Information Security Policy

1. Our Commitment

Inzinc Consulting India Pvt. Ltd. (“Inzinc”, “we”, “our” or “us”) recognises that information is an important business asset and that protecting information entrusted to us is essential to maintaining the confidence of our clients, business partners and other interested parties.

We are committed to protecting information against unauthorised access, disclosure, alteration, loss, misuse or disruption and to maintaining appropriate safeguards for the confidentiality, integrity and availability of information.

This policy establishes our overall commitment to information security across our consulting, audit, training, digital and associated business activities.

2. Our Information Security Objectives

Our information security practices are intended to:

  • protect confidential, personal, proprietary and business-sensitive information;
  • ensure that information is accessible only to persons who have a legitimate business need and appropriate authorisation;
  • maintain the accuracy, completeness and integrity of information;
  • support the availability of information and systems required for business operations;
  • identify and manage information security risks in a proportionate manner;
  • prevent, detect and appropriately respond to information security incidents;
  • comply with applicable legal, regulatory, contractual and client requirements; and
  • continually improve our information security practices.

3. Protection of Client Information

Information received from clients is used only for legitimate business purposes connected with the services being provided or as otherwise authorised by the client.

Access to client information is limited based on business need. We take reasonable measures to prevent unauthorised access, sharing, copying, alteration or disclosure of such information.

Where information is provided to us under confidentiality, non-disclosure or contractual arrangements, it is handled in accordance with the applicable obligations.

Client information is not intentionally disclosed to third parties except where:

  • the client has authorised the disclosure;
  • disclosure is necessary for an agreed service;
  • an authorised service provider is involved under appropriate confidentiality or security obligations; or
  • disclosure is required by applicable law or a competent authority.

4. Access to Information and Systems

Access to information, applications and systems is provided according to legitimate business requirements.

Appropriate authentication and access-control measures are used to reduce the risk of unauthorised access. Access rights may be reviewed, modified or withdrawn when responsibilities change or when access is no longer required.

Users are expected to protect their authentication credentials and must not knowingly allow unauthorised persons to use their accounts or access company information.

5. Information Handling

Information is handled according to its nature, sensitivity and business importance.

Reasonable safeguards are applied when information is created, stored, processed, transmitted, shared, retained or disposed of.

Confidential or sensitive information is not knowingly shared through unauthorised channels or with persons who do not have a legitimate need to receive it.

6. Technology and Cybersecurity

We use appropriate technical and organisational measures to protect our information and technology environment.

These measures may include, as appropriate to the risk:

  • access controls and secure authentication;
  • endpoint and device protection;
  • software and security updates;
  • malware protection;
  • secure configuration;
  • backup and recovery arrangements;
  • encryption or other appropriate protection for sensitive information;
  • monitoring of relevant security events; and
  • controls over externally provided technology services.

Security measures are reviewed and adjusted where necessary based on changes in technology, identified risks and business requirements.

7. Remote Working and Mobile Devices

Where work is performed remotely or through mobile devices, personnel are expected to maintain the same level of care for company and client information as they would within a controlled office environment.

Appropriate precautions are taken to prevent unauthorised viewing, access, loss or disclosure of information while working remotely, travelling or using portable devices.

8. Cloud Services and Third-Party Providers

Where cloud services, software platforms or other external service providers are used, information security considerations form part of the selection and use of such services where relevant.

The level of assessment and control applied to a supplier is proportionate to the nature of the service and the information involved.

Third parties handling confidential or sensitive information on our behalf may be required to comply with applicable confidentiality, contractual, privacy or security obligations.

9. Information Security Incidents

Suspected or actual information security incidents are expected to be reported promptly through the appropriate internal channels.

Incidents are evaluated and managed according to their nature and potential impact. Where appropriate, actions may include containment, investigation, recovery, corrective action and communication with affected parties or relevant authorities.

Lessons arising from incidents are considered as part of our continual improvement activities.

10. Business Continuity and Information Availability

We recognise the importance of maintaining access to information and services necessary for our business operations.

Appropriate backup, recovery and continuity arrangements are maintained based on business needs and identified risks.

These arrangements are intended to support recovery from disruptions while protecting the confidentiality and integrity of information during restoration activities.

11. Awareness and Responsibilities

Information security is a shared responsibility.

Personnel and other authorised users are expected to:

  • comply with applicable information security requirements;
  • protect confidential and sensitive information;
  • use company information and systems responsibly;
  • follow applicable access and security controls;
  • promptly report suspected information security incidents or weaknesses; and
  • avoid activities that could compromise the security of information or systems.

Information security awareness is promoted as appropriate to individual roles and responsibilities.

12. Privacy and Personal Information

Personal information is handled with appropriate care and only for legitimate purposes.

Where personal information is collected or processed, reasonable measures are taken to protect it against unauthorised access, disclosure, alteration or loss and to meet applicable privacy and data-protection obligations.

Further information regarding personal information collected through our website may be provided in our Privacy Policy.

13. Risk-Based Approach

Information security risks are considered as part of our business and operational decision-making.

Security measures are selected having regard to factors such as:

  • sensitivity and importance of the information;
  • potential impact of loss, disclosure, alteration or unavailability;
  • contractual and legal obligations;
  • threat and vulnerability information;
  • technology involved; and
  • practical and proportionate risk-treatment requirements.

No technology environment can eliminate every security risk. Our objective is therefore to identify relevant risks and maintain reasonable and proportionate measures to manage them.

14. Continual Improvement

We periodically review our information security practices and make improvements where required based on changes in:

  • business activities;
  • technology;
  • information security threats;
  • applicable requirements;
  • client expectations;
  • incidents and lessons learned; and
  • identified risks and opportunities.

15. Policy Governance

Management is responsible for establishing the overall direction for information security and supporting the implementation of appropriate controls within the organisation.

This Information Security Policy is reviewed periodically and whenever significant changes affecting information security occur.

16. Contact

Questions or concerns regarding information security at Inzinc Consulting India Pvt. Ltd. may be communicated to us through our official contact channels.

Inzinc Consulting India Pvt. Ltd.
Website: www.inzincindia.com