This policy outlines Unicis Tech OÜ's commitment to protecting customer data and information assets in accordance with ISO 27001:2022 and applicable EU regulations (GDPR, NIS2, CRA, DORA).
Unicis Tech OÜ is committed to:
This commitment is endorsed by senior management and communicated to all employees and contractors working with customer data.
Our Information Security Management System applies to:
Out of scope: Cloud platforms managed by vendors (AWS, Mautic, Dolibarr, GitHub, etc.) — vendors are responsible for their security.
We measure our security performance against these targets:
| Objective | Target | How We Measure |
|---|---|---|
| Incident Response | Respond to P1 security incidents within 2 hours | Incident response log |
| Vulnerability Management | Patch critical vulnerabilities within 7 days | Patch deployment log |
| Access Control | 100% of access requests approved; revoke within 24h of departure | Access control log |
| Incident Detection | Detect suspicious activities continuously via monitoring | Security monitoring alerts |
| Data Encryption | 100% of customer data encrypted at rest and in transit | Encryption audit |
| Audit Compliance | Zero high/critical findings in annual audits | Third-party audit reports |
See our Scorecard for real-time performance metrics.
We identify, assess, and manage information security risks using international best practices. See Risk Assessment Framework for our methodology.
Risks are prioritized by impact and likelihood; we focus resources on the most serious threats.
Every person who touches customer data has a security responsibility:
See Accountability Chart for security roles and responsibilities.
We continuously improve security through:
| Role | Responsibility |
|---|---|
| CEO / ISMS Sponsor (Predrag) | Approve and support security policy; allocate resources; review metrics quarterly |
| CTO / Technical Lead (Peter) | Implement technical security controls; manage vulnerabilities; respond to security incidents |
| Operations Lead (Alexander) | Manage access control; support incident response; coordinate security training |
| All Employees | Follow security policies; report incidents; complete annual training |
This ISMS policy helps Unicis comply with:
| Regulation | How ISMS Supports It | Related Document |
|---|---|---|
| GDPR (EU 2016/679) | Article 32 (technical & organizational measures); Article 33 (incident notification) | Privacy Policy |
| NIS2 (EU 2022/2555) | Article 21 (cybersecurity measures); Article 23 (incident reporting) | NIS2 Scope |
| CRA (EU 2023/1230) | Security updates; incident management; product security | CRA Scope |
| DORA (EU 2023/2164) | Operational resilience; risk management; third-party risk | Trusted Subprocessors |
Have questions about our security commitments or compliance?
→ Email us: security@unicis.tech