Xpress Payment Solutions Limited is committed to maintaining and improving information security, service management and business continuity processes by adopting an integrated management system. This provides a framework for integration of the ISO 27001:2013, ISO 20000:2018 and ISO 22301:2019.
- To ensure uninterrupted availability of all key business resources required to support essential (or critical) business activities.
- To reduce the number of information security, service and business continuity high priority risks on Xpress Payment Solution Limited's risk register.
- To provide for an orderly and expedited recovery/continuity of critical business processes after a disruptive incident.
- To reduce or avoid information security breaches and related loss.
- To Ensure Compliance with Xpress Payment Solution Limited's Contractual, Regulatory, and Legal requirements and reduce information security related regulatory sanctions/penalties.
- To ensure Information collected, held, and used by the organization is appropriately protected and available in line with business requirements.
- To improve information security culture and consciousness in the organization.
- To provide training in information security, service and business continuity for key resources
- Create awareness to all staff on the needs and responsibilities of Information Security, Service & Business Continuity Management.
- To ensure that the Confidentiality, Integrity and Availability of information is maintained throughout business functions and processes
- To ensure information is only accessible to authorized persons from within or outside the company and minimize damage by preventing and reducing the impact of security incidents
- To ensure that all employees are made aware of their individual obligations in respect of Service Delivery.
- Xpress Payments shall continually improve the effectiveness of the Business Continuity, Service continuity and Information Security Management Framework across all business units within scope.
The Integrated Management System policy, objectives and targets will be reviewed annually (or sooner if necessary) by Top Management. This policy statement is communicated to all employees and persons working for or on behalf of the company and will be made available to the public, stakeholders, and any other interested parties on request.