INTEGRATED MANAGEMENT SYSTEM POLICY

(quality, information security, environment, business continuity, artificial intelligence)
Purpose, scope and normative basis
1.The Integrated Management System Policy (hereinafter referred to as the "IMS Policy") expresses all the intentions and direction of allclouds.pl sp. z o.o. (hereinafter referred to as the "Organization") in the areas of quality, information security, environmental protection, business continuity and artificial intelligence management, formally established by the Top Management.
2.The IMS Policy covers the activities specified in §2 of the IMS Book: consulting and training activities in the field of IT, supplies and service of equipment, software and IT systems, implementation of IT projects and software design and production.
3.The scopes of the component systems, in accordance with point 4.3 of the relevant standards, are determined as follows:
- Quality Management System and Business Continuity Management System - the entire Organization and all its products,
- Information Security Management System - all information resources of the Organization, including information stored in the public cloud; z tego względu Organizacja rozszerza swój SZBI o wymagania PN-EN ISO/IEC 27017 i PN-EN ISO/IEC 27018,
- Environmental Management System - the premises of the Organization's headquarters and an external server room in which the Organization maintains its own computing infrastructure in a colocation model,
- Artificial Intelligence Management System - additionally, beyond the scope indicated in section 2, Cognitive Deployment Framework (CDF).
4.Special notes regarding the implementation of PN-EN ISO/IEC 27017 and PN-EN ISO/IEC 27018 (§2¹ of the IMS Book):
- the Organization's activities comply with these standards to the extent that the implementation of main and auxiliary processes takes place or can take place in the cloud computing,
- The organization acts as a cloud service client within the meaning of PN-EN ISO/IEC 27017 and as an administrator of personal data (PII controller) transferred for processing in the public cloud within the meaning of point 3.3 of PN-EN ISO/IEC 27018; the organization entrusts personal data received from customers to cloud service providers for further processing on the basis of entrustment agreements,
- The organization is the administrator of personal data of its team members and subcontractors and processors based on agreements with clients and subcontractors,
- The organization is a customer of Microsoft Azure and Asana cloud services,
- The organization envisages the possibility of creating a cloud service supply chain referred to in point 4.2 of PN-EN ISO/IEC 27017 when its customers are ready to implement such solutions, and declares to ensure compliance with these standards if it is created,
- The organization has human and organizational resources to provide mass memory, network and workstation virtualization services via cloud computing, build databases and applications, and transfer the client's operations to the cloud computing; When selecting a supplier, the Organization is guided by the Customer's requirements and the obligations arising from this Policy.
5.Special notes regarding the implementation of ISO/IEC 42001:2023 (§2² of the IMS Book):
- the CDF product covered by the Artificial Intelligence Management System includes: the CDF methodology used in customer projects, the CDF Platform - a web application for managing AI implementations, the CogOps service (CDF Phase F6) - continuous operation of AI systems and the Cognitive SLA service - guaranteeing the quality of AI reasoning,
- CDF, as a product covered by the Artificial Intelligence Management System, is not subject to certification in the scope of the PN-EN ISO 9001, PN-EN ISO/IEC 27001, PN-EN ISO/IEC 27017, PN-EN ISO/IEC 27018, PN-EN ISO 14001 and PN-EN ISO 22301 standards, the scope of which is defined in section 2,
- other products and development works of the SAIE ecosystem referred to in §3 section 2, are subject to the principles of §7 of this Policy and the AI Use Policy; their inclusion in these principles does not extend the scope of certification of the Artificial Intelligence Management System. Extending the scope requires a prior amendment to §2² of the IMS Book and notification to the certification body.
6.The IMS Policy meets the requirements of the following standards:
- PN-EN ISO 9001:2015-10 - quality management systems (point 5.2),
- PN-EN ISO/IEC 27001:2023-08 - information security management systems (point 5.2),
- PN-EN ISO/IEC 27017:2021-07 and PN-EN ISO/IEC 27018:2020-11 - security of cloud computing services and protection of personal data in the public cloud (point 5),
- PN-EN ISO 14001:2015-09 - environmental management systems (point 5.2),
- PN-EN ISO 22301:2020-04 - business continuity management systems (point 5.2),
- ISO/IEC 42001:2023 - Artificial intelligence management system (clause 5.2).
7.The IMS Policy applies to all employees, collaborators and subcontractors acting on behalf of the Organization, to the extent appropriate to the tasks entrusted to them.
