Information Security Policy

Information Security Policy

Executive summary of the Information Security Policy that governs the Information Security Management System (ISMS) operated by Oncode S.r.l. for the Onwork SaaS platform. The policy is consistent with ISO/IEC 27001 and supporting standards (27002, 27017, 27018, 27701).

Version
v1.0
Effective
2026-04-25
Download PDF

Purpose

The purpose of this policy is to protect the confidentiality, integrity and availability of information assets entrusted to Oncode S.r.l. by its customers, employees and partners; comply with applicable laws and regulations; and continuously improve the ISMS.

Scope

The ISMS covers the design, development, operation, maintenance and support of the Onwork SaaS platform, including all related infrastructure, processes, personnel and third parties operating on behalf of Oncode S.r.l.

Governance and roles

  • Top Management approves the policy and allocates resources.
  • CISO / ISMS Manager oversees implementation and effectiveness.
  • DPO ensures GDPR compliance and acts as the point of contact with the supervisory authority.
  • Asset owners are accountable for the protection of specific information assets.

Risk management

Risk assessments are conducted at least annually and whenever significant changes occur. Risks are documented in the ISMS Risk Register; treatment plans (avoid, mitigate, transfer, accept) are approved by Top Management.

Information classification and handling

Information is classified as Public, Internal, Confidential or Restricted, and handled according to documented procedures (storage, transmission, disposal). Customer Data is treated as Confidential by default; sensitive subsets are handled as Restricted.

Access control

Access is granted on a least-privilege, need-to-know basis, reviewed quarterly. Strong authentication and MFA are enforced for privileged access. Joiner-mover-leaver processes ensure timely provisioning and de-provisioning.

Physical and environmental security

Production infrastructure runs on AWS, which provides ISO 27001-certified data centres with strict physical security controls. Office premises follow the Oncode access-control policy.

Operations security

  • Documented change management with peer review.
  • Patching and vulnerability management with SLAs.
  • Centralised logging and continuous monitoring.
  • Capacity and availability planning.

Communications security

Encryption in transit and at rest, network segmentation, firewalls and Web Application Firewall (WAF) protect data flows. Remote access uses VPN with MFA.

System acquisition, development and maintenance

Secure SDLC controls include security requirements, secure coding practices, code review, SAST/DAST, dependency scanning, and threat modelling for major changes. Production deployments are gated by automated tests and security checks.

Supplier relationships

Suppliers are assessed against security and privacy criteria before engagement and reviewed annually. Contracts include confidentiality, security and DPA obligations. The list of sub-processors is published at /sub-processors.

Incident management

Documented incident-response procedures with severity tiers, on-call coverage, internal communication channels, evidence preservation and post-mortems. Personal data breaches are notified to controllers within 24 hours.

Business continuity

Business continuity and disaster recovery plans are maintained and tested annually. Recovery objectives: RPO 24h / RTO 4h.

Compliance

Compliance with applicable laws and contractual obligations is monitored, including GDPR, Italian Privacy Code, NIS2, cybersecurity laws and intellectual property rights. Internal audits are performed at least annually.

Policy review

This policy is reviewed at least annually and whenever significant changes occur in the business, threat landscape or regulatory environment. The full ISMS documentation is available to customers under NDA on request.