ISO IEC 27001:2022
INFORMATION SECURITY POLICY
Criticalcase S.r.l., a company subject to the direction and coordination of Critical Holding S.r.l., considers information security to be an essential factor for the protection of its information assets and a strategic element that can easily be transformed into a competitive advantage. We are aware that our design and development activities for third parties may involve entrusting us with critical data and information. For this reason, we intend to adopt the technical and organizational measures necessary to best guarantee the integrity, confidentiality, and availability of both our internal information assets and those entrusted to us by our Clients.
In line with this approach, Criticalcase S.r.l. has decided to implement an Information Security Management System (ISMS) defined according to the rules and criteria set by international best practices and standards, also in compliance with the guidelines of the international standard ISO IEC 27001:2022. The primary goal of the ISMS is to promote the continuous improvement of system performance.
The objective of the Information Security Management System of Criticalcase S.r.l. is to ensure an adequate level of data and information security within the design, development, and delivery of Criticalcase S.r.l. services. This is achieved through the identification, evaluation, and treatment of the risks to which these services are exposed, prioritizing the following security requirements:
- Confidentiality: The property that information is made available or disclosed only to authorized individuals.
- Integrity: The property of information remaining intact by reducing, to acceptable levels, the risk of deletion or modification resulting from unauthorized entities or uncontrollable events.
- Availability: The property of information being accessible and usable upon demand by authorized processes and users.
Furthermore, through this policy, Criticalcase S.r.l. intends to formalize the following objectives in the field of information security:
- Best preserve the image of Criticalcase S.r.l. as a reliable and competent supplier;
- Protect its own information assets;
- Best avoid delivery delays;
- Adopt measures to ensure staff retention and professional development;
- Fully comply with current and mandatory legal and regulatory requirements;
- Increase the level of awareness and competence on cybersecurity issues among its staff.
To achieve these objectives, we have established procedures, tools, and responsibilities for crucial system activities, such as:
- Protection and classification of all information;
- Prompt availability of information to the people directly involved;
- Systematic risk analysis associated with information management, applied to every organizational change and project/contract;
- Definition of responsibilities for secure data and information management at every management level.
Key Roles and Responsibilities
The key roles participating in the achievement of these objectives are:
Employees
They implement procedures in compliance with this policy and report any anomalies—even those not formally codified—of which they become aware.
Executive Management
Tasked with setting objectives, ensuring clear alignment with business strategies, and providing visible support for security initiatives. Management promotes security by guaranteeing adequate budgets dedicated to security, consistent with defined corporate policies and strategic guidelines.
Information Security Management System (ISMS) Manager
Responsible for designing the Information Security Management System, specifically:
- Issuing all necessary rules, including document classification types, to enable Criticalcase S.r.l. to conduct its activities securely;
- Adopting criteria and methodologies for risk analysis and management;
- Suggesting organizational, procedural, and technological security measures to safeguard the security and business continuity of Criticalcase S.r.l.;
- Planning specific and periodic security training paths for staff;
- Periodically monitoring the exposure of Criticalcase S.r.l. services to major threats;
- Investigating security incidents and adopting appropriate countermeasures;
- Promoting an information security culture.
External Entities / Third Parties
Suppliers (of goods and services) maintaining relationships with Criticalcase S.r.l. must guarantee compliance with the security requirements outlined in this security policy, including through the signing of a Non-Disclosure Agreement (NDA) upon assignment when such a clause is not explicitly included in the main contract.
Note: Management will periodically verify the effectiveness and efficiency of the Information Security Governance System, ensuring adequate support for the implementation of necessary improvements. This enables a continuous process that keeps changing surrounding conditions and Criticalcase S.r.l.’s business objectives under control to ensure proper adaptation.
