Opticon Data Solutions S.r.l. is a company operating in the Legal Tech sector with the aim of supporting businesses in the digitization and compliance monitoring processes related to governance and data protection.
Given the nature of its business, Opticon Data Solutions considers information security a primary factor in protecting its information assets and a strategic asset that can easily be transformed into a competitive advantage.
The company pays particular attention to security issues throughout the design and development lifecycle of its services, which must be regarded as company assets.
The ISMS (Information Security Management System) applies to all activities related to the development of cloud-based solutions supporting governance and data protection, including the analysis, design, and production of tools, as well as the associated data stored within Opticon Data Solutions’ data centers.
Recognizing that its services for external parties may involve the handling of critical data and information, the technical organizational unit operates in accordance with internationally recognized security standards.
We consider it necessary to share this “Information Security Policy” with all suppliers, contractors, partners, and any parties external to Opticon Data Solutions who could have a significant impact on the security of the company’s information, in order to request and implement, where necessary, actions aimed at mitigating risks and enhancing the level of information security.
For these reasons, the necessary technical and organizational measures are adopted to best ensure the integrity, confidentiality, and availability of both internal information assets and those entrusted by its customers, including personal data.
On this basis, Opticon Data Solutions has decided to implement an Information Security Management System (ISMS) defined according to the rules and criteria set forth by “Best Practices” and relevant international standards, in accordance with the requirements of the international standard ISO/IEC 27001:2022.
The objective of Opticon Data Solutions’ Information Security Management System is to provide cloud services that support data protection governance and compliance, as well as to ensure an adequate level of data and information security in the design, development, and delivery of cloud services that support data protection governance and compliance through the identification, assessment, and management of the risks to which these services are subject.
Opticon Data Solutions’ Information Security Management System defines a set of organizational, technical, and procedural measures to ensure compliance with the following basic security requirements:
Furthermore, through this policy, Opticon Data Solutions intends to formalize the following objectives in the area of information security:
– to best preserve the company’s reputation as a reliable and competent provider;
– to best protect its own information assets and those of its customers;
– operate according to defined rules to maintain adequate security for the information managed by the company through its hardware and software systems;
– achieve continuous improvement of business processes, increasing the efficiency and added value of individual activities, through the ongoing maintenance of a dynamic Information Security Management System consistent with the business management model defined in the ISO/IEC 27001:2022 standard;
– to optimize the processes for delivering documentation resulting from client consulting services, in compliance with rules that ensure the proper management of data and information regarding clients and other stakeholders;
– to adopt measures designed to ensure employee retention and professionalism;
– to fully comply with the requirements of current and binding regulations;
– to increase its employees’ awareness and expertise regarding security issues;
– raise awareness among its suppliers, employees, and partners who may have an impact on information security;
– improve the security of the system implemented by Opticon Data Solutions S.r.l.
The SGSI applies to the provision of cloud services that support governance and compliance with data protection regulations, as well as to the data associated with them.
All information created or used by the company must be safeguarded and protected – in accordance with its assigned classification – from the moment of its creation, throughout its use, until its disposal. Information must be managed securely, accurately, and reliably, and must be readily available for authorized uses.
For the purposes of this document, “use of information” refers to any form of processing that utilizes electronic or paper-based media or that allows, in any form, for verbal communication.
With regard to consulting activities, this system requires – in accordance with the ISO/IEC 27001:2022 standard – that the Information Security Officer periodically conduct a risk analysis that takes into account the strategic objectives set forth in this policy, incidents that occurred during that period, and any strategic, business, and technological changes that have taken place; The purpose of the risk analysis is to assess the risk associated with each asset to be protected in relation to the identified threats.
Management collaborates with the Information Security Officer on the methodology to be used for risk assessment and approves the relevant document; in drafting the methodology, Management also participates in defining the rating scales to be used to assign values to the parameters that contribute to the risk assessment.
Following the completion of the risk analysis by the Information Security Manager and based on the methodology agreed upon with Management, Management evaluates the results, establishing the acceptable risk threshold, the risk mitigation measures to be taken for risks exceeding that threshold, and the residual risk following such mitigation. This analysis will also be weighted according to the business value of the individual assets to be protected and must clearly identify the actions to be taken, which will be classified according to a priority scale that aligns with corporate objectives, the available budget, and the need to maintain compliance with applicable regulations and laws.
