Information Security Statement
Information Security Policy
Falsum Group Limited (“Falsum”) and its Subsidiary Companies
1.0 Policy Objective
1.1. The objective of this policy is to protect the information assets that Falsum and its subsidiary companies handle, store, exchange, process, or access. It aims to ensure the ongoing maintenance of the confidentiality, integrity, and availability of these assets.
1.2. To implement controls that provide appropriate protection for information assets, proportionate to their value and the threats they face.
1.3. To ensure Falsum complies with all relevant legal, customer, and third-party requirements relating to information security.
1.4. To continually enhance the organisation’s Information Security Management System (ISMS) and its capability to withstand threats that could potentially compromise information security.
2.0 Scope
2.1. This policy and its sub-policies apply to all individuals, processes, services, technology, and assets specified within the Scope. It also applies to all employees and subcontractors of information security-critical suppliers who access or process any of the organisation’s information assets.
3.0 Core Policy
3.1. Falsum recognises that, despite existing threats to information security, most security incidents can be prevented.
3.2. The Director, Sam Ballard-Robinson, is committed to achieving the objectives outlined in this policy through the following measures:
3.2.1. Falsum demonstrates the effectiveness of the ISMS by conformance with certification to the international standard ISO 27001:2017.;
3.2.2. The systematic identification of security threats and the application of a risk assessment procedure to identify and implement appropriate control measures;
3.2.3. Regular monitoring of security threats and testing/auditing the effectiveness of control measures;
3.2.4. The maintenance of a risk treatment plan focused on eliminating or reducing security threats;
3.2.5. The development and regular testing of a Business Continuity Plan;
3.2.6. The clear definition of responsibilities for implementing the ISMS;
3.2.7. The provision of appropriate information, instruction, and training to ensure all employees are aware of their responsibilities and legal duties, and can support the implementation of the ISMS;
3.2.8. The implementation and maintenance of the sub-policies outlined in this policy.
3.3. The suitability and effectiveness of this policy and the methods identified within it for achieving the organisation’s commitments will be regularly reviewed by the Director and senior management.
3.4. The implementation of this policy, along with its supporting sub-policies and procedures, is crucial to the success of Falsum’s business. All employees and contractors who impact information security must support this as an integral part of their daily responsibilities.
3.5. All information security incidents must be reported to the Head of Technical Solutions. Violations of this policy may result in action under the organisation’s Disciplinary and Appeals Policy and Procedure.
Signed on behalf of the Directors:
Position: Director
Date: 01-Jan-2024
For further information, please contact us via one of our preferred methods:
Email: legal@falsum.co.uk
Phone: +44 (0) 20 7735 2455
Moving food across a border?
Tell us the product and the route. We'll tell you exactly what you need.