Information Security Policy

Date issued: July 2024
Version: 14
Owner: Head of IT

Why do we need this policy?

Information, and the information technology (IT) and communications facilities that support it, are critically important business assets. Their availability, integrity and confidentiality are vital to Business Stream’s effective operation.

Business Stream is committed to using and maintaining good information security practices by:

  • Making sure we comply with all IT and security-related laws.
  • Ensuring our IT assets, such as hardware, software, infrastructure and data, are protected against security threats.
  • Creating and maintaining awareness of the need to secure these assets as part of our everyday work.
  • Establishing an effective Business Stream Information Security Policy.

All authorised personnel, including employees, contractors, secondees, consultants, and agency staff, are granted access to the necessary IT and communication facilities for effective job performance. Third-party service providers are granted access to fulfil contractual obligations. Users directly impact the availability, integrity, and confidentiality of Business Stream's information and systems, and are accountable for actions logged under their username.

Using IT improperly could have adverse consequences for Business Stream, third party service providers and the individuals who use these systems. Information security is everyone’s responsibility. As a responsible organisation, Business Stream regularly monitors the use of the information technology and communications facilities to ensure that the Information Security Policy is being adhered to.

What this policy covers

The use of Business Stream's information technology and communication facilities.