LEGAL / INFORMATION SECURITY POLICY
Information Security Policy.
Protecting the organization’s information assets from all threats, internal or external.
The principal focus of Nityo's Information Security Policy is to provide:
- Confidentiality — maintaining the restriction of access to information by authorized persons, entities and processes at authorized times and in an authorized manner;
- Integrity — safeguarding the accuracy and completeness of information and information processing systems; and
- Availability — ensuring that authorized users have access to information and associated assets when required.
The purpose of this policy is to protect the organization’s information assets from all threats, whether internal or external, deliberate or accidental. It is the policy of the organization to ensure:
- Information is made available with minimal disruption to staff and the public as required by the business process.
- Critical information is protected from unauthorized access, use, disclosure, modification and disposal, whether intentional or unintentional.
- All breaches of information security, actual or suspected, are reported and investigated by designated personnel, with appropriate corrective and preventive actions taken.
- All employees, and third parties such as sub-contractors, consultants and vendors, are adequately communicated on information security programs.
- Information security objectives resulting from risk assessment are documented, communicated and monitored for their progress and evaluated for their results.
- A commitment towards the continual improvement of the information security management system.
- Risk assessment and treatment is re-reviewed after every six months.
- The policy is reviewed at periodic intervals (half-yearly) to check its effectiveness and applicability against changes in technology, risk levels, legal and contractual requirements, and business efficiency.

