- Home
- Information Security Management System Policy
Information Security Management System Policy
At ONE, we are committed to protecting the confidentiality, integrity, and availability of all information entrusted to us. Our Information Security Management System (ISMS) is built on the principles of ISO/IEC 27001:2022 and the TISAX ISA 6.0.3 framework, supporting secure and reliable operations for our customers, partners, and employees.
Our Commitment
• Information security is embedded into core ONE business processes in Hamburg.
• Leadership ensures the ISMS is adequately resourced, effective, and continually improved.
• We adhere to applicable legal, regulatory, and contractual information security requirements.
How ONE Protects Information
• We proactively identify, assess, and treat information security risks.
• Strong technical and organizational controls safeguard sensitive and confidential information.
• All employees and relevant partners follow established security policies and complete regular security awareness training.
• Security incidents are managed through a structured detection, response, and recovery process to minimize impact and maintain trust.
Scope of Our ISMS
ONE ISMS covers all information assets, IT systems, business processes, employees, and third-party providers involved in processing or handling company and customer information in Hamburg.
Continuous Improvement
We regularly conduct audits, assessments, and management reviews to ensure our ISMS remains effective, resilient, and aligned with evolving business needs and security requirements.