INFORMATION SECURITY
Protecting the Information Entrusted to Us
Information processing is fundamental to ELLECOM GmbH's activities, and the protection and security of information entrusted to us is an important organisational responsibility.
ELLECOM has established an Information Security Management System to protect the confidentiality, integrity and availability of information. Information security is managed based on risk, applicable legal and regulatory requirements and business needs.
Our information-security framework supports the protection of company information, customer information and personal data through defined policies, responsibilities and processes.
OUR INFORMATION SECURITY PRINCIPLES
CONFIDENTIALITY
Access to information is provided to persons with appropriate authority.
INTEGRITY
Information is maintained with the objective of ensuring that it remains complete and accurate.
AVAILABILITY
Information is managed so that it is available when it is needed.
RISK-BASED INFORMATION SECURITY
ELLECOM manages information security based on risk, legal and regulatory requirements and business needs.
Our information-security objectives include protecting company information and personal data, providing appropriate resources for information-security management, managing information-security risks associated with third-party suppliers and promoting a culture of information security and data protection.
INFORMATION SECURITY FRAMEWORK
ELLECOM's Information Security Management System is supported by a structured framework of internal policies and processes addressing key areas of information security.
These include data protection and retention, access control, asset management, information-security awareness and training, acceptable use, business continuity, backup, malware and antivirus protection, change management, third-party supplier security, logging and monitoring, network security, information transfer, secure development, physical and environmental security, encryption, incident management, patch management, risk management and information classification and handling.
THIRD-PARTY INFORMATION SECURITY
ELLECOM recognises that third parties that process, store or transmit information may introduce information-security risks.
Third-party suppliers are therefore managed with the objective of reducing and controlling information-security risks associated with information entrusted to external parties.
LEGAL & REGULATORY OBLIGATIONS
ELLECOM takes its legal and regulatory obligations seriously.
Applicable legal, regulatory and contractual requirements are considered within our information-security management framework and maintained within our internal processes.
TRAINING & AWARENESS
Information security is a shared organisational responsibility.
ELLECOM maintains training and communication arrangements to promote awareness and understanding of information-security policies, processes and responsibilities. Relevant training requirements are identified and managed within the organisation.
MONITORING & REVIEW
Compliance with ELLECOM's information-security policies and procedures is monitored through management review and periodic internal and external audits.
Information-security compliance may also be evaluated through business-tool reports and feedback to the responsible policy owner.
CONTINUAL IMPROVEMENT
ELLECOM's Information Security Policy and supporting information-security arrangements are reviewed and updated as part of our continual-improvement process.
Resources are provided to develop, implement and continually improve information-security management appropriate to ELLECOM's business.
OUR INFORMATION SECURITY COMMITMENT
The right people.
With the right access.
To the right information.
At the right time.
CONFIDENTIALITY · INTEGRITY · AVAILABILITY

