From efc1d08b6b6e3a0c4400d04a02124e56a1fdbf5c Mon Sep 17 00:00:00 2001 From: Roman Dolinovskyi Date: Wed, 30 Sep 2026 13:11:15 +0300 Subject: [PATCH] [CN-68569] renew information security policy --- src/content/docs/docs/security-policy.mdx | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/src/content/docs/docs/security-policy.mdx b/src/content/docs/docs/security-policy.mdx index d93d74250..1cc91d9b5 100644 --- a/src/content/docs/docs/security-policy.mdx +++ b/src/content/docs/docs/security-policy.mdx @@ -7,7 +7,7 @@ template: splash Crowdin Information Security Policy (hereinafter the Policy) defines the objectives and basic principles of information security. Information security means implementation and maintenance of the appropriate level of its properties. -The Policies requirements apply to the entire Crowdin organization and all business processes, and are available mandatory for all Personnel as well as those involved in these business processes. Compliance with the requirements of the Policy is an important aspect for achieving Crowdin's strategic goals and objectives. +The Policy's requirements apply to the entire Crowdin organization and all business processes, and are mandatory for all Personnel as well as those involved in these business processes. This Policy is maintained as documented information, communicated to all Personnel and those involved in Crowdin's business processes, and made available to interested parties as appropriate. Compliance with the requirements of the Policy is an important aspect for achieving Crowdin's strategic goals and objectives. Crowdin information security policy meets the requirements of ISO / IEC 27001: 2022. @@ -42,7 +42,7 @@ Policies have been set by the organization in a variety of areas and these must The main relevant policies are: - Business Continuity Plan - Information Security Management Framework -- Risk Assessment and Treatment Methodology +- Risk Assessment and Treatment Methodology - Incident Response Plan - Acceptable Use Policy - Access Control Policy @@ -62,7 +62,7 @@ The main relevant policies are: - Segregation of Duties Policy - Supplier Relationship Security Policy - Workstation Security Policy -- Сhange Management Policy +- Change Management Policy - Communication Procedure - Corrective and Preventive Actions Procedure - Disciplinary procedure @@ -75,6 +75,7 @@ The main relevant policies are: - Security in Customer Support Policy - Competitive Intelligence Ethics Policy - Remote Work Policy +- Contract Policy ## Internal and external issues @@ -101,10 +102,13 @@ External issues: - Supporting technologies and infrastructure - Automation and artificial intelligence - Military conflicts and political changes +- Climate change and extreme weather events - etc. These general internal and external issues will be considered in more detail as part of the risk assessment process and will be regularly reviewed and monitored. +Crowdin has determined that climate change is a relevant issue for the ISMS, with an indirect impact. Crowdin's services are delivered from cloud infrastructure, so the direct exposure of information assets to climate-related events is limited. The relevant impacts are extreme weather events, power supply disruptions affecting offices and personnel, and the resilience of cloud and other key suppliers. These impacts are addressed through the information security risk assessment and the Business Continuity Plan, and are reviewed as part of the regular review of the organization's context. + ## The interested parties that are relevant to the ISMS of Crowdin have been determined below with their individual expectations. An interested party is defined as a person or organization that can affect, be affected by, or perceive themselves to be affected by a decision or activity. @@ -139,6 +143,10 @@ The following are defined as interested parties that are relevant to the ISMS: | Auditors | Expect that a proportionate level of security controls are in place at all times to protect assets | Documentary and practical confirmation of the implementation of ISMS | | Emergency Services | Safe working environment etc. | Fire Safety, First aid provision etc. | +The requirements listed above are addressed through the ISMS to the extent that they relate to information security: the confidentiality, integrity and availability of information, and compliance with legal, regulatory and contractual requirements identified in the ISMS Scope. Financial, commercial and employment-related requirements, such as return on capital or investment, payment terms, remuneration and social benefits, and market monitoring, are managed through Crowdin's general business processes and are outside the scope of the ISMS. + +Climate-related requirements of interested parties have been considered. Where such requirements relate to information security, in particular the availability and continuity of services, they are covered by the expectations and requirements listed above. Other sustainability requirements, such as sustainability reporting, are outside the scope of the ISMS. + ## Information security objectives: - Ensure compliance with the requirements of ISO / IEC 27001: 2022 which will allow Crowdin to be a certified company and trusted supplier for its customers. Ensure compliance with relevant laws, regulations (legislation of Estonia, Ukraine), contractual agreements, and organizational policies related to information security. @@ -158,7 +166,7 @@ This strategic objectives are supported by annual KPIs, described in more detail ## What will be done -Current policies, processes, and security measures will be continuously reviewed. Any gaps in alignment with ISO/IEC 27001:2022 standards will be identified and addressed. +Crowdin's management commits to satisfying applicable information security requirements and to the continual improvement of the ISMS. Current policies, processes, and security measures will be continuously reviewed. Any gaps in alignment with ISO/IEC 27001:2022 standards will be identified and addressed. A proactive risk management strategy will be maintained. This strategy includes conducting regular risk assessments, vulnerability scans, and security audits. Identified risks will be analyzed, and continuous mitigation measures will be implemented.