At Plumage, we are committed to protecting our information assets and maintaining an effective Information Security Management System (ISMS). We recognize that information security is fundamental to maintaining customer trust, ensuring business continuity, and meeting our legal, regulatory, and contractual obligations. To achieve this commitment, we shall:
Adopt a process-oriented and risk-based approach to information security management.
Identify, assess, and manage information security risks to an acceptable level through a risk management framework.
Protect the confidentiality of information by preventing unauthorized access, use, or disclosure.
Maintain the integrity of information by ensuring its accuracy, completeness, and protection from unauthorized modification.
Ensure the availability of information and critical business systems to support business continuity and operational resilience.
Protect personally identifiable information (PII) and comply with privacy, regulatory, customer, and contractual requirements.
Establish, maintain, and periodically test business continuity and disaster recovery arrangements.
Promptly report, investigate, and appropriately respond to all actual or suspected information security incidents.
Continually improve the suitability, adequacy, and effectiveness of the Information Security Management System in accordance with ISO / IEC 27001:2022.
Promote information security awareness through regular education and training for employees, contractors, and suppliers.
Ensure that information security objectives are established, monitored, and aligned with the organization's strategic direction and business objectives.