CardExchange, Inc., which provides desktop ID card and visitor management software and SaaS based credential management solutions, is committed to preserving the confidentiality, integrity and availability of all assets, including personally identifiable information (PII), in scope of the information security management system (ISMS) in order to maintain its legal, regulatory and contractual compliance and commercial image. CardExchange Inc is committed to ensuring compliance with all applicable legislative, regulatory and contract requirements, including all applicable PII protection legislation. To achieve this, CardExchange Inc has implemented an ISMS in accordance with the international standard ISO/IEC 27001:2013. The ISMS is subject to continual, systematic review and improvement.
2. Policy Objectives
3. Roles and responsibilities
The Chief Technology Officer (CTO) is accountable for the management and maintenance of the risk treatment plan. Additional risk assessments may, where necessary, be carried out to determine appropriate controls for specific risks. All employees and those working under the scope of the ISMS are expected to comply with this policy and with the ISMS that implements this policy. CardExchange Inc has established a Management Team (InfoSec) chaired by the Chief Operating Officer (COO) to support the ISMS framework and to periodically review the Information Security Policy.
Document owner and approval
Login to your account and get access to your Partner Benefits