Information Security Policy
The confidentiality, Integrity and availability of information is vital to Customers and CDMS.
This policy with specific associated policies within CDMS, for the security of customer databases and company information in all electronic and physical formats, applies to all CDMS employees and third parties. This is supported and driven through a management security forum and systematic risk assessment.
The Information Security Management System (ISMS) is committed to meeting customer contractual obligations and to comply with all relevant legislation.
CDMS has certification to ISO 27001:2005 for all our activities activities, which is maintained to meet related internationally recognised standards and to continually improve the ISMS.
Assets together with associated risks have been identified and are reviewed regularly to ensure appropriate action is taken to mitigate those risks. This is within a context of their impact, probability and costs of action.
All employees are given appropriate ISMS training and must comply with this and all associated specific policies.

Stephen Clark
Managing Director
August 2008
