NITA is committed to protecting the confidentiality, integrity, and availability of the information it manages, and to maintaining an Information Security Management System (ISMS) aligned with the ISO/IEC 27001 international standard.
Our Commitment
Top management is fully committed to information security and provides the resources needed to build, maintain, and continually improve our ISMS. This commitment includes:
- Meeting all applicable legal, regulatory, and contractual information security requirements
- Continually improving our security processes and controls
- Working toward and maintaining ISO/IEC 27001 certification
- Regularly assessing and managing information security risks
- Ensuring staff receive the training and competencies needed to protect information effectively
Our Objectives
For the current financial year, NITA has set the following information security objectives:
- Raise organization-wide information security awareness
- Achieve full compliance with relevant information security laws and regulations
- Keep our security policies and procedures regularly reviewed and up to date
- Prioritize ongoing risk assessment across our operations
- Meet our stated information security targets
Governing Policies
This statement is supported by a suite of detailed internal policies covering areas such as acceptable use, access control, password management, secure development, anti-malware protection, change management, information classification, physical security, data retention and disposal, vulnerability management, and backup procedures.
Oversight
Our ISMS is overseen by a designated ISMS Manager, who reports to top management, and is subject to regular internal audits, management reviews, and external certification audits to ensure ongoing effectiveness.
Accountability
All employees, contractors, and stakeholders are expected to uphold this policy. Non-compliance may result in disciplinary action, in accordance with NITA's internal procedures.