INFORMATION SECURITY POLICY STATEMENT

fieldstar

 

The objective of information security is to protect the information assets of FIELD STAR SRL, its customers and partners, to ensure business continuity and to minimize damage to the business by preventing and minimizing the impact of security incidents.

The information security policy is approved by the Administrator and reflects the commitment of the management of Field Star SRL to implement and maintain an Information Security Management System, through which we can protect the information assets of the organization from all threats, whether internal or external, deliberate or accidental.

By complying with the SR ENISO/CEI 27001:2023 standard, we ensure that:

• Information will be protected against unauthorized access
• Information confidentiality will be maintained
• Information integrity will be maintained
• Information availability will be ensured when business processes require it
• Applicable legislative and regulatory requirements are met
• Business Continuity Plans will be drafted, maintained and tested.
• All personnel will be trained on information security
• All security incidents, real or suspected, will be reported and investigated by the Information Security Officer

Through this statement, the General Manager provides firm support, guidance in creating opportunities for implementing the objectives of the Information Security Policy to both the Information Security Representative (ISR) and any employee who comes up with initiatives to protect sensitive information.
All employees are directly responsible for implementing the Policy in their areas of responsibility.
Information security procedures have been implemented to apply the Policy.
Business requirements regarding the availability of information and information systems will be met.
It is the responsibility of each employee of our organization and collaborators to adhere to this Information Security Policy Statement, to know and apply the procedures as established in the Information Security Management Manual.
Failure to comply with the Security Policy will entail the application of disciplinary measures (in the case of employees) and the revocation of access rights to computing facilities and information.

The organization’s management is committed to a process of continuous improvement of the Information Security Management System, to ensuring the resources necessary to achieve the proposed objectives and apply the information security policy.

Date: 30.05.2025
General Manager: Marian Dumitrescu