Last reviewed: 2026
Integrated Management System Policy
Olla Systems Limited is committed to maintaining and improving information security and business continuity processes by adopting an integrated management system. This provides a framework for integration of the ISO 27001:2022, ISO 27017:2015, and ISO 22301:2019 standards.
Our Core Values for the Integrated Management System
The company defines our core values for Integrated Management System as follows:
- To ensure uninterrupted availability of all key business resources required to support essential (or critical) business activities.
- To reduce the number of information security, and business continuity high priority risks on Olla Systems Limited's risk register.
- To ensure confidentiality of data stored, processed, or transmitted in cloud environments through encryption and controlled access.
- To secure cloud APIs, interfaces, and integrations to prevent unauthorized access, data leakage, or manipulation.
- To manage and protect cloud assets through lifecycle management, secure provisioning, configuration, and decommissioning.
- To ensure availability of cloud services and data through resilient architecture, backups, disaster recovery, and redundancy controls.
- To enforce strong identity and access management (IAM) to control user access, authentication, authorization, and privilege usage within cloud systems.
- To ensure compliance with ISO 27001, GDPR, NDPR, PCI DSS, and other regulatory and contractual obligations applicable to cloud operations.
- To provide an orderly and expedited recovery/continuity of critical business processes after a disruptive incident.
- To reduce or avoid information security breaches and related loss.
- To ensure compliance with Olla Systems Limited's contractual, regulatory, and legal requirements and reduce information security related regulatory sanctions/penalties.
- To ensure information collected, held, and used by the organization is appropriately protected and available in line with business requirements.
- To improve information security culture and consciousness in the organization.
- To provide training in information security, cloud security and business continuity for key resources.
- To create awareness among all staff of the needs and responsibilities of Information Security, Cloud Security & Business Continuity Management System.
- To ensure that the confidentiality, integrity and availability of information is maintained throughout business functions and processes.
- To ensure information is only accessible to authorized persons from within or outside the company, and to minimize damage by preventing and reducing the impact of security incidents.
- To ensure that all employees are aware of their individual service delivery obligations.
- To ensure continual improvement of our Information Security, Cloud Security & Business Continuity Management System.
Review & Communication
The Integrated Management System policy, objectives and targets will be reviewed annually (or sooner if necessary) by Top Management. This policy statement is communicated to all employees and persons working for or on behalf of the company, and will be made available to the public, stakeholders, and any other interested parties on request.