{"id":1469,"date":"2026-08-18T15:12:08","date_gmt":"2026-08-18T13:12:08","guid":{"rendered":"https:\/\/im4digital.com\/IT\/?page_id=1469"},"modified":"2026-08-18T15:16:12","modified_gmt":"2026-08-18T13:16:12","slug":"politiche-sistema-di-gestione","status":"publish","type":"page","link":"https:\/\/im4digital.com\/IT\/politiche-sistema-di-gestione\/","title":{"rendered":"Politiche Sistema di gestione"},"content":{"rendered":"<div class=\"et_pb_section_0 et_pb_section et_section_regular et_flex_section\">\n<div class=\"et_pb_row_0 et_pb_row et_flex_row\">\n<div class=\"et_pb_column_0 et_pb_column et-last-child et_flex_column et_pb_css_mix_blend_mode_passthrough et_flex_column_24_24 et_flex_column_24_24_tablet et_flex_column_24_24_phone\">\n<div class=\"et_pb_text_0 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module preset--module--divi-text--default\"><div class=\"et_pb_text_inner\"><p data-start=\"0\" data-end=\"16\"><strong>Information Security Management System Policies<\/strong><\/p>\n<p data-start=\"18\" data-end=\"44\">Last updated: 18\/08\/2026<\/p>\n<p data-start=\"46\" data-end=\"267\">IM4DIGITAL SRL (\u201cwe,\u201d \u201cus,\u201d or \u201cour\u201d) respects your privacy and is committed to protecting your personal data in accordance with Regulation (EU) 2016\/679 (\u201cGDPR\u201d) and the Italian Privacy Code (D.lgs. 196\/2003 as amended).<\/p>\n<hr data-start=\"269\" data-end=\"272\" \/>\n<h3 data-start=\"274\" data-end=\"298\">Commitment and Objectives of the Management System<\/h3>\n<p data-start=\"56\" data-end=\"588\" class=\"PDq2pG_selectionAnchorContainer\">The Top Management of IM4DIGITAL SRL establishes, implements, and supports this Management System Policy, recognizing it as a fundamental element for achieving the organization's strategic objectives and ensuring the success of its business. This policy is appropriately defined in relation to the organization's context and purpose, which consist of the <strong data-start=\"411\" data-end=\"482\">\"Design, development and delivery of on-premise and SaaS platforms\"<\/strong>, and fully supports the company's Mission and Vision, as analyzed in the document <strong data-start=\"565\" data-end=\"587\">\"Context Analysis\"<\/strong>.<span aria-hidden=\"true\" class=\"PDq2pG_selectionAnchor\"><\/span><\/p>\n<p data-start=\"590\" data-end=\"1056\">The primary objective is to protect the company's information assets and the data entrusted to it by customers, ensuring their confidentiality, integrity, and availability. To this end, Top Management is committed to defining and periodically reviewing measurable information security objectives. This policy provides the framework for establishing such objectives, in alignment with the risk management process formalized in the <strong data-start=\"1020\" data-end=\"1055\">\"PRO Risk Management Procedure\"<\/strong>.<\/p>\n<p data-start=\"1058\" data-end=\"1715\">IM4DIGITAL SRL is committed to complying with all applicable requirements, including legal, regulatory, and contractual requirements relating to information security. Top Management is also committed to the continual improvement of the effectiveness of the <strong data-start=\"1315\" data-end=\"1364\">Information Security Management System (ISMS)<\/strong>, in accordance with the requirements of the ISO\/IEC 27001 standard. This commitment is demonstrated through structured monitoring activities, internal audits, and periodic management reviews, as described in the procedures <strong data-start=\"1588\" data-end=\"1634\">\"PRO Measurement and Monitoring Procedure\"<\/strong>, <strong data-start=\"1636\" data-end=\"1671\">\"PRO Internal Audit Management\"<\/strong>, and <strong data-start=\"1677\" data-end=\"1714\">\"PRO Management Review Procedure\"<\/strong>.<\/p>\n<p data-start=\"1717\" data-end=\"2349\" data-is-last-node=\"\" data-is-only-node=\"\">This policy is maintained as documented information, in accordance with the <strong data-start=\"1793\" data-end=\"1846\">\"PRO Documented Information Management Procedure\"<\/strong>. The Management System Manager is responsible for ensuring that the policy is communicated, understood, and applied at all levels of the organization. Top Management ensures that the policy is made available to relevant interested parties, where appropriate. Specific responsibilities relating to information security are further detailed in the <strong data-start=\"2193\" data-end=\"2257\">\"POL Information Security Roles and Responsibilities Policy\"<\/strong>, and adherence to the principles established herein is a duty incumbent upon all personnel.