Legal / Legal
IMS Policy Statement
1 min read
Policy Statement
- FOREN’s current strategy and Integrated Management System provides the context for identifying, assessing, evaluating and controlling information/process/service-related risks through establishment and maintenance of the IMS. The risk assessment and risk treatment plan capture how identified risks are controlled in alignment with FOREN’s risk management strategy.
- In particular, business continuity and contingency plans, data backup procedures, access control to systems and information security incident reporting are fundamental to this policy. All employees of FOREN shall have the responsibility of reporting incidents.
- All employees of FOREN and external parties identified in the IMS are expected to comply with this policy. All staff and certain external parties will receive or be required to provide appropriate training.
- FOREN is committed to aligning its processes, operations to IMS standards to ensure cyber resilience and the protection of its information asset
- The IMS is subject to continuous and systematic review with improvements, where necessary. The Head of Technology is the owner of this document and is responsible for ensuring that this policy document is reviewed and approved by the Executive Management at least annually and in the event of relevant changes and/or incidents.
- A current version of this document is available to all members of staff on the shared drive (IMS Project). This policy is issued on a version-controlled basis under the signature of the CEO, FOREN.
- Breach of the policy or security mechanism may warrant disciplinary measures, up to and including termination of employment/contract as well as legal action in line with the Cybercrime Prohibition Act 2015.

