Security Policy
Standards implemented
- PN-EN ISO/IEC 27001:2023-08E
- PN-EN ISO/IEC 27002:2023-01E
- PN-EN ISO 22301:2020-04P
- PN-EN ISO 9001:2015 (Quality Management System)
BackOffice Outsourcing Sp. z o.o. ensures the high quality of the outsourcing services provided and ensuring the highest standards of information security and business continuity. Our activities are based on international ISO standards, modern IT solutions and internal procedures consistent with the current legal and technological status.
The implemented and consistently implemented Company Security Policy meets the requirements specified in:
- Personal Data Protection Act,
- GDPR Regulation (EU 2016/679),
- Act on the national cybersecurity system,
- Act on the provision of electronic services,
- and industry regulations relating to postal services and customer data processing.
Main areas of implementation of the Security Policy
- Contingency plans (business continuity & disaster recovery):
Ensuring business continuity and uninterrupted operations at the Company's headquarters and at its contractors. This includes incident response procedures, backup scenarios, recovery procedures and recovery test schedules. - IT systems management:
- Internal security policies,
- Access management (minimum privilege, IDs, login and activity tracking),
- Physical and logical security (firewalls, encryption, anti-virus scanners, system integrity monitoring).
- Personal data protection:
- Fulfillment of data administrator obligations in accordance with GDPR,
- Log of processing activities,
- Data protection training,
- Procedures for data protection violations and reporting to the Personal Data Protection Office.
- Quality Management System compliant with ISO 9001:2015:
The company has implemented and certified a QMS that provides a systematic approach to process management, risk analysis and continuous improvement. This includes, but is not limited to:- mapping and optimization of operational processes,
- control of documentation and information flow,
- internal audits,
- cyclical management reviews,
- mechanisms for responding to complaints and non-conformities.
- Employee training:
Training in the field of information security, personal data protection, ISO compliance and incident response are organized periodically, and their course and results are recorded. - Risk management:
We use methodologies to identify, analyze and assess operational, technological and legal risks. Each area of activity is subject to a risk assessment, which is documented and updated. - Office and physical records protection:
- Access control to rooms (entrance control systems, monitoring, entry/exit registration),
- Alarm systems,
- Registration of incoming and outgoing documents in the COK system (cok.com.pl),
- Archiving scans on secure servers,
- Restricted access zones for sensitive data and paper records.
Integrated approach
BackOffice Outsourcing pursues a consistent security, quality and business continuity policy, fully integrated with the process management and regulatory compliance system. The implemented standards ISO 27001, ISO 22301, ISO 9001 and ISO 27002 create the foundation for professional and auditable management in the Company. Thanks to this, we guarantee our clients, partners and stakeholders:
- assurance of data confidentiality, integrity and availability,
- organizational resilience in crisis situations,
- quality and repeatability of services provided,
- transparency and legal compliance.