Information
Security Policy
How TAK Devs protects the confidentiality, integrity, and availability of information assets, meeting every legal, regulatory, and contractual obligation along the way.
Scope & Objective
Who this policy covers, and why it exists.
Scope
This policy applies to all users of information assets, including TAK Devs employees, temporary agency staff, vendors, business partners, and contractor personnel, across every function and geographic location. It covers every Information Systems environment operated by TAK Devs or contracted through a third party, including documentation, physical and logical controls, personnel, hardware such as desktops, network, and wireless devices, software, and information itself.
Objective
The objective is to provide a consistent instrument for TAK Devs' Information Security Governance, Operations, and Risk Management frameworks. The policy guides how the company identifies, assesses, escalates, and manages issues that matter for smooth operations, in service of TAK Devs' strategic objectives.
Terms & Definitions
One term anchors this document.
The intentions and direction of an organization, as formally expressed by its top management.
Information Security Policy Statements
The commitments that keep TAK Devs' information assets protected.
The information assets of TAK Devs are protected from all types of threats, whether internal or external, deliberate or accidental, so that the confidentiality of information is maintained, the integrity of information can be relied upon, the availability of information is ensured, and all legal, regulatory, statutory, and contractual obligations are met.
Applies to all information assets of TAK Devs and its third parties or vendors. For third parties, applicability is limited to assets used to provide services for TAK Devs.
Applies to Information Security functions and services across all Affiliates of TAK Devs.
Applies to all TAK Devs employees and its third party in-agreement employees. For third parties, this is limited to employees and subcontractors engaged on a TAK Devs project and the scope of that engagement. Any shared staff member supporting TAK Devs operations must abide by the appropriate sections of this policy. Non-compliance may result in disciplinary action and legal consequences where applicable.
Applies across all locations where TAK Devs' information assets reside, and to every function and unit where information is processed.
TAK Devs is committed to satisfying all applicable requirements from regulators, clients, internal process, and the ISO 27001:2022 standard.
TAK Devs is committed to continually improving information security compliance to protect and safeguard the information assets within its scope.
TAK Devs' Top Management ensures leadership, direction, and resource allocation for the Information Security Management System (ISMS).
Information security risks are systematically identified, assessed, treated, and reviewed in accordance with the organization's risk management methodology.
TAK Devs implements appropriate administrative, technical, and physical controls, including:
TAK Devs complies with all applicable legal, statutory, regulatory, and contractual requirements, including intellectual property and data protection obligations.
All TAK Devs employees receive appropriate information security awareness to ensure this policy is implemented effectively.
The ISMS is monitored, measured, internally audited, and reviewed by management to ensure effectiveness and alignment with business objectives. Non-compliance with this policy may result in disciplinary action and legal consequences where applicable.
A shared responsibility. Every employee, contractor, vendor, and affiliate operating under TAK Devs is expected to know and follow this policy within the scope of their engagement. Questions about applicability or reporting a concern should be directed to TAK Devs' management.






