Compliance & Security
Information Security Policy
Our commitment to information security and the protection of your data through ISO 27001:2013 compliance.
Introduction
The management of Novative is fully committed to the effective management of information security and the protection of confidentiality, integrity and availability of all information assets and related and supporting assets.
The company maintains an Information Security Management System (ISMS) based upon, and compliant with, the ISO 27001:2013 Information Security Management Systems standard.
Scope
This policy applies to all information assets and business activities and to all employees, consultants, associates and third parties.
Information Security Objectives
The security in terms of confidentiality, integrity and availability of information are recognised as critical to the operation and administration of Novative and to the ongoing growth of the company.
Novative has developed the following high-level information security objectives aligned with business objectives:
- Provide assurance to all stakeholders / Interested parties that information assets are adequately protected by maintaining the ISMS and ISO 27001:2013 certification.
- Manage risk efficiently and continuously.
- Protect the company, our customers, employees and third parties against information security threats.
- Ensure compliance to all applicable regulatory, legal and contractual requirements including the GDPR and all applicable data protection legislation.
It is the policy of the company that we will:
- Secure information based on the three founding principles of Information Security Confidentiality, Integrity and Availability.
- Ensure that information is accessible only to those authorised to have access i.e. on “Need to know basis.”
- Promote a culture of information security across the company and ensure that all employees are fully aware of their responsibilities.
- Maintain proactive and effective risk management and associated controls in order to minimise the risks of security incidents and breaches.
- Continually improve the management of information security.
- Apply appropriate due diligence in relation to information governance and security in all aspects of the business.
Reporting Security Incidents
All employees, contractors, temporaries are responsible for immediately reporting any suspected security incidents to the information security officer through email at security@novative.com.
Responsibilities
- It is the responsibility of the CEO to maintain and review this policy.
- It is the responsibility of all employees to be aware of and comply with this policy and all associated ISMS policies and procedures.
- Any non-compliance with this policy may be subject to disciplinary procedures.
- It is the responsibility of the Information security officer to review this policy and ensure that it is published to all employees.
Review
This policy is reviewed at least annually as part of management review and in response to organisational, legislative/regulatory or contractual changes or security incidents/breaches as appropriate.
On this page
Jump to a section of our Information Security Policy.
Contact
Questions concerning our Information Security Policy? Reach our team at info@novative.com or call +41 22 365 65 45 (Switzerland Head Office).
Ready to Transform Your HR & Payroll Operations?
Join hundreds of enterprises worldwide that trust Novative to expertly manage their HR and payroll processes.