8.The IMS Policy consists of: Quality Policy (§3), Information Security Policy (§4), Environmental Policy (§5), Business Continuity Policy (§6) and Artificial Intelligence Management System Policy (§7).
Declaration of the Supreme Management
1.Pursuant to the principle specified in point 5.2.1 lit. d PN-EN ISO 9001, point 5.2 lit. d PN-EN ISO/IEC 27001, point 5.2.1 lit. e PN-EN ISO 14001, point 5.2.1 lit. d PN-EN ISO 22301 and point 5.2 of ISO/IEC 42001 The Top Management declares constant striving to improve the Integrated Management System.
2.If, during everyday work or during an audit in the Organization, it is found that any of the relevant requirements of the implemented standards are not met or can be met more fully, the Organization will take appropriate improvement or corrective actions.
3.Top Management undertakes to meet the applicable requirements of the implemented standards, legal requirements relevant to the Organization's activities and the expectations of interested parties, as well as to provide the resources necessary for the operation and improvement of the IMS.
4.By constantly improving management, the Organization ensures reliable and timely implementation. The component systems are consistent and related in terms of procedures for setting objectives, supervision of documents and records, training, monitoring, measurement and supervision of non-conformities, corrective actions and management review.
5.This Policy constitutes a framework for establishing and reviewing IMS objectives, specified in §5 of the IMS Book and monitored in the Organization's task system.
Quality Policy
Top Management, in accordance with point 5.2.1 of PN-EN ISO 9001:2015, establishes, implements, communicates and declares maintaining the Quality Policy with the following content.
1.The organization offers the client comprehensive, innovative, unique and competitively priced solutions that allow to achieve a high functional level of the implemented IT systems, in particular their security.
2.The subject of the Organization's offer is the Sovereign Artificial Intelligence Ecosystem (SAIE), which consists of:
- TWIN:DESK - AI digital desk; sovereign work environment with AI combining work modules, model selection and organizational knowledge in one, configurable place (basic product),
- PROXY:AI - Services, Policy and Compliance Gateway; one point of control for each language model invocation, including data classification, routing, policy enforcement, cost accounting, and immutable log (core product),
- CDF Platform - AI implementation methodology ensuring effectiveness and compliance of implementations; a superior layer to other elements of the ecosystem,
- SAVANT-AI - cognitive system constituting the sovereign knowledge core of the organization (research and development work),
- GENESIS-AI - Agent Factory; environment for the creation and orchestration of autonomous AI agents (research and development),
- HCG - work improvement methods and CDT - employee's digital cognitive twin; methodological layers expressing the philosophy of working with AI adopted in the Organization.
3.The purpose specified in section 1 The organization implements through:
- maintaining lasting and positive relationships with clients, learning and analyzing their needs and consistent implementation of the client's business requirements and goals,
- tracking the latest trends in the IT market and economy,
- building competences based on a permanent group of experienced specialists in many fields of IT and other fields relevant to achieving the Organization's goals, as well as striving to improve their qualifications,
- maintaining permanent and long-term relationships with business partners enabling obtaining expert knowledge in the field of offered products,
- building a range of own services,
- designing and delivering solutions enabling quick return of funds invested by the client,
- ensuring timely and reliable implementation of contractual obligations.
4.With respect to basic products referred to in paragraph. 2, The Organization accepts the following quality commitments:
- sovereignty as a product property, not a declaration - each implementation variant (sovereign cloud, on-premise, appliance, offline mode) provides a full functional scope, and the choice of variant determines only the place of data processing,
- enforcement of compliance by technical means - regulatory requirements are enforced by the product architecture (data classification, routing, approval thresholds, log), and not by a policy provision that can be bypassed,
- traceability and accountability - each model call and each agent action leaves a record enabling the reconstruction of the course and the presentation of evidence for audit purposes,
- risk-appropriate human supervision - the level of autonomy is open and controlled, and human approval is required for high-risk tasks,
- no dependence on a single supplier - an open technology stack allows for the replacement of the model layer without rebuilding the customer's system,
- interoperability within the ecosystem - SAIE products and developments benefit from a common layer of control provided by PROXY:AI.
5.With respect to the research and development work referred to in section 2, The organization separates the scope of research work from commercial activities, documents the technological readiness levels achieved and does not present the results of development work as ready for production implementation before confirming their maturity.
