The confidentiality, integrity, and availability of information, in all its forms, are critical to the on-going functioning and good governance of Sicuro Group. Failure to adequately secure information increases the risk of financial and reputational losses from which it may be difficult for Sicuro Group to recover. This information security policy outlines Sicuro Group’s approach to information security management. It provides the guiding principles and responsibilities necessary to safeguard the security of the company’s information. Supporting policies provide further details. Sicuro Group is committed to a robust implementation of Information Security Management within the constraints of it’s available financial, technical and human resources. It aims to ensure the appropriate confidentiality, integrity, and availability of its data. The principles defined in this policy will be applied to all the physical and electronic information assets for which Sicuro Group is responsible. Sicuro Group is specifically committed to preserving the confidentiality, integrity, and availability of documentation and data supplied by, generated by and held on behalf of third parties pursuant to the carrying out of work agreed by contract in accordance with the requirements of data security standard ISO 27001.
The primary objectives of this policy are to:
This policy is applicable to and will be communicated to all staff, systems, and processes in the Sicuro Group companies. This includes Sicuro Group LLC, Intelyse LLC and Graal FZE. Other Sicuro Group affiliated companies (Sicuro USA, Sicuro Holdings Limited, and Sicuro Logistics Services Ltd) are specifically excluded from the scope.
Sicuro Group data, for the purposes of this policy, is data owned, processed or held by Sicuro Group.
5.2 Legal & Regulatory Obligations
Sicuro Group has a responsibility to abide by and adhere to all current UAE legislation as well as a variety of regulatory and contractual requirements. A non-exhaustive summary of the legislation and regulatory and contractual obligations that contribute to the form and content of this policy is provided in Appendix A.
5.3 Information Classifications
The following provides a summary of the information classification levels that have been adopted by Sicuro Group.
5.4 Compliance Policy Awareness, and Disciplinary
Any security breach of Sicuro Groups information systems could lead to the possible loss of confidentiality, integrity, and availability of personal or other confidential data stored on these information systems. The loss or breach of confidentiality may result in criminal or civil action against Sicuro Group. The loss or breach of confidentiality of contractually assured information may result in the loss of business, financial penalties or criminal or civil action. All current staff and other authorized users will be informed of the existence of this policy and the availability of supporting policies.
5.5 Incident Handling
If a member of Sicuro Group is aware of an information security incident, then they must report it to the Information Security Manager.
5.6 Supporting Policy
Supporting policies have been developed to strengthen and reinforce this policy statement. These are published together and are available for viewing on the Sicuro Group shared network. All staff and any third parties authorized to access Sicuro Group’s network or computing facilities are required to familiarize themselves with these supporting documents and to adhere to them in the working environment.
Scott Wilcox – CEO
Article 378 of the Penal Code (Federal Law 3 of 1987)
Federal Decree Law No. 5 of 2012 on Combating Cybercrimes (Cybercrime Law)
Federal Law by Decree No. (3) of 2003 Regarding the Organisation of Telecommunications Sector (Telecommunications Law)
TRA Unsolicited Electronic Communications Policy
European Union’s GDPR
As of the 25th of May 2018, the EU General Data Protection Regulation (GDPR) aims to unify the rules and regulations around data across Europe. It aims to strengthen the rights of individuals when it comes to their personal data. GDPR requires organizations in and outside the EU to make additional changes to the way they treat their data. These new regulations are designed to ensure companies are processing and protecting the personal data of EU residents irrespective of where they operate.
Sicuro Group welcomes these changes as we fully believe that it will bring about a higher level of data awareness, security, and care. To ensure we provide the highest level of service to our clients and partners, Sicuro Group has many GDPR compliant practices already in place to comply with our ISO standards. This is a continuous and conscious effort to keep our clients’ interests at the forefront of how we operate.
To ensure these standards are maintained, Sicuro Group will:
We are committed to protecting your data. We are committed only using data when it is necessary and ethical to do so to improve our services and fulfill our contractual obligations. We aim to operate with honesty, with transparency, and in full compliance with GDPR.