At PropCo, we recognise that information which is generated internally, generated externally, or circulates within our organisations is an important business asset of significant value to the company and needs to be protected. This statement sets out top management’s commitment to protecting that information, and to the Information Security Management System (ISMS) through which we do so.
Scope and Applicable Standard
The ISMS is certified to ISO/IEC 27001:2022. From 2025 onward, PropCo maintains certification to ISO/IEC 27001:2022 only. Where quality practices consistent with ISO 9001:2015 continue to be applied, they are operated as internal good practice.
The boundaries and applicability of the ISMS, including the entities, locations, services and exclusions in scope, are defined in Scope of the ISMS in Information Security Management System. This statement is to be read alongside that document.
Information Security Objectives
This policy provides the framework for setting, monitoring, reviewing and achieving our information security objectives. Those objectives are established, measured and maintained in Security Objectives Plan in Information Security Management System (ISMS), and are reviewed at management review in line with Procedure for Management Review in Information Security Management System (ISMS)
The objectives this policy exists to support are:
- To preserve the confidentiality, integrity and availability of all physical, electronic, information and associated assets held throughout the company;
- To identify, assess and treat information security risks in line with Risk Assessment and Risk Treatment Process in Information Security Management System (ISMS)
- To meet all regulatory, legislative and contractual requirements relating to information security, as recorded in Relevant Laws, Regulations and Contractual Requirements in Information Security Management System (ISMS)
- To protect the personal data we hold and process in accordance with applicable data protection law;
- To deliver reliable, high-quality products and services to our customers, delivered securely and to specification;
- To continually improve the suitability, adequacy and effectiveness of the ISMS.
We are committed to:
- Satisfying all applicable requirements related to information security, including legal, regulatory, statutory and contractual obligations, and all applicable codes of practice;
- The continual improvement of the Information Security Management System, informed by risk, audit results, incidents, nonconformities and management review;
- Meeting and, wherever possible, exceeding the expectations of our customers, stakeholders and other interested parties;
- Providing the resources, equipment, competence and training necessary for the ISMS to achieve its intended outcomes;
- Ensuring that all employees and contractors are made aware of their individual obligations under this policy and of the implications of not conforming to ISMS requirements;
- Conducting our business in an ethical and professional manner, and upholding a strong ethical standard in all business and professional dealings;
- Fostering communication between everyone involved in the organisation, and admitting and rectifying mistakes as quickly as possible where they occur;
- Providing opportunities for all employees to develop their skills and talents to the extent that they wish.

