Last updated on 22 August, 2024.
We are fully aware of the importance of maintaining the availability, confidentiality and integrity of information related to the company, our employees, clients and other partners and stakeholders while considering Accountability and Non-repudiation through our Information Security policy. Therefore, we have established and set up an information management system to protect all necessary assets. This policy encompasses all systems, automated and manual, for which the entity has administrative responsibility, including systems managed or hosted by third parties on behalf of the entity. It addresses all information, regardless of the form or format, which is created or used in support of business activities.
In adherence to international standards, we proudly hold ISO/IEC 27001 certification, ensuring an effective Information Security Management System (ISMS). Our information security approach prioritizes safeguarding data confidentiality, integrity, and availability. We continually identify, assess, and manage risks, conduct regular IT audits, and uphold IT governance through relevant standards. Proactive measures prevent security incidents, protect reputations, and ensure compliance with legal obligations, regulations, and data privacy requirements. Our commitment aims to establish us as a trustworthy and dependable partner for our clients. Establishing ourselves as a robust and dependable partner for our clients.
To ensure the security and confidentiality of any information that we handle as a company or on behalf of clients, partners and stakeholders, we have adopted the following principles:
To fulfill our goals in the information security area, we have implemented policies to cover all important parts of information security. Adopted Information Security Management System and implemented adequate tools, we ensure that all employees, contractors and partners are aware of their individual responsibility to maintain and ensure high standards of information security.
Systems encompass servers, platforms, networks, communications, databases, and software applications. Our responsibility for maintenance/administration is assigned centrally. We-
Implement controls based on data classification for each system.
Synchronize system clocks to UTC using centralized reference time sources.
Establish environments/test plans for system validation pre-production.
Enforce separation of environments (development, test, QA, production).
Develop and enforce formal change control procedures for all systems.
In order to ensure the security of our database and Software system, we have Implemented secure coding, protected classified test data, used production data with documented approval, avoided storing source code, removed non-essential scripts, restricted privileged access, and document migration processes for software transfer.
For robust network security, we authorize and document system connections, annually reviewing their validity. Our network architecture incorporates tiered segmentation, and management is exclusively performed from a secure network. Authentication is enforced for users and devices accessing internal systems, while network traffic capture is limited to authorized entities. Additionally, we conduct risk assessments before implementing significant network changes.
We follow the standard procedure for internal account management and access control, which covers:
Sensitive information, encompassing user data and login credentials, transmitted via the OLES website, is mandated to undergo encryption. This process shall adhere to secure and widely accepted encryption protocols.
Our People and Culture Policy is dedicated to fostering an inclusive, respectful, and supportive work environment. We prioritize diversity, equity, and employee well-being, promoting continuous learning and professional growth. This commitment ensures a positive workplace culture, driving both individual and organizational success.
Our Internal Audit Policy ensures sturdy governance and operational efficiency through regular, objective audits. We assess compliance, risk management, and internal controls, providing actionable insights for continuous improvement. This rigorous approach guarantees transparency, accountability, and adherence to industry standards and regulations.
Omnilab ES ensures that all partners and staff recognize the critical importance of information security, including the protection of personal information. We emphasize the necessity of proper information handling and provide ongoing education on information security practices.
We have established an incident response plan to promptly address security incidents related to the website. All personnel must report any suspicious activity or security incidents immediately. In case of any incident of breach, please contact our dedicated team at: marketing@omnilabes.com.
Periodic security audits and assessments of the OLES website shall be conducted to identify vulnerabilities and ensure compliance with security policies.
This Information Security Policy shall be reviewed periodically to ensure its relevance and effectiveness. We reserve the right to make updates as necessary to address emerging threats and changes in technology.
For questions or concerns regarding this Information Security Policy, please contact the Omnilab ES Information Security Team at marketing@omnilabes.com or, +88-01720875032
The official website address of OmniLab Enterprise Solutions Ltd. is https://omnilabes.com. By using the Omnilab ES or OmniLab Enterprise Solutions websites, all users acknowledge and agree to comply with this Information Security Policy.
OmniLab Enterprise Solutions prioritizes safeguarding data through our ISO/IEC 27001 certified Information Security Management System (ISMS), emphasizing risk management, continuous improvement, and compliance with legal obligations.
We implement rigorous security measures including encryption, access control, and regular IT audits to protect the confidentiality and integrity of all client information.
Yes, please report any security incidents or suspicious activities immediately to our dedicated support team at [email protected].
Omnilab ES uses secure and widely accepted encryption protocols to ensure the protection of sensitive information transmitted via our website.
Our Information Security Policy is reviewed periodically to ensure its effectiveness and relevance, with updates made as necessary to address new threats and technological changes.
OmniLab Enterprise Solutions conducts regular training and educational programs for all employees and partners to reinforce the importance of information security, emphasizing proper handling of personal and sensitive data in alignment with our ISO/IEC 27001 standards.
LOCATION
SUBSCRIBE US
Sign up to get amazing offers and our monthly newsletter.