Information security policy

How we protect our information from threats and accidental damage.

Is it for you? 

It's for all employees.

Key points

  • The purpose of this policy is the protection of the confidentiality, integrity and availability of Barnardo’s information assets from threats, deliberate or accidental, internal or external. 
  • Barnardo’s uses ISO27001 principles to manage information security.
  • The policy describes a number of key actions and outcomes that need to be in place to make sure data is secure, including having data accessible only to people inside our organisation.
  • All breaches of information security and suspected weaknesses must be reported and investigated.

Your responsibilities

  • It is the responsibility of all employees to comply with this policy. 
  • The Trustees of Barnardo’s are legally responsible for information security. 
  • The Director of Information Services is accountable for ensuring that cost-effective security and legal controls are implemented that are appropriately matched with identified risks. They are supported in this task by the Information Security Officer, Managers and other users of our IT Systems. 
  • The Information Security Officer has the role and responsibility for managing information security at an operational level.  The Information Security Officer is responsible for maintaining the policy, providing advice and guidance on all matters related to the policy, reporting on and ensuring the information security management system is maintained and continually improved.
  • All managers are directly responsible for implementing the policy within their operational areas, and for adherence by staff they are responsible for. 
Published
31 January 2019
Latest update
18 August 2023
  1. 18 August 2023
    Added the latest Information Security policy
  2. 23 June 2022
    Added the latest Information Security policy
  3. 1 February 2021
    Added the latest Information Security policy
  4. 28 August 2020
    Added the latest Information Security policy
  5. 8 April 2020
    Added the latest Information Security policy
  6. 31 January 2019
    First published