<\/p>\n<hr data-start=\"791\" data-end=\"794\" \/>\n<h3 data-start=\"796\" data-end=\"841\">Information Security Objectives<\/h3>\n<p data-start=\"37\" data-end=\"351\" class=\"PDq2pG_selectionAnchorContainer\">IM4DIGITAL defines the following strategic information security objectives, in line with its business context, regulatory and contractual requirements, and the company's strategic direction. Achieving these objectives is a commitment of Top Management and a shared responsibility at all levels of the organization.<span aria-hidden=\"true\" class=\"PDq2pG_selectionAnchor\"><\/span><\/p>\n<p data-start=\"353\" data-end=\"660\">The Chief Executive Officer and the General Manager, with the support of the ICT Manager and the Management System Manager, shall ensure that the objectives are reviewed at least annually and updated based on the results of risk assessments, audit findings, and changes in the internal and external context.<\/p>\n<p data-start=\"662\" data-end=\"693\">The fundamental objectives are:<\/p>\n<ul data-start=\"695\" data-end=\"2181\" data-is-last-node=\"\" data-is-only-node=\"\">\n<li data-start=\"695\" data-end=\"925\"><strong data-start=\"697\" data-end=\"717\">Confidentiality:<\/strong> Protect proprietary, customer, and personnel information from unauthorized access and disclosure. This includes intellectual property, source code, personal data, and any information classified as sensitive.<\/li>\n<li data-start=\"927\" data-end=\"1095\"><strong data-start=\"929\" data-end=\"943\">Integrity:<\/strong> Ensure the accuracy, completeness, and reliability of information and the systems that process it, preventing unauthorized or accidental modifications.<\/li>\n<li data-start=\"1097\" data-end=\"1330\"><strong data-start=\"1099\" data-end=\"1116\">Availability:<\/strong> Ensure that information, systems, and services, particularly those delivered through SaaS solutions, are accessible and usable when required by authorized users, in accordance with Service Level Agreements (SLAs).<\/li>\n<li data-start=\"1332\" data-end=\"1583\"><strong data-start=\"1334\" data-end=\"1376\">Regulatory and Contractual Compliance:<\/strong> Ensure full compliance with applicable laws, including regulations on the protection of personal data such as the GDPR, as well as with all contractual obligations entered into with customers and suppliers.<\/li>\n<li data-start=\"1585\" data-end=\"1751\"><strong data-start=\"1587\" data-end=\"1607\">Risk Management:<\/strong> Identify, assess, and treat information security risks systematically, with the aim of reducing them to a level acceptable to the organization.<\/li>\n<li data-start=\"1753\" data-end=\"1979\"><strong data-start=\"1755\" data-end=\"1782\">Operational Resilience:<\/strong> Maintain and improve the organization's ability to withstand and recover from security incidents or adverse events, as defined in the <strong data-start=\"1917\" data-end=\"1978\">\"PRO Business Continuity and Disaster Recovery Procedure\"<\/strong>.<\/li>\n<li data-start=\"1981\" data-end=\"2181\" data-is-last-node=\"\"><strong data-start=\"1983\" data-end=\"2004\">Security Culture:<\/strong> Promote a security culture throughout the organization, ensuring that all personnel are aware of their responsibilities and adequately trained to perform their duties securely.<\/li>\n<\/ul>\n<p>.<\/p>\n<p><!-- \/wp:paragraph --><\/p>\n<\/div><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1469","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/pages\/1469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/comments?post=1469"}],"version-history":[{"count":3,"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/pages\/1469\/revisions"}],"predecessor-version":[{"id":1473,"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/pages\/1469\/revisions\/1473"}],"wp:attachment":[{"href":"https:\/\/im4digital.com\/IT\/wp-json\/wp\/v2\/media?parent=1469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}