Express Teleservice Corp.
Information Security Policy
This policy defines the mandatory minimum information security requirements for the Express Teleservice Corp.
This policy acts as an umbrella document to all other security policies and associated standards and guidelines.
Express Teleservice Corp. is committed to preserving the confidentiality, integrity and availability of information stored and processed in Express Teleservice Corp., whether it belongs to Express Teleservice Corp., our employees, partners, customers, or suppliers and their clients.
For this purpose, Express Teleservice Corp. has established and implemented an information security management system (ISMS) to the requirements of ISO 27001. Express Teleservice Corp. maintains and continually improves the ISMS.
Express Teleservice Corp. management demonstrates leadership and commitment concerning the ISMS by:
- ensuring the information security policy and the information security objectives are established and are compatible with the strategic direction of the organization;
- ensuring the integration of the information security management system requirements into the organization’s processes;
- assigning specific roles and responsibilities;
- ensuring that the resources needed for the ISMS are available; and
- promoting continual improvement of the ISMS.
The key objectives of the ISMS include the following:
- Ensuring compliance with applicable information security regulations and expectations of interested parties;
- Ensuring cyber resilience and process continuity in Express Teleservice Corp.;
- Identifying information security risks and reducing them to an acceptable level;
- Protection against unauthorized access to customer and end-user information;
- Ensuring the continuity of key services.
The specific objectives of the ISMS include the following:
- Development and implementation of policies, procedures, and measures to ensure information security;
- Monitoring and analysis of security incidents, as well as conducting investigations and implementing corrective measures;
- Curtailing unwanted traffic and updating anti-fraud technical and organizational measures;
- Raising staff awareness and competence in information security matters.
The fundamental principles of the ISMS are as follows:
- Information security is an integral part of every procedure, process or activity in Express Teleservice Corp.;
- All Express Teleservice Corp. employees treat information security as a vital part of their day-to-day work;
- Express Teleservice Corp. continually improves the suitability, adequacy and effectiveness of the ISMS.
The Information Security Policy is valid until 31.12.2025. The Information Security Policy is subject to periodic assessment, revision and updating every two years or, if necessary, at shorter intervals to reflect changing conditions.
Date: 02/01/2024
Approved by: Nadejda Papernaia