Policy Statement
The Board and Management of Paylode Services Limited, the company behind Payonus, which operates in the Information Technology sector, are committed to preserving the confidentiality, integrity and availability of all physical and electronic information assets throughout the organization, in order to preserve its asset, legal, regulatory as well as contractual, compliance and image. The Information Security Management Systems (ISO 27001) requirements will continue to be aligned with organizational goals and is also intended to be an enabling mechanism for information sharing, electronic operations, and reducing information & technology-related risks to acceptable levels.
Payonus is committed to providing quality services to our customers, both internal and external, by aligning Information Technology investments with organizational goals. Payonus has aligned its processes and operations to the requirements of the ISO 27001:2022 standard to ensure cyber resilience, protection of its information assets and maximization of benefit/returns on IT investments.
Our Commitments
It is therefore Payonus's policy to ensure:
- Payonus's current strategy and Information Security Management Systems (ISMS) provide the context for identifying, assessing, evaluating and controlling information/process-related risks through the establishment and maintenance of the ISMS. The risk assessment and risk treatment plan capture how identified risks are controlled in alignment with Payonus's risk management strategy.
- Information security education, awareness and training are made available to all stakeholders.
- All employees of Paylode Services Limited working on Payonus, and external parties identified in the Management Systems, are expected to comply with this policy.
- The ISMS shall be subject to continuous and systematic review with improvements adopted where necessary.
- Management is committed to the continual improvement of the ISMS in the organization.
- Breach of the policy or security mechanism may warrant disciplinary measures, up to and including termination of contract, as well as legal action in line with the Cybercrime Prohibition Act 2015.