Version 5.0
The confidentiality, integrity, and availability of information, in all its forms, are critical the ethical, legal and professional duty of Sicuro Group and its subsidiaries, including Sicuro Communications and Technology, Intelyse and Graal. This information security policy outlines Sicuro Group’s approach to information security management. It provides the guiding principles and responsibilities necessary to safeguard the security of the company’s information. Supporting policies provide further details. Sicuro Group is committed to a robust implementation of Information Security Management within the constraints of it’s available financial, technical and human resources. It aims to ensure the appropriate confidentiality, integrity, and availability of its data. The principles defined in this policy is applied to all the physical and electronic information assets for which Sicuro Group is responsible. Sicuro Group is specifically committed to preserving the confidentiality, integrity, and availability of documentation and data supplied by, generated by and held on behalf of third parties pursuant to the carrying out of work agreed by contract in accordance with the requirements of data security standard ISO 27001.
PURPOSE
The primary objectives of this policy are to:
SCOPE
This policy is applicable to and will be communicated to all staff, systems, and processes in the Sicuro Group companies. This includes Sicuro Group LLC, Intelyse LLC and Graal FZE.
DEFINITIONS
Sicuro Group data, for the purposes of this policy, is data owned, processed or held by Sicuro Group.
POLICY
Information security principles
The following information security principles provide overarching governance for the security and management of information at Sicuro Group.
Sicuro Group has a responsibility to abide by and adhere to all current UAE legislation as well as a variety of regulatory and contractual requirements. A non-exhaustive summary of the legislation and regulatory and contractual obligations that contribute to the form and content of this policy is provided in Appendix A.
Information Classification
The following provides a summary of the information classification levels that have been adopted by Sicuro Group.
Compliance, Policy Awareness, and Disciplinary Procedures
Any security breach of Sicuro Groups information systems could lead to the possible loss of confidentiality, integrity, and availability of personal or other confidential data stored on these information systems. The loss or breach of confidentiality may result in criminal or civil action against Sicuro Group. The loss or breach of confidentiality of contractually assured information may result in the loss of business, financial penalties or criminal or civil action. All current staff and other authorised users will be informed of the existence of this policy and the availability of supporting policies.
Incident Handling
If a member of Sicuro Group is aware of an information security incident, then they must report it to the Operations Technical Manager or a member of senior management.
Supporting Policies
Supporting policies have been developed to strengthen and reinforce this policy statement. These are published together and are available for viewing in the Sicuro Group office. All staff and any third parties authorised to access Sicuro Group’s network or computing facilities are required to familiarise themselves with these supporting documents and to adhere to them in the working environment.
REVIEW AND DEVELOPMENT
This policy and its subsidiaries shall be reviewed by senior management and updated regularly to ensure that they remain appropriate in the light of any relevant changes to the law, organisational policies or contractual obligations. The Information Security Manager will determine the appropriate levels of security measures applied to all additional information systems
Responsibilities
APPENDIX A: Non-comprehensive summary of relevant legislation
Article 378 of the Penal Code (Federal Law 3 of 1987)
TRA Unsolicited Electronic Communications Policy
European Union’s GDPR
As of the 25th of May 2018, the EU General Data Protection Regulation (GDPR) aims to unify the rules and regulations around data across Europe. It aims to strengthen the rights of individuals when it comes to their personal data. GDPR requires organizations in and outside the EU to make additional changes to the way they treat their data. These new regulations are designed to ensure companies are processing and protecting the personal data of EU residents irrespective of where they operate.
Sicuro Group welcomes these changes as we fully believe that it will bring about a higher level of data awareness, security, and care. To ensure we provide the highest level of service to our clients and partners, Sicuro Group has many GDPR compliant practices already in place to comply with our ISO standards. This is a continuous and conscious effort to keep our clients’ interests at the forefront of how we operate.
To ensure these standards are maintained, Sicuro Group will:
Law No. (26) of 2015 Regulating Data Dissemination and Exchange in the Emirate of Dubai
Federal Decree Law No. 3 of 2012 On the Establishment of the National Electronic Security Authority
Federal Decree Law No. 9 of 2014 amending certain provisions of Federal Law no. 4 of 2002 concerning combating money laundering crimes
Article 31 of the Constitution provides for a general right of “freedom of corresponding through the post, telegraph or other means of communication and the secrecy thereof shall be guaranteed in accordance with the law”.
Privacy of Consumer Information Policy (Issued on 31 May 2005)
This applies to all telecommunications licensees and to any entity that has access to personal information made available to it for purposes of providing telecommunications services.
The aim of the policy is to ensure that the information of telecommunications consumers in the UAE is protected. Consumer information includes:
Dubai Law No. 23 of 2006 relating to the Formation of the Dubai Statistics Center (Dubai Statistics Center Law)
The Dubai Statistics Center Law restricts the disclosure of personal data obtained in the course of the collection of statistics. Personal data and information collected as an outcome of statistics is considered confidential and must not be disclosed or published for non-statistical purposes, except by the Dubai Statistics Center or with its prior approval (Article 7, Dubai Statistics Center Law). Similarly, it cannot be used as a basis for taxation or criminal law activity unless it is used as evidence against those who supply the Dubai Statistics Center with false information. Article 8 excludes personal data from the types of data permitted for publication by the Dubai Statistics Center.
Data Protection Law Amendment Law, DIFC Law No. 5 of 2012 (Data Protection Law, DIFC)
Data Protection Regulations Consolidated Version No. 2 of 2012
The DIFC is a free zone and the financial hub of Dubai. It hosts the Dubai stock exchange, a number of local offices of international banks and financial institutions, and service providers such as law firms.
The Office of the Data Protection Commissioner was established under the Data Protection Legislation, DIFC as a neutral and objective body to ensure the protection of all personal information in the DIFC. The legislation creates a legal and procedural framework which ensures that all personal data in the DIFC is treated fairly, lawfully, and securely when it is stored, processed, used, disseminated or disclosed.
DIFC Data Protection Legislation is generally consistent with data protection laws in other developed jurisdictions (specifically, EU Directive 95/46/EC on data protection (Data Protection Directive) and the UK Data Protection Act 1998).