Information Security Policy
Information Security Policy
LAB Information Technology Incorporated has established a policy that aligns with its organizational purpose to maintain and continually improve internal processes and controls, using our Information Security Management System, to meet or exceed all applicable information security requirements for managed IT services. Through this effort, it is our goal to establish a framework that ensures the confidentiality, integrity and availability of information throughout the organization in order to provide assurance to internal and external parties.
To this end, LABUSA has produced this Information Security Policy aligned to the requirements of ISO/IEC 27001 to ensure that the organization:
- Complies to all applicable laws and regulations and contractual obligations.
- Implements Information Security Objectives that consider information security requirements following the results of applicable risk assessments.
- Communicates these Objectives and performance against them to all interested parties.
- Adopts an Information Security Management System comprising a Security Manual and Procedures which provide direction and guidance on information security matters relating to employees, customers, suppliers, and other interested parties who come into contact with its work.
- Works closely with customers, business partners and suppliers in seeking to establish appropriate information security standards.
- Adopts a forward-thinking approach on future business decisions, including the continual review of risk evaluation criteria, which may impact on information security. Instructs all members of staff in the needs and responsibilities of Information Security Management.
- Constantly strives to meet, and where possible exceed, its customer’s expectations.
- Implements continual improvement initiatives, including risk assessment and risk treatment strategies, while making best use of its management resources to better meet information security requirements.
Responsibility for upholding this policy is truly company-wide under the authority of the President who encourages the personal commitment of all staff to address information security as part of their skills.