Document Reference: P-ISP01 Dec 2025
Issue: 0 dated 19/12/2025
POLICY REVIEW RECORD
This Information Security Policy was first issued in this format in December 2025.
| Issue | Revision no. | Date | Details |
|---|---|---|---|
| 0 | 19/12/2025 | P-ISP01 Dec 2025 |
1. Purpose
The purpose of this policy is to safeguard the confidentiality, integrity, and availability of Sleaford Building Services Ltd’s information assets and systems. This policy establishes the framework for managing information security in line with the company’s legal, regulatory, and contractual obligations, particularly when undertaking work for sensitive clients such as the Ministry of Defence (MoD) and Ministry of Justice (MoJ).
2. Scope
This policy applies to:
- All employees, contractors, and temporary staff.
- All information assets, systems, and data owned, processed, or accessed by Sleaford Building Services Ltd.
- All offices, project sites, and remote working environments.
It encompasses all forms of information — electronic, verbal, and paper-based.
3. Objectives
- To protect client and company data against unauthorised access, disclosure, alteration, or destruction.
- To maintain compliance with applicable legislation and standards, including:
- UK GDPR and Data Protection Act 2018
- Official Secrets Act 1989 (where applicable)
- MoD Security Policy Framework (SPF) and MoJ supplier security requirements
- ISO/IEC 27001:2022 (as a guiding framework)
- To ensure staff understand their responsibilities in protecting information.
- To manage security incidents effectively and prevent recurrence.
4. Information Security Principles
Sleaford Building Services Ltd is committed to the following principles:
- Confidentiality: Information shall be accessible only to authorised individuals.
- Integrity: Information shall be accurate, complete, and protected from unauthorised modification.
- Availability: Information and systems shall be accessible to authorised users when required.
5. Roles and Responsibilities
5.1 Managing Director
- Has ultimate responsibility for ensuring effective information security management.
- Approves this policy and ensures adequate resources are provided.
5.2 Information Security Officer (ISO)
- Manages the day-to-day implementation of information security measures.
- Conducts risk assessments and security audits.
- Acts as the main point of contact for security incidents and client security queries.
5.3 Line Managers
- Ensure team compliance with security policies and procedures.
- Report any security breaches immediately.
5.4 All Employees and Contractors
- Must comply with this policy and related procedures.
- Must protect passwords, access credentials, and client information.
- Must immediately report any actual or suspected security incidents.
6. Information Classification
| Classification | Description | Example |
|---|---|---|
| Public | Suitable for public disclosure | Company brochures, website content |
| Internal | For internal business use only | Internal emails, process documents |
| Confidential | Restricted to authorised staff | Client data, project drawings, supplier contracts |
| Restricted | High-sensitivity data requiring enhanced controls | MoD or MoJ project documentation, security-cleared material |
Restricted and Confidential data must never be stored on unencrypted devices or transmitted over unsecured channels.
7. Access Control
- Access to systems and data shall be granted on a need-to-know and least-privilege basis.
- User accounts must be unique and protected by strong passwords or multi-factor authentication (MFA).
- Access rights shall be reviewed quarterly or upon role changes.
8. Data Protection and Privacy
Personal data shall be processed lawfully, fairly, and transparently under the UK GDPR and Data Protection Act 2018. All individuals whose personal data is processed by Sleaford Building Services Ltd have rights to access, rectification, and erasure in accordance with legislation.
9. Secure Working Practices
- Sensitive client data must only be accessed via company-managed, encrypted devices.
- Remote access shall use secure VPN connections.
- Portable media (USBs, drives) must be encrypted and authorised by management.
- Hard copy documents containing confidential information must be stored securely and shredded after use.
10. Physical Security
- Offices, stores, and project sites shall maintain access control (locks, ID badges, or access cards).
- Visitors must be escorted at all times.
- Equipment must not be left unattended in insecure environments.
11. Information Security Incident Management
All information security incidents (e.g., lost devices, data breaches, phishing attempts) must be reported immediately to the Information Security Officer.
An incident log shall be maintained, and corrective actions will be implemented promptly. Significant breaches involving personal data shall be reported to the Information Commissioner’s Office (ICO) within 72 hours, if required.
12. Supplier and Subcontractor Security
All subcontractors and suppliers handling client or company data must adhere to equivalent information security standards. Security clauses shall be included in all contracts, with periodic reviews of supplier compliance.
13. Training and Awareness
All staff shall receive information security training:
- Upon induction.
- Annually thereafter.
- Whenever new systems, regulations, or risks are introduced.
Training includes data handling, phishing awareness, and secure working practices.
14. Policy Compliance and Review
Non-compliance with this policy may result in disciplinary action, termination of employment, or legal proceedings. This policy shall be reviewed annually or following significant changes to legislation, technology, or company operations.
Date: 22nd December 2025
Next Review Date: 22nd December 2026