CloudVantage Startup Program

Apply Now

Information Security Policy

Effective from 9th Sep, 2026

1. Information Security Policy

Information is a critical business asset that supports CloudVantage's operations, products and services and provides significant value to the organisation. CloudVantage recognises that information and supporting information assets may be exposed to internal and external threats that could compromise confidentiality, integrity, availability and business continuity.

CloudVantage is committed to establishing, implementing, maintaining and continually improving an effective Information Security Management System (ISMS) in accordance with the requirements of ISO/IEC 27001:2022.

The purpose of this Information Security Policy is to provide a framework for protecting CloudVantage's information and information assets from security threats, whether internal or external, deliberate or accidental, and to minimise the likelihood and impact of information security incidents.

2. Policy Commitments

CloudVantage is committed to:

  • Protecting the confidentiality, integrity and availability of information and information assets.
  • Complying with applicable legal, regulatory, contractual and other information security requirements.
  • Identifying, assessing and appropriately treating information security risks and opportunities.
  • Establishing and maintaining appropriate information security objectives that support CloudVantage's business objectives and strategic direction.
  • Providing the necessary resources, competence, awareness and support required to implement and maintain the ISMS.
  • Integrating information security requirements into relevant business processes, projects, technology operations and decision-making.
  • Continually improving the suitability, adequacy and effectiveness of the ISMS through monitoring, measurement, audits, management reviews, corrective actions and lessons learned.
  • Maintaining effective arrangements for the identification, reporting, response and management of information security incidents.
  • Promoting information security awareness and ensuring that personnel understand their responsibilities for protecting CloudVantage's information and information assets.

3. Scope of Information Security

The Information Security Policy applies to CloudVantage's information assets and supporting resources, including information stored, processed or transmitted electronically or physically. This includes information contained in computers and other devices, applications, cloud infrastructure, networks, databases, removable media, printed documents and other physical records, as well as information communicated verbally or through other communication channels.

The policy applies to employees, contractors, third parties and other relevant persons who have access to CloudVantage's information assets or information systems within the defined ISMS scope.

4. ISMS Objectives

CloudVantage has established the following information security objectives:

  • Compliance: Achieve and maintain 100% compliance with applicable legal, regulatory and contractual information security requirements.
  • Security and Incident Management: Protect the confidentiality, integrity and availability of information and improve information security incident response through effective controls, testing and staff training.
  • Continual Improvement: Strengthen the effectiveness of the ISMS through risk assessment, monitoring, internal audits, corrective actions and management review.

5. Responsibilities

  • Top Management provides leadership and support for the implementation and continual improvement of the ISMS and ensures that information security requirements are integrated into relevant organisational processes.
  • Managers are responsible for implementing this policy within their areas of responsibility and ensuring that personnel under their supervision understand and comply with applicable information security requirements.
  • The Information Security Manager is responsible for coordinating the implementation, maintenance and continual improvement of the ISMS and providing appropriate guidance and support to the organisation.
  • All employees, contractors and relevant third parties are responsible for complying with this policy and applicable information security procedures and controls and for promptly reporting suspected or actual information security incidents.

Failure to comply with applicable information security requirements may result in appropriate corrective or disciplinary action in accordance with CloudVantage's established processes.

6. Policy Review and Communication

This Information Security Policy shall be reviewed at least annually and whenever significant changes occur in CloudVantage's business, technology, regulatory environment, information security risks or organisational context, to ensure its continuing suitability, adequacy and effectiveness.

The policy shall be approved by Top Management, communicated to relevant personnel and made available to relevant interested parties where appropriate.

Approved by Management. Date: 9th September 2026.