Santa Monica Networks (hereinafter – SMN) is committed to ensuring that all information entrusted to us and managed by us – whether it concerns clients, partners, employees, or internal organizational data – is properly protected throughout its entire lifecycle.
The management recognizes information security as one of the key components of business continuity, reliability, and compliance. Therefore, the Information Security Management System (ISMS) within our organization is implemented in accordance with the requirements of ISO/IEC 27001:2022, integrated with other management systems, and is continuously improved.
The purpose of this policy is to define the principles and directions of information security management, under which SMN:
-
Ensures the confidentiality, integrity, and availability of information;
-
Identifies and manages risks related to information;
-
Implements and maintains compliance with legal and contractual requirements;
-
Promotes a culture of information security throughout the organization.
This policy applies to:
-
All SMN operations in Lithuania and Latvia;
-
All organizational information assets – whether digital, paper-based, or verbal;
-
All employees, partners, service providers, and other interested parties with access to information or systems.
Information Security Principles:
-
Minimum access rights: Employees are granted only the access necessary to perform their duties;
-
Risk management: Information security risks are assessed periodically and in response to changes;
-
Incident management: All information security incidents are recorded, analyzed, and their impact is managed;
-
Continual improvement: The ISMS is reviewed, assessed, and improved at least once per year;
-
Legal compliance: Adherence to GDPR, national legislation, ISO/IEC 27001:2022, and contractual obligations is ensured;
-
Employee engagement: Every employee is responsible for complying with the information security policy.
SMN management is committed to:
-
Allocating sufficient human, technical, and financial resources for maintaining the ISMS;
-
Defining, evaluating, and reviewing information security objectives;
-
Ensuring that all interested parties are informed about this policy;
-
Incorporating information security principles into strategic business decisions;
-
Ensuring that this policy is implemented at all levels of the organization.
This policy represents the public-facing part of SMN's information security policy, intended to inform external stakeholders about the organization's commitment to information security.
It is a summarized version of the information security policy, outlining the key principles and directions of ISMS implementation in accordance with ISO/IEC 27001:2022.
All detailed internal documentation – including procedures, instructions, methodologies, and responsibilities – is intended for internal SMN use and is not publicly available.
This policy is reviewed at least once per year or in response to changes in legislation, business processes, or the risk environment.
To learn more about information security or to report a potential security breach, please contact: info@smn.lt