Information Security Management System (ISMS) Policy
Our Commitment to Information Security
Simply AVS is committed to protecting the confidentiality, integrity, and availability of all information we handle in the delivery of our audio visual design, installation, and support services.
We recognise the importance of strong information security practices in safeguarding client data, project information, internal systems, and supply chain communications. Our approach is aligned with recognised best practice for Information Security Management Systems (ISMS), including principles from ISO/IEC 27001.
Purpose of This Policy
This ISMS Policy defines how Simply AVS manages information security across our business operations and projects.
It provides the framework for:
- Protecting sensitive and confidential information
- Managing information security risks
- Ensuring compliance with legal, contractual, and regulatory requirements
- Supporting secure delivery of AV solutions and services
- Promoting continual improvement in security practices
Scope
This policy applies to all employees, contractors, suppliers, and partners working with Simply AVS, including:
- Office-based operations
- On-site installation and commissioning activities
- Remote and hybrid working environments
- Cloud-based systems and digital platforms
- Client project documentation and communications
It covers all information assets including digital, physical, and verbal information.
Information Security Principles
Simply AVS operates according to the following core principles:
- Confidentiality – Information is accessible only to those authorised to use it
- Integrity – Information is accurate, complete, and protected from unauthorised modification
- Availability – Information and systems are available when required for business operations
Risk Management Approach
We adopt a risk-based approach to information security, identifying potential threats and implementing appropriate controls to reduce risk to an acceptable level.
This includes:
- Assessing risks to information assets
- Implementing proportionate security controls
- Reviewing risks regularly or when changes occur
- Improving controls as part of continuous improvement
Roles and Responsibilities
Information security is a shared responsibility across the organisation.
- Management is responsible for leadership, oversight, and approval of the ISMS
- Employees and contractors are responsible for following security procedures and reporting incidents
- IT and technical teams are responsible for implementing and maintaining secure systems
- Suppliers and partners are expected to follow appropriate security standards when handling information on our behalf
Access Control
Access to systems, data, and client information is granted on a need-to-know basis.
We ensure that:
- User access is controlled and regularly reviewed
- Strong authentication methods are used where appropriate
- Access is removed when no longer required
- Sensitive information is protected from unauthorised access
Data Handling & Protection
We take appropriate steps to protect all information throughout its lifecycle, including:
- Secure storage of digital and physical data
- Controlled sharing of project and client information
- Secure disposal of unnecessary or outdated information
- Use of approved systems for communication and file sharing
Incident Management
We maintain procedures for identifying, reporting, and responding to information security incidents.
This includes:
- Prompt reporting of suspected security incidents
- Investigation and containment of incidents
- Root cause analysis where appropriate
- Implementation of corrective actions
- Continuous improvement to prevent recurrence
Supplier & Third-Party Security
We work with trusted suppliers and partners and expect them to maintain appropriate security standards.
Where necessary, we:
- Assess supplier security practices
- Apply contractual security requirements
- Limit access to only required information
- Monitor third-party performance and compliance
Compliance & Legal Requirements
Simply AVS complies with applicable legal, regulatory, and contractual obligations relating to information security, including data protection requirements under UK GDPR.
We ensure that security practices are aligned with client expectations and industry standards.
Awareness & Training
We promote information security awareness across the organisation through:
- Staff onboarding and induction
- Ongoing training and guidance
- Clear communication of policies and procedures
- Encouraging a security-conscious culture
Continual Improvement
We are committed to continually improving our information security management system by:
- Reviewing policies and procedures regularly
- Learning from incidents and near misses
- Updating controls in response to changes in technology and risk
- Strengthening security practices over time
Responsibility for This Policy
This policy is approved by the management of Simply AVS and is reviewed periodically to ensure it remains effective, relevant, and aligned with business needs.
Conclusion
Simply AVS is committed to maintaining a robust and practical approach to information security across all areas of our business. This ISMS Policy underpins how we protect information, manage risk, and deliver secure, reliable AV solutions to our clients.