Information Security Policies of Entaksi Solutions SpA

Entaksi places the utmost importance on protecting its clients’ data. The following is the Information Security Policy, a set of rules and procedures adopted by the company to safeguard the protection of processed data.
The company’s overall objective is the proper management of all information generated or processed, ensuring business continuity and preventing or minimizing potential damage. To achieve this goal, Entaksi uses an Integrated Management System (IMS) that fully covers the company’s operations while ensuring information security.
The IMS includes the design, production, marketing, installation, and support of software applications, as well as the provision of IT services such as Software as a Service (SaaS) distribution.
Information
Information protection and security policies must safeguard three fundamental aspects of data:
  • Confidentiality: access to data must be limited according to user privileges, aligned with their classification level, and information must be protected against unauthorized access.
  • Integrity: information must be complete and accurate. All systems, assets, and networks must operate correctly according to specifications that ensure full functionality.
  • Availability: information must be accessible and distributable to authorized users according to its classification level.
All information processed by Entaksi in the exercise of its functions is classified based on its content and managed according to its assigned classification. Information is protected, managed, and made available according to permitted uses. Entaksi periodically conducts a risk analysis to assess information asset risk treatment and adjusts its system according to the results.
Roles and Responsibilities
All Entaksi personnel involved in the creation or management of information are responsible for its correct classification and handling and receive appropriate and ongoing training in this regard.
Defined roles and responsibilities exist within the company to ensure the maintenance and proper operation of the Integrated Management System and the achievement of security objectives.
External parties who come into contact with data managed by Entaksi are defined through service contracts and are required to sign a confidentiality agreement.
Business Continuity
The ISO/IEC 22301:2019 standard establishes the requirements necessary for the correct implementation of a Business Continuity Management System (BCMS). Entaksi has adopted this international standard to ensure the continuity of its IT services.
Entaksi implements the technical and organizational measures necessary to maintain an adequate level of security for business continuity and periodically updates its strategies and procedures to ensure their ongoing effectiveness.
Continuous monitoring of system performance and selected parameters is central to the implementation of this management system. Management continuously reviews company objectives through a specific Business Process Impact Analysis and periodic risk assessments. Objectives such as resource planning, consistent compliance with requirements, and consideration of stakeholder needs are considered fundamental to the company.
Incident Management
Proper management of IT incidents is considered a fundamental requirement for IT service security.
A simple response to an incident is not sufficient to guarantee complete information protection. For this reason, Entaksi has adopted a structured approach to incident management, aligning its Integrated Management System with ISO/IEC 27035:2016 for information security incident management.
The framework includes a strategic level of incident management planning, with a dedicated and specially trained Incident Response Team (IRT).
Procedures pay particular attention to response activities and communication points between the company and clients, improving not only prevention but also reaction phases. In particular, potential damage involving personal data (data breaches) is managed with the utmost transparency.
Data Protection
Entaksi maintains its Integrated Management System in compliance with the General Data Protection Regulation (GDPR) of the European Union No. 2016/679.
For more information regarding data processing, please consult the Privacy Policy.
Compliance
This policy is periodically reviewed and constantly updated in response to new threats, technological advancements, and the resolution of known issues. It is also compliant with the standards for which Entaksi has obtained certifications, as described on the dedicated page.
Regarding information security in particular, the IMS complies with the controls established by ISO 27001:2013 and its extensions ISO/IEC 27017:2015 and ISO/IEC 27018:2019, as well as data protection regulations, including in particular
Switch The Language