6.The Top Management undertakes to meet the relevant requirements of PN-EN ISO 9001:2015, legal requirements relevant to the Organization's activities and the expectations of interested parties, as well as to continuously improve the Quality Management System.
7.Supervision of the risks of processes covered by the Quality Management System is carried out in the IMS Risk Register, in accordance with the Risk Assessment Methodology and the risk management procedure.
8.Measurable objectives of the Quality Management System are specified in §5 of the IMS Book and are subject to review during the management review.
Information Security Policy
The Top Management, demonstrating appropriate commitment and aiming to ensure compliance with the implemented information security standards, in accordance with point 5.2 of PN-EN ISO/IEC 27001:2023-08, point 5 of PN-EN ISO/IEC 27017 and point 5 of PN-EN ISO/IEC 27018, adopts the Information Security Policy with the following content.
1.The Information Security Policy applies to the entire information system of the Organization, including information stored by the Organization and its clients in public computing clouds. The context of using cloud computing is specified in §1 section 4.
2.The Organization strives to ensure the security of information covered by the Information Security Management System at the highest level and to ensure compliance with all relevant legal requirements.
3.The Management Board takes the necessary steps to ensure appropriate protection of information assets - including personal data for which the Organization is the controller or processor - against all identified threats.
4.The risk assessment method, risk assessment criteria and risk management are described in the Risk Assessment Methodology and the risk management and asset inventory procedure. The risk analysis considers separately the loss of confidentiality, integrity and availability of information, taking into account the specificity of cloud services.
5.Information is protected adequate to its value, in accordance with the Information Classification Procedure. The list of safeguards used is included in the currently applicable Declaration of Application, which is reviewed at least once a year and after each risk analysis.
6.Access to classified and sensitive information is carried out in accordance with the need-to-know principle. Information processing measures are implemented with sufficient redundancy to meet accessibility requirements.
7.Security requirements regarding IT systems also apply to third parties and are reflected in the concluded contracts. Services provided by third parties are subject to regular monitoring and auditing.
8.Events and incidents in the field of information security are reported to the Management Board Representative for IMS or the Technical Director; the course of action is specified in the Incident Management Procedure.
9.Each team member is trained at least once a year on the principles and requirements of this Policy and related documents.
10.The Management Board is responsible for establishing and implementing the Information Security Policy. Its implementation is supervised by the Management Board Representative for IMS and the Technical Director. All staff members are responsible for its implementation in accordance with their duties and positions.
11.Measurable goals of the Information Security Management System are specified in §5 of the IMS Book.
Environmental Policy
1.The Top Management, appreciating the importance of pro-ecological activities, sets a course of action aimed at systematically striving to minimize the effects on the environment resulting from the Organization's activities in the field of design, implementation and servicing of IT systems, delivery and service of hardware, software and IT systems, implementation of IT projects, software design and production, as well as advisory and training activities.
2.The implemented Environmental Management System aims to:
- obtaining management support for environmental protection activities,
- formal declaration by the management of joining the implementation of the environmental protection program,
- defining ecological goals and planning their implementation,
- identifying risks and opportunities,
- informing and training employees,
- creating a continuous improvement system,
- assessing the effectiveness of functioning and documenting activities carried out,
- involvement of all employees of the Organization in the implementation of pro-ecological policy.
3.The Organization, within its capabilities and within the limits of the Environmental Management System, undertakes to prevent pollution caused by its activities and to meet relevant legal requirements in this respect.
4.The physical boundaries of the Environmental Management System include the premises of the Organization's headquarters and an external server room in which the Organization maintains its own computing infrastructure in a colocation model, in accordance with §1 section 3. Within the limits of collocation, the Organization supervises those environmental aspects over which it has influence - in particular the consumption of electricity by its own computing infrastructure, its energy efficiency and the handling of waste electrical and electronic equipment; The organization treats aspects that are under the control of the facility operator as aspects that it can influence and takes them into account in the requirements for the supplier.
Business Continuity Policy
1.In accordance with point 5.2.1 of PN-EN ISO 22301, the Top Management establishes and announces the Business Continuity Management System Policy with the content specified in this paragraph.
2.The organization operates in a narrow and difficult market; the systems it creates operate on highly sensitive data, the circulation of which often determines the proper functioning of key public institutions. Therefore, the organization ensures the continuity of services in order to maintain their high quality, adequate to the requirements and security of customer data.
