top of page

INFORMATION SECURITY POLICY

Information Security Policy

 

 

BLUE SCRIPT DESIGNS

 

Information Security Policy

 

Version: 1.0

​

Effective Date: 6 August 2026

​

Last Reviewed: 6 August 2026

​

Next Scheduled Review: 6 August 2027

​

​

​

Information Security Policy

​

1. Introduction

 

Information is one of Blue Script Designs' most valuable assets. Protecting the confidentiality, integrity and availability of information is essential to maintaining the trust of our clients, employees, suppliers and business partners.

 

As a provider of website development, digital marketing, branding and online business solutions, we recognise our responsibility to safeguard the information entrusted to us and to maintain robust security practices throughout our operations.

 

This Information Security Policy outlines the principles, controls and responsibilities that support the protection of our information assets and technology systems.

 

​

​

2. Purpose

​

The purpose of this policy is to:

​

  • Protect company and client information.

  • Maintain confidentiality, integrity and availability of information.

  • Reduce cyber security risks.

  • Protect against unauthorised access.

  • Support compliance with legal and regulatory obligations.

  • Promote secure working practices.

  • Strengthen client confidence.

  • Support business continuity.

​

​

​

3. Scope

​

This policy applies to:

​

  • Employees.

  • Directors.

  • Contractors.

  • Freelancers.

  • Consultants.

  • Temporary workers.

  • Suppliers who process information on our behalf.

  • Anyone authorised to access Blue Script Designs' systems or information.

​

It applies to all forms of information including:

​

  • Digital information.

  • Electronic communications.

  • Cloud-based services.

  • Portable devices.

  • Paper records.

  • Client documentation.

  • Business records.

 

​

​

4. Information Security Objectives

​

Blue Script Designs aims to:

 

  • Protect confidential information.

  • Prevent unauthorised access.

  • Minimise cyber security risks.

  • Maintain reliable business systems.

  • Protect client data.

  • Promote secure working practices.

  • Ensure business resilience.

  • Continuously improve information security.

​

​

 

5. Information Security Principles

​

Our approach to information security is based upon three fundamental principles:

​

Confidentiality

 

Information should only be accessible to authorised individuals.

 

Integrity

 

Information should remain accurate, complete and protected against unauthorised modification.

 

Availability

 

Information and systems should remain available to authorised users whenever reasonably required.

 

These principles underpin all of our information security practices.

​

​​

 

6. Information Classification

 

Information should be handled according to its sensitivity.

 

Examples include:

 

Public Information

​

Information intended for public release.

​

Examples:

 

  • Website content.

  • Marketing material.

  • Public policies.

​

Internal Information

 

Information intended for internal business use.

 

Examples:

 

  • Internal procedures.

  • Staff communications.

  • Operational documentation.

​

 Confidential Information

​

Information requiring restricted access.

​

Examples:

​

  • Client information.

  • Commercial contracts.

  • Financial records.

  • Credentials.

  • Intellectual property.

  • Project documentation.

 

Access should always reflect business need.

 

​

 

7. Access Control

 

Access to systems and information is granted only where required for legitimate business purposes.

 

Blue Script Designs aims to ensure:

 

  • User accounts are individually assigned.

  • Access permissions are appropriate.

  • Unnecessary privileges are removed.

  • Former personnel no longer retain access.

  • Administrative access is limited.

  • Access rights are reviewed periodically.

​

​

​

8. Password Security

​

Strong password management is essential to protecting business systems.

​

Users are expected to:

​

  • Create strong and unique passwords.

  • Avoid password sharing.

  • Store passwords securely.

  • Change compromised passwords immediately.

  • Use password managers where appropriate.

  • Protect authentication credentials from unauthorised access.

 

Passwords should never be disclosed through email, messaging platforms or unsecured communications.

 

​

 

9. Multi-Factor Authentication (MFA)

 

Where supported, Blue Script Designs encourages the use of Multi-Factor Authentication (MFA) to provide an additional layer of security.

 

MFA is particularly important for:

 

  • Email accounts.

  • Cloud services.

  • Website administration.

  • Domain management.

  • Hosting platforms.

  • Financial systems.

  • Customer relationship management (CRM) systems.

​

​

 

10. Device Security

 

All company-owned and authorised devices should be appropriately protected.

 

Security measures may include:

 

  • Automatic screen locking.

  • Device encryption where available.

  • Secure passwords or biometric authentication.

  • Anti-malware software.

  • Firewall protection.

  • Operating system updates.

  • Secure disposal of obsolete equipment.

​

Users should report lost or stolen devices immediately.

​

​

​

11. Software Security

​

Blue Script Designs seeks to ensure software remains secure by:

​

  • Applying security updates.

  • Installing patches promptly where appropriate.

  • Removing unsupported software.

  • Using reputable software providers.

  • Reviewing software permissions.

  • Avoiding unauthorised applications.

​

Software should only be installed where properly authorised.

​

​​

​

12. Cloud Services

​

Cloud platforms play an important role in our business operations.

​

Where cloud services are used, we seek to ensure:

​

  • Appropriate access controls.

  • Strong authentication.

  • Secure configuration.

  • Regular backups.

  • Reliable providers.

  • Appropriate contractual protections.

​

​

​

13. Email Security

​

Email remains one of the most common methods of cyber attack.

​

Employees and representatives should:

​

  • Verify unexpected emails.

  • Check recipients carefully before sending confidential information.

  • Avoid opening suspicious attachments.

  • Avoid clicking unknown links.

