The third edition of ISO/IEC 27002 was published last February… the new controls are now in ISO/IEC 27001:2022 Annex A which was published on 25 October last
 

Privacy policy

Personal data are only collected on this website by invitation if a person elects to ask a question. We ask for a contact email so that a reply can be given. The information is only used to reply. IMS-Smart Limited does not use cookies on its public website.

Personal data collected in the SAAS, including cookies, are for user authentication, access control, ensuring compliance with the contract, and helping in the use of the SAAS. IMS-Smart Limited registers a single client administrator for each client, who is responsible for registering/deregistering their users. A username for each account is required, but this chosen by the client administrator and does not have to be the person’s name.

Personal data are also collected through correspondence with IMS-Smart Limited (client’s name, contact and invoicing information), and are for the purpose of conducting business with that client or prospective client.

Since the data subject provides their PII they are responsible for its accuracy. IMS-Smart Limited’s responsibility is to maintain it that way. PII is held encrypted in the company’s databases. Database backups are retained for 6 months and are then discarded.

Integrity and confidentiality are ensured by the information security controls as specified and managed by the company’s ISO/IEC 27001:2022 conformant ISMS.

The Director is accountable for all aspects of PII.