3.The organization strives to create a stable workplace for its employees, functioning regardless of disruptions from the external or internal environment, as a condition for maintaining a permanent team responsible for software design and production.
4.The Top Management, acting through the Management Board Representative for IMS, will meet the applicable requirements of PN-EN ISO 22301 and adapt its activities to the relevant legal requirements.
Artificial Intelligence Management System (AIMS) Policy
1.In accordance with point 5.2 of ISO/IEC 42001:2023, the Top Management establishes the Artificial Intelligence Management System Policy, defining the target strategic direction and principles of artificial intelligence management in the Organization.
2.The AIMS Policy applies to:
- all AI systems designed, implemented, operated or maintained by the Organization,
- CDF methodology (Cognitive Deployment Framework) as a product and service provided to customers,
- products and development works of the SAIE ecosystem - TWIN:DESK, PROXY:AI, SAVANT-AI and GENESIS-AI - at all stages of their life cycle, subject to §1 section 5,
- all employees, collaborators and subcontractors acting on behalf of the Organization,
- the entire AI service supply chain - from concept to system retirement.
3.The organization adopts the following artificial intelligence management principles:
- responsible AI development and implementation - each AI system is built with accountability, transparency and security at every stage of its lifecycle,
- transparency - each artifact created with the participation of AI is marked with the AI-assisted tag in the task system, code repository, documents and internal communication,
- human supervision (human in command) - the level of supervision is adapted to the risk category and the level of system autonomy (LOA) in accordance with the CDF methodology; no AI artifact reaches the customer without human review,
- privacy and data protection - confidential and proprietary data is not transferred to external language models; personal data processed by AI systems are subject to impact assessment (DPIA),
- fairness and non-discrimination - The organization identifies and mitigates bias in AI systems; HR decisions cannot be made solely by AI,
- security of AI systems - The organization applies a security by design approach in all phases of the life cycle of AI systems; the use of unauthorized AI tools (Shadow AI) is prohibited.
4.The AIMS Policy refers in particular to ISO/IEC 42001:2023, ISO/IEC 27001:2023-08, ISO/IEC 23894:2023, Regulation (EU) 2024/1689 (EU AI Act), Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2022/2554 (DORA), Directive (EU) 2022/2555 (NIS2) together with the Act on the National Cybersecurity System and NIST AI RMF.
5.The Management Board declares full commitment to the implementation, maintenance and continuous improvement of AIMS, including ensuring compliance of the AIMS Policy with the strategic direction of the Organization as Sovereign AI Platform Company, integrating AIMS requirements with business processes and CDF product strategy, providing the necessary resources, appointing the Management Board Representative for IMS responsible for supervising AIMS and supporting the AI Council as the main decision-making body in AI matters.
6.Details of the rules set out in this paragraph are included in the AI Use Policy (AI-GOV_POL_AIUsage) and related documents.
Communication, availability and version control
1.The IMS policy is communicated to employees and understood within the Organization; constitutes the basis for setting the objectives of the IMS and assessing its ongoing usefulness.
2.The IMS Policy is made available to employees in the OneDrive electronic files and on the ISO information panel in the Organization's task system, and to interested parties - on the allclouds.pl website.
3.There is one approved content of the IMS Policy. The content published on allclouds.pl must be identical to the internal content and bear the version number and approval date. The Management Board Representative for IMS is responsible for the compliance of both contents.
4.The published content is updated within 7 business days from the approval of the new version by the Management Board.
Policy Review
1.The IMS Policy is reviewed at least once a year as part of a management review, and each time there is a significant change in the context of the Organization, the scope of certification, legal requirements or the results of risk analysis.
2.The review includes an assessment of the usefulness, adequacy and effectiveness of the Policy and its consistency with the objectives of the IMS and the IMS Risk Register.
3.Changes to the IMS Policy are approved by the Management Board by way of a resolution.
Final provisions
1.This Policy replaces the content of §4 of the IMS Book v6.1 (§4a–§4e) and the content of the IMS Policy previously published on allclouds.pl. Until the IMS Book v6.2 is issued, §4 of the IMS Book shall apply in the wording of this Policy.
2.The policy enters into force on the day of approval by the Management Board and remains valid until it is replaced by a new version.
3.In matters not regulated in this Policy, the provisions of the IMS Book and detailed IMS policies and procedures shall apply.