Quality & Information Security Policy Applicability

 

The quality &security policies and standards in this document apply to all information, data, software, hardware, and networks used within Softweb Technologies Pvt. Ltd. These policies also extend to companies, entities, and business units that align with core and support processes in the manufacturing of mining and allied machinery. Specifically, the information security policy covers the following information assets of Softweb Technologies Pvt. Ltd.:

  • All proprietary information that belongs to Softweb Technologies Pvt. Ltd.
  • All client/customer information 
  • All supplier, contractor and other third-party information 
  • All software assets such as application software, system software, design tools and utilities
  • All physical assets such as computer equipment, communication equipment, paper documents, media and equipment relating to facilities maintenance
  • Digital/Virtual assets in the form of soft copies such as SLA’s, SOW’s, License documents, SOP’s, Audit reports, etc.

 

This quality &security policy applies to any person (such as employees, system administrators or in- charge, users, auditors, contractors, consultants, outsourced vendors, third parties and others) who access Softweb Technologies Pvt. Ltd. quality &information systems. This policy shall be communicated throughout the organisation to users in a form that is relevant, accessible and understandable to the intended audience.

 

QMS Policy Statement

 

Softweb Technologies Pvt. Ltd. is committed to delivering high-quality products and services that consistently meet applicable customer, statutory, and regulatory requirements while enhancing customer satisfaction through the effective implementation and continual improvement of the Quality Management System.

To achieve this commitment, we shall:

  • Understand the current and future needs and expectations of our customers and other relevant interested parties.
  • Work closely with our customers, suppliers, and business partners to achieve shared business and quality objectives.
  • Deliver products and services with the highest practicable standards of quality, reliability, and consistency.
  • Implement and maintain an effective Quality Management System through systematic planning and risk-based thinking to support the achievement of our business objectives.
  • Adopt advanced technologies, innovative solutions, and industry best practices to enhance quality and operational excellence.
  • Develop the competence of our employees through continuous education, training, and awareness programs.
  • Establish measurable quality objectives, monitor performance, and evaluate customer satisfaction to drive continual improvement.
  • Continually improve our processes, products, services, and the effectiveness of the Quality Management System.
  • Ensure compliance with all applicable statutory, regulatory, contractual, and other relevant requirements.

This Quality Policy is communicated, understood, implemented, and maintained throughout the organization and is periodically reviewed for its continuing suitability and effectiveness.

ISMS Policy Statement

 

At Softweb Technologies Pvt. Ltd., top management fully recognizes the critical importance of information security and the expectations of all interested parties—both internal and external, including clients, suppliers, regulatory authorities, and government bodies. Information security is integrated as a core management function, with a key focus on ensuring the confidentiality, integrity, availability, and privacy of all information assets.

 

This policy is aligned with the principles and requirements of ISO/IEC 27001:2022, and the company is committed to the following:

 

  • Ensure strict adherence to all applicable laws, regulations, and contractual obligations related to information security.
  • Establish and maintain clearly defined security objectives based on rigorous risk assessments.
  • Communicate these objectives to all interested parties to promote transparency and continuous improvement.
  • Maintain a robust Information Security Management System (ISMS), comprising detailed manual and standardised procedures.
  • Ensure that all relevant stakeholders, including employees, customers, and suppliers, understand and follow the documented security practices.
  • Collaborate actively with customers, partners, and suppliers to establish and maintain appropriate information security standards, ensuring mutual protection of sensitive data.
  • Implement a culture of continual improvement, including:
    • Regular risk assessments
    • Development and application of risk treatment strategies
    • Monitoring and adjustment of controls based on evolving threats and business challenges

 

  • Conduct periodic reviews of risk evaluation criteria to guide informed business decisions and strategic direction.
  • Allocate sufficient management resources to meet and exceed information security requirements.
  • Ensure all employees are trained and aware of their individual roles and responsibilities in maintaining information security.
  • Foster a company-wide culture of personal accountability for safeguarding information assets.
  • This policy is owned and governed by the Chief Operating Officer (COO), who ensures its ongoing relevance and effectiveness.
  • While responsibility is shared across the organisation, the COO leads efforts to embed a security-first mindset into everyday operations.
  • Continuously strive to meet and exceed customer expectations regarding the security, privacy, and reliability of our information systems.

 

This ISMS Policy serves as a guiding framework for all operations related to the design and development of software, reflecting the company’s commitment to industry best practices and robust information security management.

 

Organisation of Quality &Information Security

 

Entities shall define quality &information security roles and responsibilities to provide an appropriate governance structure to their Information Security Management System.

 

Policy Framework

The policy will be supported by a comprehensive Quality & Information Security Standard that shall cover all the controls required to be adhered to, in order to fulfil the requirements stated in this policy.  Respective entities shall maintain up-to-date supporting documents for adherence to this policy and the standard.

 

Policy Deviations 

Any deviations from the policies and Standard mentioned herein, either due to conflicts with laws/regulations, pre-existing policies or implementation issues, shall be documented, or the risk associated must be accepted by the Group IT Infrastructure Head. A log of deviations with a rationale to be maintained at the entity level and should be available for review at all times.

 

Policy Review

All IMS policies shall be reviewed and approved by management annually or whenever there are major changes (if applicable) in the organisation.  Records of the management review and approval(s) shall be maintained.