INFORMATION SECURITY POLICY
Gemeric Consulting Limited Liability Company
Identifier: IT-P-001
Page: 1 / 2
Edition: 2024.09.02.
Version: 1.0
INFORMATION SECURITY POLICY
The objective of Gemeric Consulting Ltd. is to protect its data and information for the sake of both material and moral security, and to earn and maintain the trust of customers and other stakeholders. To this end, the company has implemented and maintains an Information Security Management System (ISMS) covering the following activities and processes:
Software development, operation, and logistic supply chain administration.
Physical Protection
Gemeric Consulting Ltd. places great emphasis on the physical protection of data and assets. This includes ensuring the appropriate security of buildings, servers, and other equipment.
Information Protection Considerations
Information protection aspects are taken into account throughout all processes. The security of data is considered a matter of utmost importance.
Employee Awareness
Our goal is to make all employees aware of the importance of confidentiality, integrity, and authenticity of the information they handle.
External Service Provider Requirements
External service providers are expected to comply with the security principles and policies prescribed by Gemeric Consulting Ltd.
Information Security Management System
Gemeric Consulting Ltd. has implemented its Information Security Management System in accordance with the MSZ ISO/IEC 27001:2023 standard. Its aim is to ensure compliance with applicable legal requirements, the adopted information security standard, and the expectations of our clients.
Basic Requirements
The purpose of the ISMS is to ensure the continuity of processes and prevent unauthorized persons from accessing confidential information.
Risk Management
We review current threats, assess and evaluate risks annually, and take appropriate measures to reduce any unacceptable risks.
To reduce the risks of data loss or data theft, we perform regular data backups, apply encryption measures, and enforce access controls. To prevent unauthorized access, all employees are required to use strong passwords. Firewalls and intrusion detection systems are in place and monitored continuously. To avoid malware infections, antivirus software and regular system updates are applied.
The management of Gemeric Consulting Ltd. places particular importance on the operation and continuous improvement of the ISMS. It expects and requires all employees, external partners, and any other parties who have access to the organization’s information or systems to comply with its policies and applicable regulations.
The organization’s management also takes into account the effects of climate change when operating and continuously improving the ISMS, including the selection of external service providers.
This policy applies to all employees, external partners, and any other parties who have access to the organization’s information or systems.
Budapest, 2024.09.02.
Viktória Kökény
Company director

