Integrated Quality and Information Security Management System (IMS)
QUALITY, INFORMATION SECURITY AND DATA POLICY
| Versione Data | Changelog |
| 1.0 24/09/2025 | Initial Release |
Prepared and verified by: Cristoforo Sabatino (Security & Compliance Manager)
Approved by: Marco Baffi (CEO of Mizar Tech & IMS Manager)
Original approval date: 24/09/2025
Document classification: External or public use
1. Introduction
Mizar Tech (a company of the MSA Mizar S.p.A. Group) defines its quality, information security and personal data policy in compliance with ISO/IEC 27001 and Regulation (EU) 2016/679 (GDPR), in order to ensure data protection and regulatory compliance, and in compliance with ISO 9001, in order to ensure appropriate quality levels in business processes and the services provided.
2. Scope
This policy derives from the information security policy of the parent company MSA Mizar S.p.A. and also incorporates quality aspects. It applies exclusively to the subsidiary Mizar Tech.
MSA Mizar ensures that all Group companies, including Mizar Tech, adopt an appropriate level of protection for the personal data processed, including within Cloud services provided to third parties, both as Data Controller and Data Processor, in full compliance with the GDPR.
3. Quality, Information Security and Data Policy
Mizar Tech bases its policy on the principles of maximum functionality, effectiveness and efficiency. The protection of information security and personal data, together with the quality of processes and services provided, is regarded as a fundamental principle for safeguarding all stakeholders and customers of SaaS cloud services, whether companies or individuals.
Achieving appropriate levels of quality and security in business processes also enables Mizar Tech to mitigate and counter losses and damage that may affect people, the company image and reputation, and economic and financial matters, while ensuring compliance with the applicable contractual and legislative framework governing the protection of information and personal data.
Security is integrated into business processes and applications from the design stage, in accordance with the principles of “Security by Design and Default” and “Privacy by Design and Default”.
Mizar Tech also promotes transparency in operational processes, simplifies procedures and ensures easy access for customers and suppliers, while maintaining appropriate quality levels and respecting information security requirements.
3.1 Management Commitments - Objectives
With regard to the Quality Management System, Management undertakes to:
- Adopt and implement recognised principles and good practices to ensure the quality of business processes and services provided.
- Establish a Quality Management System, integrated with information security, ensuring compliance with ISO 9001:2015 requirements and customers’ right to the best possible service based on quality processes.
- Identify roles and responsibilities to be assigned to personnel, regardless of hierarchical level, also involving any third parties performing key duties.
- Allocate the resources required to ensure the use of appropriate measures for the quality of internal processes and customer services.
- Continuously promote the Integrated Management System, including through the ongoing commitment of governing bodies and senior management.
- Identify, document and apply rules governing service delivery in accordance with ethical principles and continuous improvement.
- Develop an awareness programme for personnel through periodic information and training sessions.
- Establish appropriate response and management measures for events that may compromise the quality of business processes and services offered to customers.
- Maintain compliance with contractual, legislative and regulatory requirements in both internal processes and customer-related activities.
- Select suppliers and promote their development in accordance with the principles of this policy, requiring them to maintain conduct consistent with those principles.
- Commit to the continuous improvement and evolution of the Integrated Management System by continuously planning, implementing, verifying and applying measures and safeguards designed to counter potential events that could compromise quality in customer processes and services, in the most environmentally sustainable manner possible.
In merito alla Sicurezza delle informazioni, la Direzione si impegna a:
- With regard to Information Security, Management undertakes to:
- Adopt and implement recognised principles and best practices, as well as security measures, to protect information from breaches, theft and fraud, and promote the achievement of certifications against applicable standards.
- Protect information relating to customers, companies, employees and citizens by ensuring confidentiality, integrity and availability.
- Ensure appropriate access to information and prevent unauthorised access.
- Define and implement security measures to prevent breaches, misuse and fraud.
- Protect personal data from unauthorised access or alteration, safeguarding data subjects’ rights in accordance with the Accountability principle under Article 5(2) of the GDPR.
- Establish internal and external information security roles and responsibilities, also involving any third parties performing key duties.