  • Report suspected phishing attempts promptly.

  • Protect sensitive information during transmission.

​

​

​

14. Remote Working

​

Blue Script Designs supports flexible and remote working where appropriate.

​

Individuals working remotely are expected to:

​

  • Use secure internet connections.

  • Protect devices from unauthorised access.

  • Avoid using public Wi-Fi without appropriate safeguards.

  • Lock devices when unattended.

  • Protect confidential information.

  • Follow company security procedures.

​

​

​

15. Data Backup and Recovery

​

Reliable backups help protect against data loss.

​

Blue Script Designs seeks to:

​

  • Maintain appropriate backup arrangements.

  • Protect backup data.

  • Test recovery procedures periodically.

  • Support business continuity.

  • Minimise disruption following incidents.

​

​

​

16. Incident Reporting

​

Security incidents should be reported immediately.

 

Examples include:

 

  • Lost devices.

  • Suspicious emails.

  • Malware infections.

  • Unauthorised access.

  • Password compromise.

  • Data breaches.

  • System vulnerabilities.

  • Ransomware attacks.

​

Prompt reporting helps minimise potential impact.

​

​

 

17. Business Continuity

 

Blue Script Designs recognises the importance of maintaining service continuity.

 

Where reasonably practicable, we seek to:

 

  • Protect critical systems.

  • Maintain backups.

  • Reduce operational disruption.

  • Recover services efficiently.

  • Review resilience measures regularly.

​

​

​

18. Third-Party Security

​

Suppliers and service providers may have access to information or systems.

​

Where appropriate, Blue Script Designs seeks to work with organisations that:

​

  • Maintain appropriate security controls.

  • Protect confidential information.

  • Comply with applicable legislation.

  • Support secure service delivery.

  • Notify relevant security incidents promptly.

​

​

​

19. Training and Security Awareness

​

Security is everyone's responsibility.

​

Blue Script Designs encourages ongoing awareness relating to:

​

  • Password security.

  • Phishing awareness.

  • Secure handling of information.

  • Device security.

  • Data protection.

  • Social engineering.

  • Secure remote working.

  • Incident reporting.

​

Awareness activities may be updated as cyber threats evolve.

 

​

 

20. Monitoring and Compliance

 

Blue Script Designs reviews its security arrangements regularly to:

 

  • Identify emerging threats.

  • Improve security controls.

  • Review business risks.

  • Monitor compliance.

  • Support continual improvement.

  • Strengthen resilience.

 

Appropriate monitoring may be undertaken to protect business systems and information while respecting applicable privacy and employment laws.

 

​

 

21. Related Policies

 

This Information Security Policy should be read alongside our:

 

  • Data Protection Policy.

  • Privacy Policy.

  • Cookie Policy.

  • Employment Policy.

  • Supplier Code of Conduct.

  • Anti-Bribery & Corruption Policy.

  • Complaints Handling Procedure.

  • Corporate Social Responsibility Policy.

 

Together, these documents provide a comprehensive framework for protecting information, maintaining compliance and supporting responsible business practices.

 

​

 

22. Policy Review

​

This policy will be reviewed annually, or sooner where necessary, to reflect:

​

  • Legislative changes.

  • Technological developments.

  • Emerging cyber security threats.

  • Business growth.

  • Industry best practice.

​

The most current version will always be available on our website.

​

​

​

23. Contact Us

​

If you have any questions regarding this Information Security Policy, please contact:

 

Blue Script Designs

​

Website:

​

[www.bluescriptdesigns.co.uk]  (http://www.bluescriptdesigns.co.uk)

​

Email:

​

[info@bluescriptdesigns.co.uk]  (mailto:info@bluescriptdesigns.co.uk)

​

​

​

Appendix A – Our Information Security Principles

​

Blue Script Designs is committed to:

​

Confidentiality

​

Protecting information against unauthorised access and disclosure.

​

Integrity

​

Maintaining accurate, complete and trustworthy information.

​

Availability

​

Ensuring authorised users have reliable access to systems and information.

​

Accountability

​

Promoting responsible use of information and technology.

​

Resilience

​

Preparing for and responding effectively to cyber security incidents.

​

Continuous Improvement

​

Reviewing and strengthening our information security practices as technology and threats evolve.

​

​

​

Appendix B – Good Information Security Practices

​

Everyone working with or for Blue Script Designs is expected to:

 

  • Use strong, unique passwords.

  • Enable Multi-Factor Authentication wherever available.

  • Lock devices when unattended.

  • Keep software up to date.

  • Verify email recipients before sending sensitive information.

  • Report suspicious emails or security incidents immediately.

  • Protect confidential client information.

  • Use approved systems and software.

  • Dispose of information securely.

  • Follow all company security procedures.

​

​

​

Appendix C – Our Cyber Security Commitment

​

Blue Script Designs understands that effective information security is essential to maintaining trust and delivering reliable digital services.

​

We are committed to:

​

  • Protecting client and business information.

  • Investing in appropriate security controls.

  • Promoting cyber security awareness.

  • Reducing information security risks.

  • Responding promptly to security incidents.

  • Supporting secure digital transformation.

  • Continually improving our information security management.

 

By embedding security into our daily operations, we aim to safeguard our clients, our business and the digital services we provide.

 

​

 

Document Classification: Public Website Policy

 

Approved By: Blue Script Designs Management

 

Document Owner: Blue Script Designs

 

Version Control: Version 1.0

 

Review Frequency: Annually

bottom of page