This analysis must also be conducted in response to events that could alter the system’s overall risk profile.
All personnel who, in any capacity, work with the company are responsible for complying with this policy and for reporting any irregularities—even those not formally documented—of which they become aware.
Management and the appointed Information Security Management System Officer, with the support of the appointed internal DPO as needed, are responsible for setting objectives, ensuring clear direction aligned with corporate strategies, and providing visible support for security initiatives. They promote security by ensuring that individual security budgets are adequate and consistent with established corporate policies and strategic guidelines.
The Information Security Manager is responsible for designing the Information Security Management System and, in particular, for:
issue all necessary regulations, including document classification guidelines, to ensure that the company can conduct its operations securely;
adopt criteria and methodologies for risk analysis and management;
recommend organizational, procedural, and technological security measures to safeguard the security and business continuity of Opticon Data Solutions S.r.l.;
plan a specific and periodic training program on security for staff;
periodically assess the exposure of company services to major threats;
investigate security incidents and implement appropriate countermeasures;
promote a culture of information security;
where necessary, actively involve suppliers, contractors, and partners who may impact or interact with the Information Security Management System.
All external parties that have a relationship with Opticon Data Solutions must ensure compliance with the security requirements set forth in this security policy, including, where necessary, by signing specific confidentiality clauses or agreements.
This policy applies equally to all departments of the Company. Compliance with this policy is mandatory for all Opticon Data Solutions employees and contractors, and it must be incorporated into the terms of any agreements with external parties who, for any reason, may come into possession of information managed by the Company. Opticon Data Solutions permits the communication and dissemination of information to external parties only for the proper conduct of business activities, which must be carried out in compliance with applicable rules and regulations.
Opticon Data Solutions will periodically assess the effectiveness and efficiency of the Information Security Management System, ensuring adequate support for implementing the necessary improvements to enable a continuous process that monitors changes in external conditions or the company’s business objectives in order to ensure the system is properly adapted.
Introduction
This document expands upon and supplements the content and descriptions contained in the “Opticon Information Security Policy” document. It specifies how the management of Opticon Data Solutions S.r.l. is committed to implementing and improving its Management System in accordance with the requirements of the ISO/IEC 27001:2022 standard on Information Security.
This document therefore serves as a constant reference for all subsequent strategic choices and decisions deemed appropriate to the operational context. It is disseminated to all stakeholders through publication on the internal information system and, upon request, made available to other stakeholders, including through publication on the company’s website.
Company managers are familiar with and endorse the guidelines set forth by Management and in the policy documents; all staff are made aware that they operate within a Management System whose purpose is to implement the company’s documentation.
The entire structure of Opticon Data Solutions S.r.l. is oriented, through the commitment of Management, toward continuous improvement based on the achievement of the following objectives.
Cloud Service Provider (CSP)
Opticon Data Solutions S.r.l. operates as a Cloud Service Provider, delivering data management services via SaaS (Software as a Service) to facilitate regulatory compliance. In providing SaaS services, Opticon Data Solutions S.r.l.:
PII Processor
If necessary, and in any case within a maximum of 48 hours, Opticon Data Solutions S.r.l. intends to jointly determine which Party shall be responsible for reporting the data breach. The notification to the Data Protection Authority, as required by EU Regulation 2016/679—GDPR—must be submitted within 72 hours of becoming aware of the incident.
For further details regarding the technical and organizational measures adopted by Opticon Data Solutions S.r.l. to ensure the security of information and personal data within its proprietary cloud services, please refer to the “ISO 27017-27018 Technical Specifications.”
This document is subject to periodic revisions and updates in order to make corrections and additions and to ensure its adequacy and effectiveness, especially in the event of significant changes affecting information security, with a view toward continuous improvement.
In accordance with the principles of maximum transparency and collaboration, this appendix to the “Opticon Information Security Policy” is communicated to all employees and made available to interested parties as deemed necessary.
Milan, 24/10/24
The Management of Opticon Data Solutions Srl
Thank you for reviewing our information security policy. Transparency regarding data processing is an essential part of our approach to digital security.