryption.
- Operatin systems an dependencies are patched swith, pitten in order o priority bi severity.
- We haud the minimum personal data needit tae operate (see oor Privacy Policy) and follae UK GDPR.
- Security incidents are triaged immediately, contained, documented, and reported to affected parties without undue delay (see security whitepaper).
- Backups for engagement systems are scheduled, encrypted and tested against agreed recovery objectives.
Responsibilities
The Director awns this policy, its implementation and its review. Onybody engaged by the company maun follow it and report suspected weaknesses or incidents at once to security@rodmena.co.uk — reporting in good faith will never be penalised.
Certification
RODMENA LIMITED is certified unner the Cyber Essentials scheme for the hail organisation, and this policy hauds the control set that certification requires. The certificate nummer, its dates and ilka ither certification status are publisht on the Trust Centre.