allclouds.pl

INTEGRATED MANAGEMENT SYSTEM POLICY

INTEGRATED MANAGEMENT SYSTEM POLICY

(quality, information security, environment, business continuity, artificial intelligence)

Purpose, scope and normative basis

1.The Integrated Management System Policy (hereinafter referred to as the "IMS Policy") expresses all the intentions and direction of allclouds.pl sp. z o.o. (hereinafter referred to as the "Organization") in the areas of quality, information security, environmental protection, business continuity and artificial intelligence management, formally established by the Top Management.

2.The IMS Policy covers the activities specified in §2 of the IMS Book: consulting and training activities in the field of IT, supplies and service of equipment, software and IT systems, implementation of IT projects and software design and production.

3.The scopes of the component systems, in accordance with point 4.3 of the relevant standards, are determined as follows:

4.Special notes regarding the implementation of PN-EN ISO/IEC 27017 and PN-EN ISO/IEC 27018 (§2¹ of the IMS Book):

5.Special notes regarding the implementation of ISO/IEC 42001:2023 (§2² of the IMS Book):

6.The IMS Policy meets the requirements of the following standards:

7.The IMS Policy applies to all employees, collaborators and subcontractors acting on behalf of the Organization, to the extent appropriate to the tasks entrusted to them.

8.The IMS Policy consists of: Quality Policy (§3), Information Security Policy (§4), Environmental Policy (§5), Business Continuity Policy (§6) and Artificial Intelligence Management System Policy (§7).

Declaration of the Supreme Management

1.Pursuant to the principle specified in point 5.2.1 lit. d PN-EN ISO 9001, point 5.2 lit. d PN-EN ISO/IEC 27001, point 5.2.1 lit. e PN-EN ISO 14001, point 5.2.1 lit. d PN-EN ISO 22301 and point 5.2 of ISO/IEC 42001 The Top Management declares constant striving to improve the Integrated Management System.

2.If, during everyday work or during an audit in the Organization, it is found that any of the relevant requirements of the implemented standards are not met or can be met more fully, the Organization will take appropriate improvement or corrective actions.

3.Top Management undertakes to meet the applicable requirements of the implemented standards, legal requirements relevant to the Organization's activities and the expectations of interested parties, as well as to provide the resources necessary for the operation and improvement of the IMS.

4.By constantly improving management, the Organization ensures reliable and timely implementation. The component systems are consistent and related in terms of procedures for setting objectives, supervision of documents and records, training, monitoring, measurement and supervision of non-conformities, corrective actions and management review.

5.This Policy constitutes a framework for establishing and reviewing IMS objectives, specified in §5 of the IMS Book and monitored in the Organization's task system.

Quality Policy

Top Management, in accordance with point 5.2.1 of PN-EN ISO 9001:2015, establishes, implements, communicates and declares maintaining the Quality Policy with the following content.

1.The organization offers the client comprehensive, innovative, unique and competitively priced solutions that allow to achieve a high functional level of the implemented IT systems, in particular their security.

2.The subject of the Organization's offer is the Sovereign Artificial Intelligence Ecosystem (SAIE), which consists of:

3.The purpose specified in section 1 The organization implements through:

4.With respect to basic products referred to in paragraph. 2, The Organization accepts the following quality commitments:

5.With respect to the research and development work referred to in section 2, The organization separates the scope of research work from commercial activities, documents the technological readiness levels achieved and does not present the results of development work as ready for production implementation before confirming their maturity.

6.The Top Management undertakes to meet the relevant requirements of PN-EN ISO 9001:2015, legal requirements relevant to the Organization's activities and the expectations of interested parties, as well as to continuously improve the Quality Management System.

7.Supervision of the risks of processes covered by the Quality Management System is carried out in the IMS Risk Register, in accordance with the Risk Assessment Methodology and the risk management procedure.

8.Measurable objectives of the Quality Management System are specified in §5 of the IMS Book and are subject to review during the management review.

Information Security Policy

The Top Management, demonstrating appropriate commitment and aiming to ensure compliance with the implemented information security standards, in accordance with point 5.2 of PN-EN ISO/IEC 27001:2023-08, point 5 of PN-EN ISO/IEC 27017 and point 5 of PN-EN ISO/IEC 27018, adopts the Information Security Policy with the following content.

1.The Information Security Policy applies to the entire information system of the Organization, including information stored by the Organization and its clients in public computing clouds. The context of using cloud computing is specified in §1 section 4.

2.The Organization strives to ensure the security of information covered by the Information Security Management System at the highest level and to ensure compliance with all relevant legal requirements.

3.The Management Board takes the necessary steps to ensure appropriate protection of information assets - including personal data for which the Organization is the controller or processor - against all identified threats.

4.The risk assessment method, risk assessment criteria and risk management are described in the Risk Assessment Methodology and the risk management and asset inventory procedure. The risk analysis considers separately the loss of confidentiality, integrity and availability of information, taking into account the specificity of cloud services.

5.Information is protected adequate to its value, in accordance with the Information Classification Procedure. The list of safeguards used is included in the currently applicable Declaration of Application, which is reviewed at least once a year and after each risk analysis.

6.Access to classified and sensitive information is carried out in accordance with the need-to-know principle. Information processing measures are implemented with sufficient redundancy to meet accessibility requirements.

