Information Security Policy
IMS P11 INFORMATION SECURITY POLICY
ISO 27001:2022 clause 5.2
1.Introduction
This Introduction This top-level information security policy is a key component of IT Solutions Ltd T/A The DS Group’s overall information security management framework and should be considered alongside more detailed information security documentation including, system level security policies, security guidance and protocols or procedures. This policy aligns with ISO 27001 (2022) and the UK Data (Use and Access) Act 2025 to ensure consistent governance of information security across The DS Group.
2. Objectives, Aim and Scope
2.1. Objectives
The objectives of the DS Group’s Information Security Policy are to:
• Ensure protection and availability of client and business data at all stages of processing.
• Minimise risk of data loss, misuse, or unauthorised access.
• Ensure compliance with legal, regulatory, and contractual obligations.
• Support continual improvement of the Integrated Management System (IMS)
2.2. Policy Aim
The aim of this policy is to establish and maintain the security and confidentiality of information, information systems, applications and networks owned or held by the DS Group by:
• Ensuring that all members of staff are aware of and fully comply with the relevant legislation as described in this and other policies.
• Describing the principles of security and explaining how they shall be implemented in the organisation.
• Introducing a consistent approach to security, ensuring that all members of staff fully understand their own responsibilities.
• Creating and maintaining within the organisation a level of awareness of the need for Information Security as an integral part of the day to day business.
• Protecting information assets under the control of the organisation.
2.3. Scope
This policy applies to:
• All information assets owned or managed by the DS Group.
• All employees, contractors, and third parties accessing information or systems.
• All systems and physical environments involved in print and mailing operations.
• Clients’ data (including personal and sensitive information) received for printing, sorting, enclosing, and posting.
• All Digital Communications (including mail, file transfer, client portals, and backups).
2.4. Out of Scope
All Personal devices not used for company work are excluded unless connected to the network.
2.5. Responsibilities for Information Security
2.5.1 Ultimate responsibility for information security rests with the Chairman of the DS Group, but on a day-to-day basis the Managing Director shall be responsible for managing and implementing the policy and related procedures.
2.5.2 The Managing Director is responsible for ensuring that their permanent and temporary staff and contractors are aware of:
• The information security policies applicable in their work areas.
• Their personal responsibilities for information security.
• How to access advice on information security matters.
2.5.3 All staff shall comply with information security procedures including the maintenance of data confidentiality and data integrity. Failure to do so may result in disciplinary action.
2.5.4 The Information Security Policy shall be maintained, reviewed and updated by the Managing Director. This review shall take place annually.
2.5.5 All employees and contractors shall be individually responsible for the security of their physical environments where information is processed or stored.
2.5.6 Each member of staff shall be responsible for the operational security of the information systems they use.
2.5.7 Each system user shall comply with the security requirements that are currently in force, and shall also ensure that the confidentiality, integrity and availability of the information they use is maintained to the highest standard.
2.5.8 Contracts with external contractors that allow access to the organisation’s information systems shall be in operation before access is allowed. These contracts shall ensure that the staff or sub-contractors of the external organisation shall comply with all appropriate security policies.
2.5.9 Training will be provided to all staff to strengthen users’ compliance with company’s information security policies.
2.5.10 Where data breaches occur, the Managing Director shall ensure reporting to the ICO within 72 hours, in line with the Data (Use and Access) Act 2025 and UK GDPR.
3 Legislation
3.1 The DS Group is obliged to abide by all relevant UK-retained or relevant European legislation. The requirement to comply with this legislation shall be devolved to employees and agents of the organisation, who may be held personally accountable for any breaches of information security for which they may be held responsible. The DS Group shall comply with the following legislation and other legislation as appropriate:
• The Data Protection Act (2018) and General Data Protection Regulation.
• The Copyright, Designs and Patents Act (1988)
• The Computer Misuse Act (1990)
• The Health and Safety at Work Act (1974)
• Human Rights Act (1998)
• Regulation of Investigatory Powers Act 2000
• Freedom of Information Act 2000
• Privacy and Electronic Communications Regulations 2003
• Digital Economy Act 2010
• Data (Use and Access) Act 2025
4 Policy Framework
4.1 Management of Security
• At top management level, responsibility for Information Security shall reside with the Managing Director.
• The Managing Director is also responsible for implementing, monitoring, documenting and communicating security requirements for the organisation.
• The Managing Director will ensure regular internal audits and risk assessments are conducted to evaluate control effectiveness.
4.2 Information Security Awareness Training
• Information security awareness training shall be included in the staff induction process.
• An ongoing awareness programme shall be established and maintained in order to ensure that staff awareness is refreshed and updated as necessary.
4.3 Contracts of Employment
• Staff security requirements shall be addressed at the recruitment stage and all contracts of employment shall contain a confidentiality clause.
• Information security expectations of staff shall be included within appropriate job definitions.
• All staff sign confidentiality agreements, password security policies, e-mail and internet policies and mobile security policies.
• All contracts will include clauses on data protection, acceptable use, and disciplinary actions for breaches.
4.4 Security Control of Assets
Each IT asset, (hardware, software, application or data) shall have a named custodian who shall be responsible for the information security of that asset.
4.5 Access Controls
Only authorised personnel who have a justified and approved business need shall be given access to restricted areas containing information systems or stored data.
Access rights shall be reviewed at least quarterly and immediately revoked upon staff departure
4.6 User Access Controls
Access to information shall be restricted to authorised users who have a bona-fide business need to access the information.
