Legal
Information Security Policy — Elsworth Associates Limited (Veterans Redress). Revision date: 06/01/2020 — Version 1.3.
Elsworth Associates Limited, operating the Veterans Redress campaign (hereinafter referred to as the "Company"), has an extensive and robust Information Security Program that consists of a vast array of policies, procedures, controls and measures. This Information Security Policy is the foundation of this program and ties together all other policies as they relate to information security and data protection.
The Company Information Security Policy covers all aspects of how we identify, secure, manage, use and dispose of information and physical assets as well as acceptable use protocols, remote access, passwords and encryption. To ensure that the importance of each information security area is not missed or vague, we use separate policies and procedures for each information security area and, where applicable, reference these external policies in this document. All information security policies and procedures should be read and referred to in conjunction with each other, as their meaning, controls and measures often overlap. The policies and documents that form part of the Company Information Security Program are:
Information and physical security is the protection of the information and data that the Company creates, handles and processes in terms of its confidentiality, integrity and availability from an ever-growing number and wider variety of threats, internally and externally. Information security is extremely important as an enabling mechanism for information sharing between other parties.
The Company is committed to preserving the information security of all physical, electronic and intangible information assets across the business, including, but not limited to, all operations and activities. We aim to provide information and physical security to:
The purpose of this document is to provide the Company's statement of intent on how it provides information security and to reassure all parties involved with the Company that their information is protected and secure from risk at all times. The information the Company manages will be appropriately secured to protect against the consequences of breaches of confidentiality, failures of integrity, or interruptions to the availability of that information.
This policy applies to all staff within the Company (meaning permanent, fixed term and temporary staff, any third-party representatives or sub-contractors, agency workers, volunteers, interns and agents engaged with the Company in the UK or overseas). Adherence to this policy is mandatory and non-compliance could lead to disciplinary action.
The Company has adopted the below set of principles and objectives to outline and underpin this policy and any associated information security procedures:
Each information asset will be assigned a security classification by the asset owner or Information Security Officer, which will reflect the sensitivity of the asset. Classifications will be listed on the Information Asset Register.
Staff at the Company will only be granted access to the information that they need to fulfil their role within the organisation. Staff who have been granted access must not pass on information to others unless they have also been granted access through appropriate authorisation. Please refer to the Company's Access Management Policy for protocols and more information.
Care needs to be taken to ensure that information assets are disposed of safely and securely, and confidential paper waste must be disposed of in accordance with relevant procedures on secure waste disposal. Where an external shredding service provider is employed, secure paper disposal bins are in each office and used in all instances of confidential paper disposal.
Electronic information must be securely erased or otherwise rendered inaccessible prior to leaving the possession of the Company, unless the disposal is undertaken under contract by an approved disposal contractor. In cases where a storage system (for example a computer disc) is required to be returned to a supplier, it should be securely erased before being returned unless contractual arrangements are in place with the supplier which guarantee the secure handling of the returned equipment. Refer to the Company's Retention Policy for protocols and more information.
Members of staff who handle confidential paper documents should take the appropriate measures to protect against unauthorised disclosure, particularly when they are away from their desks. Confidential documents should be locked away overnight, at weekends and at other unattended times.
Care should also be taken when printing confidential documents to prevent unauthorised disclosure. Computer screens on which confidential or sensitive information is processed or viewed should be sited in such a way that they cannot be viewed by unauthorised persons and all computers should be locked while unattended. Refer to our Clear Desk Policy for protocols and more information.
It is the responsibility of all Company employees with remote access privileges to the company network to ensure that their remote access connection is given the same consideration as the user's on-site connection to the Company. Refer to our Remote Access & BYOD Policy for protocols and more information.
The Company understands that adequate and effective firewalls, malware protection and protected gateways are one of the main and first lines of defence against breaches via the internet and our networks.
We utilise configured firewalls and have daily anti-virus applications running on all computers, networks and servers. The IT Manager is responsible for checking the log of all scans and for keeping these applications updated and compliant.
Systems are regularly scanned and assessed for unused and outdated software with the aim of reducing potential vulnerabilities, and we routinely remove such software and services from our devices where applicable.
The IT Manager also has full responsibility for ensuring that the latest application and software updates and/or patches are downloaded and installed, keeping our security tools current and effective. Security software is reviewed and updated monthly, or sooner where updates or patches have been released.
The Company's definition of a breach, for the purposes of this and related documents, is a divergence from any standard operating procedure (SOP) which causes a failure to meet the required compliance standards as laid out by our own compliance program objectives and/or those of any regulatory body. Compliance in this document means any area of business that is subject to rules, laws or guidelines set out by a third party which are to be followed and which, when breached, could cause emotional, reputational or financial damage to a third party.
The Company has robust objectives and controls in place for preventing security breaches and for managing them if they do occur. Due to the nature of our business, the Company processes and stores a large amount of personal information and confidential client data and as such requires a structured and documented breach incident program to mitigate the impact of any breaches. Whilst we take every care with our systems, security and information, risks still exist when using technology and being reliant on human intervention, necessitating defined measures and protocols for handling any breaches.
We carry out frequent risk assessments and gap analysis reports to ensure that our compliance processes, functions and procedures are fit for purpose and that mitigating actions are in place where necessary. However, should there be any compliance breaches, we are fully prepared to identify, investigate, manage and mitigate with immediate effect to reduce risks and impact. The Company has the below objectives with regard to breach management:
All information users within the Company are responsible for protecting and ensuring the security of the information to which they have access. Managers and staff are responsible for ensuring that all information in their direct work area is managed in conformance with this policy and any subsequent procedures or documents. Staff who act in breach of this policy, or who do not act to implement it, may be subject to disciplinary procedures.
The Company will ensure that staff do not attempt to gain access to information that is not necessary to hold, know or process, and that restrictions and/or encryption are in place for specific roles within the organisation relating to personal and/or sensitive information.
If you have a question about this policy, or you wish to request access to, correction of, or erasure of the personal information we hold about you, please contact us:
Veterans Redress, a trading style of Elsworth Associates Limited
Unit 4 Edison Court, Ellice Way, Wrexham Technology Park, Wrexham, LL13 7YT
Telephone: 0800 887 0122
Email: help@veterans-redress.org
Authorised and regulated by the Financial Conduct Authority (FCA Firm Reference Number 834626) to provide Claims Management services.