Information Security Policy

Talent Wing Consultants LLP

Purpose

The purpose of this Policy is to safeguard information belonging to Talent Wing Consultants LLP (‘consultancy’) and its stakeholders (third parties, clients or customers and the general public), within a secure environment.

It is the goal of Talent Wing Consultants LLP:

Information relates to:

The Policy

The consultancy requires all users to exercise a duty of care in relation to the operation and use of its information systems.

Authorized users of information systems

With the exception of information published for public consumption, all users must be formally authorized by appointment. Authorized users will be in possession of a unique user identity. Any password associated with a user identity must not be disclosed to any other person.

Authorized users will pay due care and attention to protect consultancy information in their personal possession. Confidential, personal or private information must not be copied or transported without consideration of:

Acceptable use of information systems

Use of the Consultancy’s information systems by authorised users will be lawful, honest and decent and shall have regard to the rights and sensitivities of other people.

Information System Owners

Directors who are responsible for information systems are required to ensure that:

  1. Systems are adequately protected from unauthorized access.

  2. Systems are secured against theft and damage to a level that is cost-effective.

  3. Adequate steps are taken to ensure the availability of the information system, commensurate with its importance (Business Continuity).

  4. Electronic data can be recovered in the event of loss of the primary source. I.e. failure or loss of a computer system. It is incumbent on all system owners to backup data and to be able to restore data to a level commensurate with its importance (Disaster Recovery).

  5. Data is maintained with a high degree of accuracy.

  6. Systems are used for their intended purpose and that procedures are in place to rectify discovered or notified misuse.

  7. Any electronic access logs are only retained for a justifiable period to ensure compliance with the data protection, investigatory powers and freedom of information acts.

  8. Any third parties entrusted with consultancy data understand their responsibilities with respect to maintaining its security.

Personal Information

Authorised users of information systems are not given rights of privacy in relation to their use of consultancy information systems. Authorised persons may access or monitor personal data contained in any consultancy information system (mailboxes, web access logs, file-store etc).

  1. Individuals in breach of this policy are subject to disciplinary procedures at the instigation of the Director with responsibility for the relevant information system, including referral to the Police where appropriate.

The Consultancy will take legal action to ensure that its information systems are not used by unauthorised persons.

Ownership

Information system owners are responsible for the implementation of this Policy within their area