1. Purpose
This Information Security Statement provides a high-level overview of the principles and measures implemented to protect the information and services provided through IIS NEPPS.
2. Scope
This Statement applies to the NEPPS Portal and to the electronic services provided through IIS NEPPS.
3. Information Security Principles
The protection of information is based on the principles of:
- Confidentiality;
- Integrity;
- Availability;
as well as on appropriate access control and accountability measures.
4. Security Governance
Administrative, organisational and technical security measures are implemented and are periodically reviewed on the basis of risk assessments and the applicable legal and regulatory framework.
5. Security Measures
IIS NEPPS implements appropriate user authentication, account management and access control mechanisms.
In addition, procedures are in place for:
- logging security events and selected system activities;
- performing regular data backups;
- protecting the underlying information and communication technology infrastructure; and
- detecting and responding to malicious activities,
in accordance with the security requirements of IIS NEPPS and the applicable legal and regulatory framework.
6. Security Incident Management
Procedures are in place for the identification, assessment, response to and recording of security incidents.
Security incidents are managed in accordance with established operational procedures, with the objective of minimizing their impact on the confidentiality, integrity and availability of the information and services provided through IIS NEPPS.
7. Business Continuity
Backup and data restoration procedures are implemented to protect information and support the continuous and reliable operation of IIS NEPPS.
These measures are intended to facilitate the recovery of information following operational disruptions or technical failures.
8. Personal Data Protection
Personal data processed through IIS NEPPS are handled in accordance with the General Data Protection Regulation (GDPR) and the IIS NEPPS Privacy Policy.
9. User Responsibilities
Users are responsible for safeguarding their authentication credentials and for reporting any suspected security incident or unauthorised use of their account through the IIS NEPPS Help Centre ticketing system.
10. Responsible Vulnerability Disclosure
Potential security vulnerabilities affecting IIS NEPPS may be reported responsibly through the IIS NEPPS Help Centre ticketing system.
Reports shall be submitted in good faith and shall not involve activities that could adversely affect the security, integrity or availability of the system.
11. Review and Update
This Information Security Statement shall be reviewed and updated whenever necessary.
The most recent version shall be published on the NEPPS Portal.