Information Security Management System (ISMS) Policy
OREL Technologies maintains an Information Security Management System (ISMS) to protect the confidentiality, integrity, and availability of the information and systems entrusted to us. This policy defines how we identify, assess, and manage security risk across our people, processes, technology, and data — and the commitments we make to our customers, partners, and the public.
Last updated: 2026
1. Purpose and scope
This policy establishes the governing principles and minimum-control baseline for information security at OREL Technologies. It applies to all directors, employees, contractors, consultants, interns, and any third party granted access to OREL systems, networks, or data.
Its scope covers every information asset and processing activity used to deliver our services — including the OrelLMS learning platform, managed security operations, platform infrastructure, internal systems, and any customer or user data we handle, whether at rest or in transit.
The policy is risk-based: controls are selected, implemented, and prioritized according to the value and sensitivity of the information they protect and the likelihood and impact of the threats they address. Not every control applies to every asset; the intent is proportionate, risk-informed protection rather than a one-size-fits-all checklist.
2. Leadership and management commitment
Senior management owns the ISMS and provides the authority, resources, and accountability needed to establish, operate, monitor, review, and continually improve it.
Security objectives are set at the leadership level, reviewed at planned intervals, and communicated throughout the organization so that responsibility for security is understood at every level.
Management assigns clear roles and responsibilities — including an accountable security owner and defined operational duties — and ensures the ISMS is aligned with organizational strategy and business requirements.
3. Security policy and governance
A documented set of security policies and standards defines approved practice for access control, acceptable use, data classification, change management, incident handling, third-party risk, business continuity, and asset management.
All policies are reviewed and updated on a planned cycle, or when significant changes occur to systems, threats, or legal and regulatory obligations.
Roles and responsibilities for information security are documented and assigned, preventing ambiguity about who can act, approve, or own an asset or control.
4. Risk management
Information security risk is assessed using a defined, repeatable methodology that identifies assets, threats, and vulnerabilities, and evaluates the likelihood and impact of compromise.
Risk treatment applies the appropriate response — mitigation through controls, acceptance with management approval, transfer, or avoidance — and is recorded so decisions and residual risk are documented and traceable.
Risk assessments are repeated on a planned cycle and whenever significant changes occur to the environment, so that new or changed threats are never silently accepted.
5. Asset management
Information assets are inventoried, classified by sensitivity, and assigned an owner responsible for their protection and proper handling throughout their life cycle.
Assets are created, stored, transmitted, retained, and disposed of according to their classification, with appropriate handling rules for each category.
Media and hardware are sanitized or securely destroyed before disposal or reuse so data cannot be recovered by unauthorized parties.
6. Access control
Access to systems, applications, and data is granted on a least-privilege, need-to-know basis — only the minimum access required for an individual’s role is provisioned.
Access rights are subject to appropriate authentication, are reviewed at planned intervals and on role change, and are revoked promptly when someone leaves or no longer requires them.
Privileged (administrative) access is tightly controlled, minimized, logged, and reviewed. Authentication uses strong credential practices and, where the risk warrants, multi-factor authentication.
Access to customer data is restricted to authorized personnel and recorded, so that who accessed what, when, and why can be established.
7. Cryptography and data protection
Data in transit is protected using up-to-date, industry-standard encryption wherever it carries sensitive or customer information. Data at rest is protected according to its classification and the requirements of the service.
Key management follows defined rules for generation, storage, rotation, and destruction, and considers the sensitivity and retention requirements of the data protected.
Customer data is treated as confidential, is never used beyond the purpose for which it was entrusted, and is not accessed without a legitimate, documented business reason.
8. Physical and environmental security
Facilities, server rooms, and the networks and equipment hosting OREL services are protected with physical access controls appropriate to the sensitivity of the assets — including access restriction, monitoring, and procedures for visitors and contractors.
Critical systems and media are protected against environmental threats such as fire, water, and power failure through appropriate safeguards.
