Information Security Management System Policies

Last updated: 18/08/2026

IM4DIGITAL SRL (“we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (“GDPR”) and the Italian Privacy Code (D.lgs. 196/2003 as amended).


Commitment and Objectives of the Management System

The Top Management of IM4DIGITAL SRL establishes, implements, and supports this Management System Policy, recognizing it as a fundamental element for achieving the organization's strategic objectives and ensuring the success of its business. This policy is appropriately defined in relation to the organization's context and purpose, which consist of the "Design, development and delivery of on-premise and SaaS platforms", and fully supports the company's Mission and Vision, as analyzed in the document "Context Analysis".

The primary objective is to protect the company's information assets and the data entrusted to it by customers, ensuring their confidentiality, integrity, and availability. To this end, Top Management is committed to defining and periodically reviewing measurable information security objectives. This policy provides the framework for establishing such objectives, in alignment with the risk management process formalized in the "PRO Risk Management Procedure".

IM4DIGITAL SRL is committed to complying with all applicable requirements, including legal, regulatory, and contractual requirements relating to information security. Top Management is also committed to the continual improvement of the effectiveness of the Information Security Management System (ISMS), in accordance with the requirements of the ISO/IEC 27001 standard. This commitment is demonstrated through structured monitoring activities, internal audits, and periodic management reviews, as described in the procedures "PRO Measurement and Monitoring Procedure", "PRO Internal Audit Management", and "PRO Management Review Procedure".

This policy is maintained as documented information, in accordance with the "PRO Documented Information Management Procedure". The Management System Manager is responsible for ensuring that the policy is communicated, understood, and applied at all levels of the organization. Top Management ensures that the policy is made available to relevant interested parties, where appropriate. Specific responsibilities relating to information security are further detailed in the "POL Information Security Roles and Responsibilities Policy", and adherence to the principles established herein is a duty incumbent upon all personnel.


Information Security Objectives

IM4DIGITAL defines the following strategic information security objectives, in line with its business context, regulatory and contractual requirements, and the company's strategic direction. Achieving these objectives is a commitment of Top Management and a shared responsibility at all levels of the organization.

The Chief Executive Officer and the General Manager, with the support of the ICT Manager and the Management System Manager, shall ensure that the objectives are reviewed at least annually and updated based on the results of risk assessments, audit findings, and changes in the internal and external context.

The fundamental objectives are:

  • Confidentiality: Protect proprietary, customer, and personnel information from unauthorized access and disclosure. This includes intellectual property, source code, personal data, and any information classified as sensitive.
  • Integrity: Ensure the accuracy, completeness, and reliability of information and the systems that process it, preventing unauthorized or accidental modifications.
  • Availability: Ensure that information, systems, and services, particularly those delivered through SaaS solutions, are accessible and usable when required by authorized users, in accordance with Service Level Agreements (SLAs).
  • Regulatory and Contractual Compliance: Ensure full compliance with applicable laws, including regulations on the protection of personal data such as the GDPR, as well as with all contractual obligations entered into with customers and suppliers.
  • Risk Management: Identify, assess, and treat information security risks systematically, with the aim of reducing them to a level acceptable to the organization.
  • Operational Resilience: Maintain and improve the organization's ability to withstand and recover from security incidents or adverse events, as defined in the "PRO Business Continuity and Disaster Recovery Procedure".
  • Security Culture: Promote a security culture throughout the organization, ensuring that all personnel are aware of their responsibilities and adequately trained to perform their duties securely.

.