Information Security Policy
Information Security Policy Information for fuentis AG.
Last updated: 11/1/2025
Informationsecurity Policy
Information Security Policy of fuentis AG
1. Purpose, Scope and Objective
This document defines the principles and strategic direction of the Information Security Management System (ISMS) of fuentis AG. It specifies how information security is governed, implemented, and continuously improved within the organization.
The policy applies to all locations, systems, processes, employees, and any third parties acting on behalf of fuentis AG.
2. Definitions
Confidentiality: Ensuring information is not accessible or disclosed to unauthorized parties.
Integrity: Safeguarding the correctness and completeness of information.
Availability: Ensuring information is accessible and usable by authorized parties when required.
Information Security: Preservation of confidentiality, integrity, and availability of information.
ISMS: A management system for planning, implementing, maintaining, monitoring, and improving information security.
3. Importance of Information Security
3.1 Business Objectives
fuentis AG develops and operates modern, risk-based management system platforms (e.g., ISMS, BCMS, Compliance). Our mission is to help organizations meet regulatory requirements efficiently through technology and best practices. Information security is a core component of our value proposition and product quality.
3.2 Requirements and Interested Parties
The ISMS considers the needs and expectations of:
Customers
Legislators and supervisory authorities
Employees
Partners
Investors
Executive Management
3.3 Role of Information Security
The protection of sensitive data—particularly customer data, development artefacts, and operational information—is essential for trust, compliance, and product reliability. Information security therefore represents a strategic corporate objective and is embedded into all key business processes.
3.4 ISMS Objectives
The ISMS of fuentis AG pursues the following objectives:
Fulfilment of ISO/IEC 27001 requirements
Strengthening the information security awareness of all employees
Continuous improvement of customer satisfaction
Systematic identification, assessment, and treatment of information security risks
Ongoing protection of our platforms, cloud services, and on-premise deployments
All objectives and progress are documented and reviewed annually.
3.5 Planning and Review
For each ISMS objective, responsibilities, actions, resources, timelines, and measurement methods are defined. The Information Security Officer reviews the achievement of objectives at least annually and reports results to management.
3.6 Information Security Measures
We comply with all relevant ISO/IEC 27001 requirements as well as internal security policies. Controls are defined as part of risk management and documented in the Statement of Applicability (SoA).
4. Responsibilities
Role | Responsibilities |
Executive Management | Strategic direction, resource allocation, overall communication of the policy |
Information Security Officer (ISO) | Implementation, maintenance, monitoring of the ISMS, reporting, annual reviews |
Human Resources | Security awareness, training, personnel-related security processes |
Asset Owners | Protection, maintenance, availability of assigned assets |
Lead Developer | Secure software development, handling of technical vulnerabilities |
All Employees | Compliance with all information security rules, reporting of incidents or weaknesses |
Recurring tasks are centrally managed and documented through the fuentis Suite.
5. Corporate Policy
Information security is anchored at the highest management level. The fuentis AG is committed to continuously developing the ISMS, providing necessary resources, and adapting processes to evolving technologies and regulatory requirements.
6. Obligations
All employees and relevant third parties must comply with this policy as well as the related information security guidelines. Violations may result in disciplinary actions.
7. Reference Documents
ISMS scope
Requirement identification procedure
ISMS objectives & KPIs procedure
Corrective actions procedure
Statement of Applicability (SoA)
8. Records
The following records are maintained in connection with this policy:
ISMS objectives & KPI reports
Assessment and audit results
Overview of regulatory and contractual requirements
Statement of Applicability
Records are maintained in accordance with the document control procedure.
9. Validity
This policy is effective as of 01 September 2025. The Information Security Officer reviews it at least annually for adequacy, effectiveness, and potential updates (e.g., based on audit outcomes, KPI evaluations, or risk assessments).