7.Security requirements regarding IT systems also apply to third parties and are reflected in the concluded contracts. Services provided by third parties are subject to regular monitoring and auditing.

8.Events and incidents in the field of information security are reported to the Management Board Representative for IMS or the Technical Director; the course of action is specified in the Incident Management Procedure.

9.Each team member is trained at least once a year on the principles and requirements of this Policy and related documents.

10.The Management Board is responsible for establishing and implementing the Information Security Policy. Its implementation is supervised by the Management Board Representative for IMS and the Technical Director. All staff members are responsible for its implementation in accordance with their duties and positions.

11.Measurable goals of the Information Security Management System are specified in §5 of the IMS Book.

Environmental Policy

1.The Top Management, appreciating the importance of pro-ecological activities, sets a course of action aimed at systematically striving to minimize the effects on the environment resulting from the Organization's activities in the field of design, implementation and servicing of IT systems, delivery and service of hardware, software and IT systems, implementation of IT projects, software design and production, as well as advisory and training activities.

2.The implemented Environmental Management System aims to:

3.The Organization, within its capabilities and within the limits of the Environmental Management System, undertakes to prevent pollution caused by its activities and to meet relevant legal requirements in this respect.

4.The physical boundaries of the Environmental Management System include the premises of the Organization's headquarters and an external server room in which the Organization maintains its own computing infrastructure in a colocation model, in accordance with §1 section 3. Within the limits of collocation, the Organization supervises those environmental aspects over which it has influence - in particular the consumption of electricity by its own computing infrastructure, its energy efficiency and the handling of waste electrical and electronic equipment; The organization treats aspects that are under the control of the facility operator as aspects that it can influence and takes them into account in the requirements for the supplier.

Business Continuity Policy

1.In accordance with point 5.2.1 of PN-EN ISO 22301, the Top Management establishes and announces the Business Continuity Management System Policy with the content specified in this paragraph.

2.The organization operates in a narrow and difficult market; the systems it creates operate on highly sensitive data, the circulation of which often determines the proper functioning of key public institutions. Therefore, the organization ensures the continuity of services in order to maintain their high quality, adequate to the requirements and security of customer data.

3.The organization strives to create a stable workplace for its employees, functioning regardless of disruptions from the external or internal environment, as a condition for maintaining a permanent team responsible for software design and production.

4.The Top Management, acting through the Management Board Representative for IMS, will meet the applicable requirements of PN-EN ISO 22301 and adapt its activities to the relevant legal requirements.

Artificial Intelligence Management System (AIMS) Policy

1.In accordance with point 5.2 of ISO/IEC 42001:2023, the Top Management establishes the Artificial Intelligence Management System Policy, defining the target strategic direction and principles of artificial intelligence management in the Organization.

2.The AIMS Policy applies to:

3.The organization adopts the following artificial intelligence management principles:

4.The AIMS Policy refers in particular to ISO/IEC 42001:2023, ISO/IEC 27001:2023-08, ISO/IEC 23894:2023, Regulation (EU) 2024/1689 (EU AI Act), Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2022/2554 (DORA), Directive (EU) 2022/2555 (NIS2) together with the Act on the National Cybersecurity System and NIST AI RMF.

5.The Management Board declares full commitment to the implementation, maintenance and continuous improvement of AIMS, including ensuring compliance of the AIMS Policy with the strategic direction of the Organization as Sovereign AI Platform Company, integrating AIMS requirements with business processes and CDF product strategy, providing the necessary resources, appointing the Management Board Representative for IMS responsible for supervising AIMS and supporting the AI ​​Council as the main decision-making body in AI matters.

6.Details of the rules set out in this paragraph are included in the AI ​​Use Policy (AI-GOV_POL_AIUsage) and related documents.

Communication, availability and version control

1.The IMS policy is communicated to employees and understood within the Organization; constitutes the basis for setting the objectives of the IMS and assessing its ongoing usefulness.

2.The IMS Policy is made available to employees in the OneDrive electronic files and on the ISO information panel in the Organization's task system, and to interested parties - on the allclouds.pl website.

3.There is one approved content of the IMS Policy. The content published on allclouds.pl must be identical to the internal content and bear the version number and approval date. The Management Board Representative for IMS is responsible for the compliance of both contents.

4.The published content is updated within 7 business days from the approval of the new version by the Management Board.

Policy Review

1.The IMS Policy is reviewed at least once a year as part of a management review, and each time there is a significant change in the context of the Organization, the scope of certification, legal requirements or the results of risk analysis.

2.The review includes an assessment of the usefulness, adequacy and effectiveness of the Policy and its consistency with the objectives of the IMS and the IMS Risk Register.

3.Changes to the IMS Policy are approved by the Management Board by way of a resolution.

Final provisions

1.This Policy replaces the content of §4 of the IMS Book v6.1 (§4a–§4e) and the content of the IMS Policy previously published on allclouds.pl. Until the IMS Book v6.2 is issued, §4 of the IMS Book shall apply in the wording of this Policy.

2.The policy enters into force on the day of approval by the Management Board and remains valid until it is replaced by a new version.

3.In matters not regulated in this Policy, the provisions of the IMS Book and detailed IMS policies and procedures shall apply.