Information Security PolicyMarketing Lama GmbH
Version 1.2
Date: 23 April 2026
Document owner: Management
Approved by: Management1. PurposeThis policy defines the strategic and organisational principles for ensuring the confidentiality, integrity and availability of information.It forms the basis of the information security management system (ISMS) in accordance with ISO/IEC 27001.The aims are:protection of company and customer datacompliance with legal and contractual requirementsreduction of information security risksassurance of business continuitybuilding a lasting security culture2. ScopeThis policy applies to:all business unitsall employeesexternal service providersall IT systemscloud infrastructuredevelopment, test and production environmentspersonal and business-critical data3. Security objectivesThe organisation pursues the following information security objectives:protection against unauthorised accessprotection against data loss or manipulationminimisation of system outagesassurance of legal compliancecontinuous improvement of the security levelSecurity objectives are reviewed regularly and adjusted where necessary.4. Embedding in the ISMSInformation security is managed systematically through:a risk-based approachdocumented processesregular review of the effectiveness of measurescontinuous improvement following the PDCA principleRisks are identified, assessed and treated.5. Governance & accountabilityManagement bears overall responsibility for information security.Security responsibilities are defined and documented.All employees are obliged to comply with security requirements.This policy is reviewed at least once a year.6. Access controlAccess follows the need-to-know and least-privilege principlesIndividual user accountsNo shared accountsMulti-factor authentication for privileged accessRegular review of permissionsUse of secure password management mechanismsAccess to personal data takes place solely where there is a business need.7. Infrastructure & network securityOperation in controlled cloud environmentsPreference for European regionsLogical network segmentationSeparation of development, test and production environmentsAccess control via firewalls and security group rulesNo publicly reachable administration interfacesEncryption of data in transitEncrypted storage of sensitive dataLogging of security-relevant eventsIn addition, security-relevant network events are monitored continuously.Cloud-native monitoring and alerting mechanisms are used to detect and prevent unauthorised access, unusual activity or potential network threats at an early stage.8. Endpoint securitySecurity updates enabledMalware protectionSystem firewall enabledScreen lock on inactivityPassword-protected or biometrically protected devicesServer systems are operated in a hardened state, including:restricted access rightsSSH key authenticationminimisation of open portsAn up-to-date endpoint protection or anti-malware solution is installed and active on all company-relevant devices.Virus definitions and security updates are applied automatically.8a. Security baselineThe following minimum requirements apply to ensure secure day-to-day operations:mandatory screen lock on inactivityuse of complex, individual passwordsuse of multi-factor authentication for security-relevant systemsa clean desk principle to prevent unauthorised viewingno sharing of access credentialsThese minimum requirements are binding for all employees.9. Secure software developmentSeparation of development, test and production environmentsNo storage of secrets in the code repositoryCode reviews before deploymentRegular updating of dependenciesLogging of security-relevant eventsSecurity requirements are taken into account as early as the design phase10. Data classificationInformation is assigned to the following protection levels:publicinternalconfidentialparticularly sensitiveProtective measures follow the respective classification.The classification determines which protective measures apply.
For example:Confidential and particularly sensitive data are transmitted in encrypted form.Particularly sensitive data are additionally stored in encrypted form.Access to confidential data is logged.11. Data securityMinimisation of personal dataGDPR-compliant processingEncrypted backupsDocumented deletion conceptsProtection against unauthorised access12. Monitoring & loggingLogging of security-relevant eventsTraceable documentation of administrative actionsRegular review of log dataDetection of unusual activity13. Vulnerability managementRegular security updatesAssessment of technical vulnerabilitiesPrioritised remediation of identified risksReduction of the external attack surfaceDetails are set out in the vulnerability and threat management policy.14. Incident managementSecurity incidents are handled in accordance with the incident management policy.This covers:identificationassessmentisolationdocumentationexternal notification where requiredfollow-up15. Third-party and supply chain managementSelection of trustworthy providersReview of security standardsContractual arrangements (e.g. data processing agreements)Risk-based assessment of external dependencies16. Training and awarenessEmployees receive regular training on information security requirements.Training is documented.17. Continuous improvementThe effectiveness of the ISMS is reviewed regularly.Findings from:security incidentsinternal reviewsvulnerability analyseslead to improvement measures.18. Entry into forceThis policy takes effect on publication and is binding for all persons concerned. This English text is a convenience translation; the German version is the authoritative one.