4.7 Computer Access Control
Access to computer facilities shall be restricted to authorised users who have business need to use the facilities.
4.8 Data Storage and Retention
All files and data uploaded to The DS Group will be encrypted and securely stored on a protected server which is maintained and backed up by our IT consultants and a secure client portal has been designed – see “Client Portal ToS.PDF” For Terms of Services
Files will be retained for a maximum of 14 days unless otherwise agreed upon or required for ongoing projects. When applicable, you will receive a notification before file deletion.
After 14 days, files will be automatically and permanently deleted from our servers using secure deletion methods that prevent any possibility of recovery.
Backup copies may be temporarily stored for disaster recovery purposes but will remain subject to the same security measures and deletion timescales.
4.9 Data Sharing and Access
Your data will not be sold, rented, or shared with third parties without your explicit consent, except when required by law or necessary for legal proceedings.
Authorised personnel may access your data strictly for troubleshooting maintenance, or
fulfilling service obligations. All access is logged and monitored.
Any external transfers of your data will be conducted securely and only with your written
agreement.
Data sharing agreements (DSAs) shall be in place before any external data transfers occur.
4.10 Application Access Control
Access to data, system utilities and program source libraries shall be controlled and restricted to those authorised users who have a legitimate business need e.g. systems or database administrators. Authorisation to use an application shall depend on the availability of a licence from the supplier.
4.11 Equipment Security
To minimise loss of, or damage to, all assets, equipment shall be physically protected from threats and environmental hazards.
4.12 Computer and Network Procedures
Management of computers and networks shall be controlled through standard documented procedures that have been authorised by top management and the company’s IT consultants.
4.13 Information weaknesses
All information suspected weaknesses are to be reported to the Managing Director and shall be investigated to establish their cause and impacts with a view to avoiding similar events.
4.14 Protection from Malicious Software
The organisation shall use software countermeasures and management procedures to protect itself against the threat of malicious software. All staff shall be expected to co-operate fully with this policy. Users shall not install software on the organisation’s property without permission from the Managing Director. Users breaching this requirement may be subject to disciplinary action.
4.15 User media
Removable media of all types that contain software or data from external sources, or that have been used on external equipment, require the approval of Managing Director before they may be used on the DS Group systems. Such media must also be fully virus checked before being used on the organisation’s equipment. Users breaching this requirement may be subject to disciplinary action.
4.16 Accreditation of Information Systems
The organisation shall ensure that all new information systems, applications and networks include are approved by the Managing Director before they commence operation.
4.17 System Change Control
Changes to information systems, applications or networks shall be reviewed and approved by the Managing Director.
4.18 Intellectual Property Rights
The organisation shall ensure that all information products are properly licensed and approved by the Managing Director. Users shall not install software on the organisation’s property without permission from the Managing Director. Users breaching this requirement may be subject to disciplinary action.
4.19 Business Continuity and Disaster Recovery Plans
The organisation shall ensure that business impact assessment, business continuity and disaster recovery plans are produced for all applications, systems and networks.
4.20 Reporting
The Managing Director shall keep the Chairman informed of the information security status of the organisation by means of regular reports and presentations.
4.21 Further Information
Further information and advice on this policy can be obtained from the Managing Director.
5 FTP Client Portal Security and Usage
5.1 Purpose
The DS Group provides a secure FTP Client Portal to facilitate the upload and transfer of client data for print, mail, and fulfilment services. This section defines the security and operational controls governing its use.
5.2 Governance and Compliance
The FTP Client Portal shall operate in full compliance with the organisation’s Information Security Policy, the Data Protection Act 2018, the UK GDPR, and the Data (Use and Access) Act 2025.
All users must also comply with the Terms of Service for the FTP Client Portal (current version available from the Managing Director or via the portal).
5.3 Data Storage and Retention
• All files uploaded to the FTP Client Portal are encrypted and stored within Tier III UK-based data centres.
• Files are retained for a maximum of 14 days, unless otherwise agreed or required for ongoing projects.
• After this period, files are automatically and permanently deleted using secure erasure methods that prevent recovery.
• Backup copies may be held temporarily for disaster-recovery purposes under identical security and deletion controls.
5.4 Access Control and Authentication
• Access is restricted to authorised DS Group personnel and verified client users who have been granted credentials.
• Users must maintain the confidentiality of their credentials and report any suspected unauthorised access immediately.
• Multi-factor authentication and secure connection protocols (e.g. SFTP/FTPS) shall be enforced.
5.5 Acceptable Use and Monitoring
• The portal must be used solely for legitimate business purposes related to contracted services.
• Uploading, distributing, or storing illegal, harmful, or unauthorised content is strictly prohibited.
• All activity within the portal is logged and monitored for security, audit, and compliance purposes.
• Misuse may result in account suspension or disciplinary action.
5.6 Service Availability and Liability
• The service is provided on a best-effort basis. Planned maintenance or unforeseen incidents may cause temporary downtime.
• The DS Group shall not be liable for service interruptions or data loss arising from events beyond its reasonable control.
5.7 Incident Response and Breach Notification
• Any actual or suspected data breach involving the FTP Client Portal must be reported immediately to the Managing Director.
• Breaches shall be handled in accordance with the organisation’s incident-management procedure and relevant legislation, with notification to affected parties and the ICO within the statutory timeframe.
5.8 Review and Amendment
This section and the related Terms of Service shall be reviewed annually, or sooner if legislation, technology, or operational practices change.
Signed: Allistair Hunter
Date: 5th April 2025
Chairman/Director