Information Security Policy
The protection of information and the systems used to process it is of strategic importance to KLC Law Firm in achieving its short- and long-term objectives, while at the same time ensuring the confidentiality of the data of clients receiving its services.
Recognising the critical importance of information and information systems to the performance of its business operations, the Company implements an Information Security Policy aimed at:
- ensuring the confidentiality, integrity and availability of the information it manages
- ensuring the proper operation of information systems
- the timely handling of incidents that may jeopardise the Company’s business operations
- compliance with legal and regulatory requirements
- continuous improvement of the level of Information Security.
For this purpose:
- the organisational structures necessary for monitoring matters related to Information Security are established
- technical measures are defined to control and restrict access to information and information systems
- the classification of information is determined according to its importance and value
- the necessary actions for protecting information during its processing, storage and transmission are described
- methods for informing and training the Company’s employees and associates on Information Security matters are defined
- methods for handling Information Security incidents are defined
- methods for ensuring the secure continuity of the Company’s business operations in the event of information system malfunctions or disasters are described.
The Company performs risk assessments related to Information Security at regular intervals and takes the necessary measures to address them. It applies a framework for evaluating the effectiveness of Information Security processes, through which performance indicators are defined, the methodology for measuring them is described, and periodic reports are produced and reviewed by Management with the aim of continuously improving the system.
The Information Security Officer is responsible for controlling and monitoring the policies and procedures related to Information Security and for taking the necessary initiatives to eliminate all factors that may compromise the availability, integrity and confidentiality of the Company’s information.
All Company employees and associates with access to the Company’s information and information systems are responsible for complying with the rules of the applicable Information Security Policy.
The Company is committed to the continuous monitoring of and compliance with the regulatory and legislative framework, as well as to the ongoing implementation and improvement of the effectiveness of the Information Security Management System.
KLC Law Firm Management