1. Purpose
This policy sets out Murzo Group's approach to information security management in alignment with ISO/IEC 27001:2022, the ISO/IEC 27000 family, and recognised good practice for protecting information, systems, people, suppliers, clients, platforms, intellectual property, and operational assets.
It is intended to support confidentiality, integrity, availability, cyber resilience, privacy protection, supplier assurance, client trust, and proportionate security governance without implying ISO/IEC 27001 certification unless certification has been formally achieved and confirmed in writing.
2. Scope
This policy applies to Murzo Group, its subsidiaries, directors, workers, contractors, consultants, authorised users, suppliers, developers, hosting providers, technology partners, platform users, security providers, and third parties who access, process, store, transmit, support, host, secure, or manage Murzo Group information or systems.
It covers digital and physical information, client data, employee data, supplier data, financial information, intellectual property, source code, websites, domains, cloud services, devices, networks, email, messaging platforms, AI tools, payment systems, business records, CCTV material, product information, food safety information, cultural property information, property files, and confidential commercial information.
3. ISMS Approach
Murzo Group may use an information security management system approach to understand its security context, identify interested parties, define security scope, assess information security risks, select appropriate controls, review performance, and improve security arrangements over time.
The ISMS approach should be proportionate to Murzo Group's size, activities, risk profile, client expectations, legal obligations, supplier dependencies, technology use, and international operating environment.
4. Leadership and Accountability
Senior management is responsible for setting security expectations, approving security priorities, supporting suitable controls, and ensuring that security responsibilities are understood where relevant. Security is a shared responsibility across people, process, technology, supplier management, and physical operations.
- Security responsibilities should be assigned for systems, accounts, data, suppliers, incidents, change, access, and sensitive projects where relevant
- Security decisions should consider legal, contractual, operational, privacy, safety, continuity, intellectual property, and reputational risk
- People acting for Murzo Group must not bypass security controls, share credentials, ignore incidents, or use unapproved systems for sensitive information
5. Information Security Objectives
Murzo Group's information security objectives are to protect information from unauthorised access, loss, alteration, misuse, disclosure, destruction, unavailability, fraud, cyberattack, supplier failure, insider misuse, and unlawful processing.
Security objectives may include protecting client trust, preserving business continuity, supporting lawful processing, protecting intellectual property, improving access control, reducing supplier risk, improving incident response, securing development activity, and maintaining appropriate evidence of security decisions where needed.
6. Risk Assessment and Treatment
Information security risks should be considered before significant systems, suppliers, platforms, integrations, websites, payment tools, data transfers, AI tools, client services, cloud services, remote access, or sensitive projects are approved or changed.
Risk treatment may include avoiding the activity, reducing risk through controls, transferring risk through contract or insurance where suitable, accepting risk by an authorised person, or escalating the issue for further review.
7. Control Selection and Statement of Applicability
Where Murzo Group chooses to operate a formal ISO/IEC 27001-aligned ISMS, selected controls should be mapped to business risks and legal or contractual needs. A Statement of Applicability may be used where proportionate to show which controls are applicable, why they are selected or excluded, and how they are addressed.
Control selection should be practical, risk-based, and consistent with Murzo Group's Cybersecurity & Data Breach Policy, Security Assurance Framework, Data Protection Policy, Information Classification & Handling Policy, Access Control, Password & MFA Policy, Acceptable Use, BYOD & Remote Working Policy, Vulnerability Disclosure Policy, and Third-Party Software, Open Source & Digital Supply Chain Policy.
8. Information Classification and Asset Protection
Information assets should be handled according to sensitivity, value, legal status, business need, and harm that could arise from unauthorised access, alteration, loss, disclosure, or unavailability.
- Confidential, personal, security-sensitive, client, legal, financial, cultural property, high-value goods, food safety, source code, and strategic information require extra care
- Access should be limited to people and systems with a legitimate need
- Information should not be copied, uploaded, shared, printed, exported, or used in AI tools unless approved for the sensitivity of the material
9. Access Control and Identity Security
Access to Murzo Group systems and information must be authorised, limited, reviewed where appropriate, and removed when no longer needed. Privileged access should be restricted and used carefully.
Passwords, multi-factor authentication, administrator accounts, shared accounts, service accounts, API keys, encryption keys, recovery codes, and supplier access must be controlled in line with risk and business need.
10. Supplier and Digital Supply Chain Security
Technology suppliers, hosting providers, developers, software vendors, payment processors, AI services, analytics tools, agencies, contractors, and managed service providers may create material security risk. Supplier access, data handling, incident reporting, subcontracting, hosting location, confidentiality, resilience, exit, and support arrangements should be considered before use.
Murzo Group does not accept responsibility for unapproved supplier systems, shadow IT, personal accounts, unofficial file-sharing, unauthorised plugins, unapproved scripts, unsafe software, or third-party platform misuse outside approved arrangements, except where law requires otherwise.
11. Secure Change, Development and Operations
Material changes to websites, systems, domains, hosting, authentication, payment flows, APIs, databases, security settings, DNS, customer forms, code, integrations, backup arrangements, or production infrastructure should be controlled according to risk.
Development and operational activity should consider secure configuration, code quality, secrets handling, dependency risk, testing, backup, rollback, vulnerability management, logging, monitoring, and separation of sensitive environments where relevant.
12. Incident Management and Resilience
Suspected security incidents, data breaches, unauthorised access, malware, phishing, ransomware, lost devices, leaked credentials, supplier compromise, payment fraud, website compromise, vulnerability disclosure, or suspicious system behaviour must be escalated promptly.
Incident response may include containment, access suspension, password reset, forensic preservation, supplier contact, customer contact, authority notification, legal advice, insurance notification, communication control, recovery, and lessons learned where appropriate.
13. Awareness, Competence and Behaviour
People who handle Murzo Group information or systems should understand relevant security expectations for their role. Awareness may include phishing, passwords, MFA, device security, confidentiality, remote working, secure sharing, reporting incidents, privacy, supplier risk, social engineering, and handling sensitive information.
14. Certification and Public Claims
This policy supports alignment with ISO/IEC 27001:2022 but does not state or imply that Murzo Group is certified to ISO/IEC 27001. No person may claim Murzo Group is certified, accredited, audited, approved, compliant, or formally conforming to ISO/IEC 27001 unless a valid certification or written authorisation confirms the exact scope, issuing body, date, status, and permitted wording.
Any reference to ISO/IEC 27001 must be accurate, not misleading, and must not use ISO logos, certification marks, or accreditation marks without permission from the relevant rights holder or certification body.
15. Third-Party and Unauthorised Activity
Third parties must not present their own security controls, platforms, certifications, claims, audits, or systems as Murzo Group controls unless this has been approved in writing. Unauthorised testing, scanning, scraping, vulnerability exploitation, data extraction, monitoring, account access, or security research is not permitted except within approved boundaries.
To the fullest extent permitted by law, Murzo Group does not accept responsibility for security failures, data loss, unauthorised access, service disruption, customer harm, supplier failure, platform misuse, or security claims caused by third parties acting outside written approval.
16. Evidence and Review
Where information security risks, incidents, audits, supplier reviews, client assurance requests, certification discussions, legal obligations, or control decisions arise, Murzo Group may use proportionate evidence to assess the issue, support assurance, demonstrate decisions, improve controls, respond to authorities, or take legal steps where appropriate.
This policy should be reviewed periodically and when Murzo Group changes systems, suppliers, services, data processing, client commitments, cyber risk, ISO/IEC 27001 requirements, certification plans, or security operating arrangements.