“WACHANGA LTD’’ aims to provide all interested parties related to its operation with secure services and products of high quality, that conform to customers specific requirements and serve security objectives. To achieve this, the Management ensures that our vision, business objectives, Information Security Management System and services’ integrity, are all supported by a high level of human and technological resources. At the same time, we are dedicated to protecting the security of any non-public information we process, as well as to protecting the personal data and privacy of any data subject related to us.
Confidentiality, Integrity and Availability of the information is our high-level priority. The Information Security Management System we developed and continuously improve, serves the purpose of Secure, Reliable and Uninterrupted service delivery to customers and partners, and provides guidance on how to organise and process information by setting the desired level of security.
To achieve all the above, the Management
Adopted an Information Security Management System (ISMS) according to the International Standard ISO 27001:2022, which applies in all the activities and organisational units, respecting also the legal and institutional framework that applies in the industry of company’s operation.
Implements the process approach on administrative and technical level.
Periodically inspects, through specific roles, the ISMS, in order to ensure its effectiveness and to establish the necessary corrective actions when necessary. The company ensures that the ISMS is maintained and continuously improved through a program of audits and reviews.
Provides management direction and support for information security and personal data protection in accordance with business and contractual requirements, and the relevant laws and regulations.
Provides all the means and resources to train and motivate its employees, and to engage their participation in the continual improvement of the ISMS.
Evaluates the operational and technological risks, and assesses opportunities arising both from the internal and external environment, and which may affect company’s operation.
Selects and assesses its external providers and maintains mutually beneficial relationships.
Ensures that the policies of the ISMS are communicated, understood, implemented and maintained at all corporate levels.
Ensures the protection of the collected Personal Data according to the GDPR (EU 679/16) and the Security of any Information as provided by the ISMS Policies and Procedures ensuring the integrity, confidentiality and availability of the information and personal data, for the benefit of the business itself, its employees, customers and partners.
Established mechanisms to support timely and rapid identification, prevention of information security threats and effective response when such threats occur.
Protects the investment in information and communication technologies and raises awareness of the risks inherent in corporate information systems.
Sets measurable business objectives according to operational criteria. These measurable objectives are established, measured, analysed and reviewed to ensure the degree of achievement.
Adopting the principle of continuous improvement, the Management recognises and rewards teamwork and the individual effort, invests in people, respects the customer and is committed in the continuous monitoring of the operational risks, the achievement of the company’s objectives as well as the updating and communication of the current policy to any interested party, as it has been defined in the Information Security Management System.