1.    Introduction

Computer Information Systems – CIS Group is a major player in the distribution and integration of solutions and products and services of the ICT Market. CIS Group operates in Africa, the Middle East and Europe since 1979 with a network of 46 branches in 30 countries.

CIS Group provides complete services to the customers through all the project lifecycle:

  • Consulting for the development of ICT strategic roadmap as well as implementation of complex solutions and after sales support.
  • Consultative Services ranging from the development of ICT strategic Roadmaps.
  • Efficient logistics for timely delivery of hardware from a wide range of sources to a wide range of destinations.
  • Implementation and after-sales services for the provisioning, installation, integration of comprehensive hardware configurations, middleware & vertical solutions.
  • Solution fine-tuning, user trainings and after-sales support.

2.  Objective

The purpose of the Information Security & Privacy Policy is to establish an organization-wide framework that:

  • Is appropriate to the context of CIS Group.
  • Standardizes the setting up of security controls and information gathering processes to protect CIS Group digital & physical assets and to provide secure communication channels with its partners and customers.
  • Guarantees the availability of the means to implement key initiatives.
  • Commits to keep improving on the information security & privacy management system (Information Management Systemsmentioned frameworks through continuous improvement, updating and capacity planning. 
  • Commits to keep expanding the breadth on the information security management system (Information Management Systemsto utilize & develop Corporate Governance GDPR, POPIA, CSA STAR, NIST, OWASP, SECAM & PCI/DSS in our Records, Policies & Procedures.  
  • Ensures compliance with applicable requirements & Frameworks including:
ISO 27001

Scope

This Policy is applicable to CIS Group and will be communicated within the organization to all the employees and externally to CIS Group customers, suppliers, and other stakeholders as appropriate. 

Policy Review

This Policy is reviewed by the ISPMS Committee at least once a year in accordance with evolving security & privacy threats. 

Policy Statement

We at CIS Group, are committed to creating and maintaining an environment that: 

  • Protects our information resources from accidental or intentional unauthorized use, modification, disclosure, or destruction.
  • Ensures the detection, prevention, response to, and investigation of cybercrime incidents and misuse of CIS Group information technology assets.
  • Prevents our channels of communication with our partners and customers from being the targets of cyberattacks.
  • Guarantees the operational resiliency for optimal business continuity.

Protecting What Matters: Data, Privacy, and Trust: 

  • Provide a framework for establishing suitable levels of information security, privacy  and information resources critical to the provisioning of ICT Integrated Solutions and Services
  • Mitigate the risks associated with theft, loss, misuse, damage, or abuse of CIS Group systems.
  • Make sure that users are aware of and comply with all current and applicable legal and other requirements including regulatory or contractual, intellectual property rights and personal data protection. 
  • Ensure all customer data, and their privacy, shall be protected in accordance with applicable industry, regulatory and legislative directives in force. 
  • Protect confidential and personal data related to our suppliers, partners, and customers.  
  • All customers shall be subject to verification of the identity as per the prevalent KYC norms provided by the regulator as a key mitigation against fraudulent activities. 
  • Respond to security and privacy related feedback and updates appropriately and efficiently. 
  • Protect the personal information and privacy of employees.  
  • Reinforce the reputation of CIS Group as an institution deserving of public trust.