- Support employees and business partners through appropriate education and training to raise cybersecurity awareness and minimise risks.
- Establish appropriate response and management measures for incidents that may compromise information security and normal operations.
- Ensure the continuity of information security in adverse scenarios or when a threat materialises.
- Train and raise awareness among personnel to reduce risks.
- Ensure business continuity in the event of crises or disasters.
- Continuously promote the Information Security Management System, including through the ongoing commitment of governing bodies and senior management.
- Meet the requirements of ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018, as well as contractual, legislative and regulatory provisions concerning Cybersecurity & Resilience.
- Maintain the Information Security Management System for Cloud activities in compliance with ISO/IEC 27017:2015 and ISO/IEC 27018:2019, ensuring ongoing conformity with their requirements.
- Continuously monitor capacity management in the production environment to prevent overload from causing system collapse, business interruptions and unplanned downtime.
- Ensure the proper management process, whether recycling or disposal, of digital information media containing company data, in order to prevent the loss of data and sensitive information.
Consistently promote the continual improvement of information security processes, controls and practices to ensure full compliance with international information security standards and effectively protect company data and information assets, in the most environmentally sustainable manner possible.
With regard to Cloud Service Provider (CSP) services, Mizar Tech operates as a Software as a Service (SaaS) provider, as it delivers claims management services on behalf of its customers, primarily various insurance companies.
Mizar Tech does not qualify as a Cloud Service Customer (CSC) under ISO/IEC 27017, as it uses only a standard colocation, or housing, service offered by a global CSP. Colocation does not fall within the scope of cloud services as defined by the standard (IaaS, PaaS, SaaS), because it consists solely of renting physical space and connectivity, without the provision of virtualised or on-demand scalable resources. Therefore, classifying the organisation as a CSC would be inappropriate and unnecessary, since it neither directly uses managed cloud services nor customises or administers cloud infrastructure provided by the CSP.
- As a provider of Cloud SaaS services, Mizar Tech:
- Has assessed the applicable baseline quality and security requirements for the design, development and implementation (activation) of cloud services;
- Assesses all information security risks relating to the provision of SaaS services to customers as part of the annual risk assessment cycle within the ISO/IEC 27001 management system;
- Has assessed the risk arising from the activities of its internal personnel in managing customer information processed in the Cloud;
- Has ensured that each customer can access only its own data and cannot physically access the machines on which the data is processed. For requests concerning its data, the customer may contact the Organisation using the communication methods formalised in the contract;
- Has ensured that the virtualisation system is secure in accordance with market best practices;
- Allows customers, through specific authentication methods, to access data uploaded to the SaaS service while ensuring segregation of information between customers;
- Ensures a lifecycle for the credentials of users of the SaaS service, promptly removing any access that is no longer required, for example following non-renewal of the contract. Ensures that any data breaches that may occur, potentially involving personal data, are promptly managed and that a protocol is defined for reporting the event to the competent authorities;
- Has a specific written procedure for managing information security incidents. The Customer must verify whether the allocation of responsibilities for information security incident management is appropriate and ensure that it meets its requirements. If an incident results in the loss of one or more characteristics among Confidentiality, Integrity, Availability and Authenticity concerning personal information (Data Protection), the Party identifying the incident must immediately notify the other Party.
3.2 Implementation of the Integrated Quality and Information Security Management System (IMS)
Mizar Tech’s integrated quality and information security management system includes all policies, objectives and procedures required to achieve the quality and security objectives set out in the preceding section. It covers all operational, administrative and support activities.
Compliance with this policy is mandatory for employees, suppliers, contractors and third parties that perform processes, provide services and process information for and on behalf of Mizar Tech.
Company Management recognises that process and service quality and information security require human and organisational resources and undertakes to provide the means necessary for the continual improvement of the system.
3.3 Related Policies and Document Protection
Mizar Tech has defined, approved and communicated a set of information security policies, available upon request and published on the Company Intranet and corporate website.
4. Review
This policy is subject to periodic review and/or review following significant changes, in order to ensure its continuing suitability, adequacy and effectiveness.
08 Settembre 2026