ISO 27001 Information Security Policy
Limesoft System's commitment to information security aligned with ISO/IEC 27001:2022 standards.
1. Policy Statement
Limesoft System is committed to protecting the confidentiality, integrity, and availability of information assets. We implement and maintain an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022 to ensure the security of client data, employee information, and organizational assets.
This policy establishes our framework for managing information security risks and protecting against unauthorized access, modification, disclosure, or destruction of information.
2. Scope
This policy applies to:
- All Limesoft employees, contractors, and third-party service providers
- All information assets including data, systems, networks, and facilities
- All operations across Nigeria, UK, Cameroon, Rwanda, and other locations
- Client information and proprietary business data
- Physical and logical access to information systems
3. Information Security Objectives
Limesoft commits to:
- Maintain confidentiality of sensitive information through access controls and encryption
- Ensure integrity of data through change management and audit controls
- Guarantee availability of systems through redundancy and disaster recovery
- Comply with applicable laws, regulations, and contractual obligations
- Conduct regular risk assessments and implement risk mitigation measures
- Train employees on information security practices and awareness
- Continuously improve security practices through monitoring and review
4. Governance & Responsibility
Information security is a shared responsibility:
Management Commitment
Senior management is responsible for establishing information security objectives, allocating resources, and ensuring compliance with this policy.
Information Security Team
Dedicated security personnel oversee ISMS implementation, risk management, incident response, and continuous improvement.
Employee Responsibility
All employees must comply with security policies, protect information assets, report security incidents, and participate in security training.
5. Access Control
Limesoft implements strict access controls:
- Authentication: Multi-factor authentication (MFA) for all systems and privileged access
- Authorization: Role-based access control (RBAC) with principle of least privilege
- Accountability: Audit trails and logging of all access and changes
- Termination: Immediate removal of access upon employment termination
- Privileged Access: Segregation of duties and enhanced monitoring for administrative access
6. Cryptography & Encryption
Sensitive information is protected through encryption:
- Data in transit encrypted using TLS 1.2 or higher
- Data at rest encrypted using AES-256 or equivalent
- Encryption keys managed securely with restricted access
- Secure key storage with backup and recovery procedures
- Regular review of encryption standards and updates
7. Incident Management
Limesoft maintains an incident response program:
- Documented incident reporting procedures and contact information
- 24/7 incident monitoring and rapid response team
- Investigation and containment of security incidents
- Notification of affected parties within 72 hours as required by GDPR and applicable laws
- Post-incident review and lessons learned
- Regular incident response drills and testing
8. Risk Management
Limesoft conducts regular information security risk assessments:
- Annual comprehensive risk assessments
- Risk identification, analysis, and evaluation
- Risk treatment planning and implementation
- Continuous monitoring of risk indicators
- Management review and adjustment of risk strategies
9. Business Continuity & Disaster Recovery
Limesoft maintains business continuity and disaster recovery capabilities:
- Documented business continuity plans with clear objectives and recovery procedures
- Data backup with regular testing and documented recovery procedures
- Geographic redundancy and failover capabilities
- Recovery time objectives (RTO) and recovery point objectives (RPO)
- Regular testing and updates of continuity plans
10. Third-Party & Supplier Security
Limesoft manages information security risks from suppliers and third parties:
- Security requirements in supplier agreements and contracts
- Due diligence review before engaging suppliers
- Regular assessment of supplier security practices
- Confidentiality agreements and data processing agreements (DPAs)
- Right to audit supplier security controls
11. Security Awareness & Training
All Limesoft employees receive regular security training:
- Mandatory security awareness training for all employees
- Specialized training for personnel with specific security responsibilities
- Regular updates on emerging threats and security practices
- Phishing simulations and security awareness campaigns
- Documented training completion and knowledge assessments
12. Compliance & Auditing
Limesoft maintains compliance with information security standards:
- Regular internal audits of ISMS effectiveness
- External audits and certifications (ISO 27001, SOC 2, etc.)
- Compliance monitoring for regulatory requirements (GDPR, NIST, PCI-DSS)
- Management review of audit findings and corrective actions
- Documentation of compliance evidence for regulatory assessments
13. Policy Review & Updates
This policy is reviewed and updated annually or when significant changes occur in the threat landscape, regulatory environment, or organizational structure. All changes are documented and communicated to relevant stakeholders.
14. Contact & Incident Reporting
Report security incidents or concerns to:
Security Team Email: security@limesoftsystem.com
General Inquiries: info@limesoftsystem.com
Phone: +234 814 641 2574