Commitment of EOS KSI Slovensko
Introduction
As one of the most significant companies in the field of receivables management, EOS KSI Slovensko is aware of the importance of protecting the information it processes. The company places particularly great emphasis on information security and has therefore decided to implement an information security management system as defined by the ISO 27001 standard in its relations with employees, clients, and contractual partners.
EOS KSI Slovensko defines information security as the protection of physical and electronic information, as well as the systems necessary for processing information, with regard to their confidentiality, integrity, and availability.
1 Company Management Declaration
The management of EOS KSI Slovensko has adopted an information security policy as part of its corporate strategy. The company's management supports the goals and principles of information security in line with the business strategy and business objectives. By establishing an Information Security Management System (ISMS) and providing the necessary resources, it enables the achievement of this system's goals. As the highest authority of the ISMS, the management actively contributes to its success.
2 Context of the Organisation
EOS KSI Slovensko is part of the multinational EOS Group, which is an international leader in receivables management, with more than 6,000 employees in over 20 countries. Data processing is the foundation of the EOS Group's business, which is why the issue of its security is an important topic across all its companies. Several dozen employees within the EOS Group are dedicated to the areas of data protection and information security.
3 Interested Parties
Various interested parties place requirements on the ISMS of EOS KSI Slovensko.
3.1 Contractual Partners (Clients, Suppliers)
Contractual partners expect the trustworthy processing of their data, but above all, the smooth operation and thus the availability of services.
3.2 Internal Parties (Employees)
Company employees expect functioning services that are available at any time during specified working hours. System downtimes should be as short as possible and should under no circumstances occur unplanned. Security should be a support in the background and, where possible, should not affect or complicate work. High demands are also placed on data confidentiality.
3.3 Shareholders (Company Management, Owners)
Shareholders expect protection against economic and legal risks, as well as risks related to damage to the company's reputation. Certification of the implemented ISMS represents a competitive advantage in the industry.
3.4 Regulatory Authorities
Regulatory authorities expect all legal and standard requirements to be met. All transmitted information must reach the regulatory authorities on time, in the correct and complete form.
4 Objectives
The strategic objectives of the ISMS defined below are supported by operational objectives that are evaluated annually.
4.1 Protection of Company Assets
- Protection of information confidentiality
- Prevention of unplanned downtimes of key systems and services
- Prevention of financial damages caused by cybercrime
4.2 Compliance with Information Security and Personal Data Protection Standards
- To provide third parties with proof of the highest level of information security by creating an ISMS and establishing security measures according to the ISO/IEC 27001 standard, as well as through external certification.
4.3 Continuous Development
- Raising staff awareness
- Continuous improvement of the ISMS and security measures