SAAED for Traffic Systems (hereinafter referred to as “SAAED“) recognizes that information is a vital asset that must be protected to support the organization’s mission and achieve its strategic objectives. SAAED acknowledges that information security is an ongoing commitment requiring proactive measures to safeguard against evolving threats. Accordingly, SAAED has adopted an Information Security Management System (ISMS) with the following defined objectives:
- Protect SAAED’s information and information assets.
- Comply with legal and regulatory requirements related to information security.
- Maintain business resilience.
To fulfill this commitment, SAAED’s management is fully committed to:
- Protect the confidentiality, integrity, and availability of its information and information systems.
- Implement a robust Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022.
- Ensure compliance with all applicable:
- Legal and regulatory requirements.
- Contractual obligations in terms of information security.
- Internal policies and procedures related to information security.
- Identify, assess, and manage information security risks using a structured risk management framework.
- Develop enforceable information security policies, standards, and procedures using a risk-based approach for addressing all applicable controls.
- Define measurable objectives and conduct regular monitoring and analysis to assess performance.
- Enforce accountability by clearly defining and assigning roles and responsibilities for managing information security.
- Allocate adequate resources for the effective operation of the ISMS.
- Promote a culture of security awareness through training and communication.
- Continuously improve the ISMS through regular reviews, audits, and corrective actions.
- Review information security policies, standards, and related documents at least annually or upon significant changes to ensure relevance and effectiveness.