Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| pub:trust_center:isms_policy [21.07.2026 13:27] – Information Security Management System Policy - Public commitment Predrag Tasevski | pub:trust_center:isms_policy [21.07.2026 13:55] (current) – [Regulatory Compliance] Predrag Tasevski | ||
|---|---|---|---|
| Line 48: | Line 48: | ||
| === Risk-Based Approach === | === Risk-Based Approach === | ||
| - | We identify, assess, and manage information security risks using international best practices. Risks are prioritized by impact and likelihood; we focus resources on the most serious threats. | + | We identify, assess, and manage information security risks using international best practices. |
| + | |||
| + | Risks are prioritized by impact and likelihood; we focus resources on the most serious threats. | ||
| === Shared Responsibility === | === Shared Responsibility === | ||
| Line 57: | Line 59: | ||
| * **Leadership: | * **Leadership: | ||
| * **Management: | * **Management: | ||
| + | |||
| + | See [[pub: | ||
| === Continuous Improvement === | === Continuous Improvement === | ||
| Line 68: | Line 72: | ||
| ====== Responsibilities ====== | ====== Responsibilities ====== | ||
| - | | Role | Responsibility | + | ^ Role ^ Responsibility |
| - | |---|---| | + | |
| | **CEO / ISMS Sponsor (Predrag)** | Approve and support security policy; allocate resources; review metrics quarterly | | | **CEO / ISMS Sponsor (Predrag)** | Approve and support security policy; allocate resources; review metrics quarterly | | ||
| | **CTO / Technical Lead (Peter)** | Implement technical security controls; manage vulnerabilities; | | **CTO / Technical Lead (Peter)** | Implement technical security controls; manage vulnerabilities; | ||
| Line 79: | Line 82: | ||
| This ISMS policy helps Unicis comply with: | This ISMS policy helps Unicis comply with: | ||
| - | | Regulation | + | ^ Regulation |
| - | |---|---| | + | | **GDPR (EU 2016/679)** | Article 32 (technical & organizational measures); Article 33 (incident notification) |
| - | | **GDPR (EU 2016/679)** | Article 32 (technical & organizational measures); Article 33 (incident notification) | | + | | **NIS2 (EU 2022/ |
| - | | **NIS2 (EU 2022/ | + | | **CRA (EU 2023/ |
| - | | **CRA (EU 2023/ | + | | **DORA (EU 2023/ |
| - | | **DORA (EU 2023/ | + | |
| - | See [[pub: | + | ====== Related Policies & Standards ====== |
| + | |||
| + | * [[pub: | ||
| + | * [[pub: | ||
| + | * [[pub: | ||
| + | * [[pub: | ||
| + | * [[pub: | ||
| ====== Questions About Security? ====== | ====== Questions About Security? ====== | ||
| - | Have questions about Unicis | + | Have questions about our security |
| → Email us: **security@unicis.tech** | → Email us: **security@unicis.tech** | ||
| + | |||
| + | ---- | ||
| + | |||
| + | ==== Navigation ==== | ||
| + | |||
| + | ← [[pub: | ||
| ---- | ---- | ||