Staff and contractors are trained in secure handling of physical assets, and secured areas follow a clear principle of least authorization.
9. Operational security
Systems are subjected to secure configuration standards, routine maintenance, and timely patching to close known vulnerabilities.
A documented change-management process ensures that changes to systems and software are planned, tested, reviewed, approved, and reversible, reducing the risk of disruption or insecure configuration.
Protection against malware and malicious code is deployed at appropriate layers, and antivirus, anti-exploit, and integrity protections are kept current.
Transfer of information between parties — internally and externally — follows agreed and secure transfer procedures, especially for sensitive or financial data.
10. Communications security
Networks are managed and secured with appropriate segmentation, monitoring, and controls to protect the confidentiality and availability of transmitted information.
Off-site assets and remote access are secured, and portable or mobile devices used by staff are protected and controlled.
Information systems and services are segregated by risk and function where practical to limit the impact of a compromise on other areas of the environment.
11. Secure development and acquisition
Security requirements are considered during the design, development, and acquisition of systems and software, and are tested before deployment.
Development follows secure-coding practices, and testing includes verification that security controls work as intended — including checking for common web and application vulnerabilities.
Changes to development, testing, and production environments are separated and controlled so that untested or unauthorized code cannot reach production.
12. Supplier and third-party relationships
Third parties who access, process, store, or transmit OREL or customer information are evaluated for security posture before engagement and are held to equivalent security expectations through agreements and monitoring.
Supplier access is limited to what is necessary, is reviewed, and is revoked when no longer required.
Risks introduced through the supply chain — including trust dependencies and partial-supplier outages — are assessed and managed as part of the risk-management process.
13. Incident management
Security incidents are detected, triaged, contained, and resolved through documented procedures with clear roles, escalation paths, and timelines.
Evidence is preserved to support investigation and, where applicable, regulatory and customer reporting.
Material incidents affecting our services or the data entrusted to us are communicated to affected customers promptly, clearly, and in plain language, along with the actions taken to contain and remediate.
Incidents are reviewed after resolution to capture lessons learned and to improve controls and response effectiveness.
14. Business continuity and disaster recovery
Business continuity and disaster-recovery arrangements ensure that critical services and data can be restored within agreed targets following a disruption.
Business continuity and recovery plans are documented, tested at planned intervals, and reviewed to keep them current with the real environment.
15. Compliance and legal obligations
The ISMS is designed so that applicable legal, regulatory, contractual, and security requirements are identified, applied, and documented.
Access to, use of, and protection of customer information and personal data comply with the agreements we hold and applicable data-protection law.
Our ISMS is aligned to recognized frameworks, including the principles of ISO/IEC 27001, to provide assurance to customers and auditors that controls are managed in a structured, auditable way.
16. People and culture
All staff and contractors receive security awareness training appropriate to their roles, covering responsibilities, acceptable use, data handling, phishing, and how to report incidents or concerns.
Awareness is reinforced on a planned cycle, and specialized roles receive role-specific security training.
Disciplinary processes provide for proportionate action in the event of a security-policy violation, and a whistleblower-friendly reporting channel exists for genuine concerns.
A non-disclosure or terms-of-engagement framework binds those handling sensitive or customer information.
17. Measurement, audit, and improvement
The effectiveness of the ISMS is measured through defined performance indicators, internal reviews, and audits conducted at planned intervals.
Internal audits evaluate whether the ISMS conforms to this policy and its supporting standards, is implemented and maintained effectively, and performs as expected.
Nonconformities and findings are corrected, and the ISMS is reviewed by management and improved continuously so that controls keep pace with changing threats and business needs.
18. Reporting and responsible disclosure
We welcome the responsible disclosure of security vulnerabilities in our public-facing systems and respond to reports promptly and in good faith.
Security enquiries, vulnerability reports, and the reporting of any concern or incident should be directed to the contact below.
Contact
For security questions, responsible disclosure of a vulnerability, or to report an incident or concern, email [email protected].