Organisational roles and responsibilities are defined and documented, with an accountable executive owner, ensuring appropriate resource is allocated to align to the Group’s strategic direction. The ISMS is centrally managed by a dedicated team of Compliance, Internal Audit, Information Security, and Cyber Security professionals.
Information Security risks are captured as part of a risk management framework based upon the defined scope and criteria of the ISMS. Internal objectives are set and monitored on a regular basis with senior stakeholders.
An overarching Information Security policy is in place with Executive Statement. Primary policies are mandatory for all staff and a secondary policy set is categorised based on relevance to certain areas of the business e.g., IT Software Development. All staff can access these on our internal Intranet site and training is provided on an annual basis within our Learning Management System.
All information is processed through the Group’s Data Classification guidelines, with appropriate controls assigned for Confidential, Private and Public data. An inventory of assets and systems is in place, with ownership assigned to relevant management.
An incident reporting policy and procedure is also in place, with an easy reporting mechanism for staff to report events or incidents. Incidents are logged and handled by internal Information Security and Cyber teams. A breach reporting procedure is documented and captured as part of the organisation’s Business Continuity Planning. Plans are reviewed and tested regularly (at least annually). Lessons learned are documented and cascaded.
Security risk assessments are conducted for suppliers based on their interaction with Radius systems and data. Contracts, agreements, and NDAs are implemented in line with a formal Supplier Management Policy.
All relevant legislation and regulatory requirements have been identified and reviewed, with ongoing horizon scanning. A Data Protection Officer has been assigned to ensure compliance with Data Privacy legislation that Radius operates under its jurisdictions. Impact assessments are conducted for any major changes to processing activities to ensure continued compliance.