Widget Works is certified to the ISO/IEC 27001:2022 standard which is reflected in our Information Security Policy and summarised in this statement.
As part of the standard, we are committed to upholding and continually maturing our Information Security Management System (ISMS) to protect the confidentiality, integrity, and availability of information, comply with applicable legal and regulatory obligations, and satisfy the expectations of interested parties.
Widget Works’ management is committed to providing continuous support to achieve our ISMS objectives through the implementation of robust security measures, regular assessments, and relevant information security policies, procedures, and controls, ensuring the protection of information assets and ongoing trust of our valued stakeholders. This is achieved by:
- Addressing availability requirements for Widget Works’ information and information systems.
- Protecting data from unauthorised access, modification, or loss.
- Implementing controls to ensure the confidentiality and integrity of information.
- Complying with all relevant statutory and regulatory requirements.
- Investigating and reporting breaches of information security where mandated.
- Developing, maintaining, and testing business continuity plans to counteract interruptions to business activities and protect critical business systems from the effects of major information failures or disasters.
- Providing information security education, awareness, and training to all Widget Works personnel.
- Conducting independent assessments to proactively manage information security risks and implement security controls to mitigate risks identified.
- Ensuring all employees and contractors are aware of, understand, and adhere to the policies and procedures of Widget Works’ ISMS.
This Information Security Policy Statement is available to all staff and to any interested parties as evidence of Widget Works’ commitment to information security and will be reviewed annually in line with our Information Security Policies and procedures.
