Information Security Policy
Parka Lausnir ehf. (Parka) follows this information security policy:
1. Parka's role is to ensure the security of the information of the company, its subsidiaries and their customers, with respect to confidentiality, integrity and availability.
2. Parka follows the objectives, laws, regulations and guidance of its Information Security Committee, which form the basis for establishing and maintaining the measures that safeguard the confidentiality, integrity and availability of data and information systems, and complies with all agreements concerning information security to which the company is a party.
3. Parka's information security policy is binding on all employees of the company and extends to all service providers, contractors and suppliers who provide services to Parka.
4. All Parka employees are committed to protecting data and information systems against unauthorised access, use, alteration, disclosure, destruction, loss or transfer.
5. Parka employees, customers, service providers, contractors and suppliers are encouraged to report information security incidents and deviations as they arise, for the purpose of promoting continuous improvement.
6. Parka regularly performs risk assessments and internal audits to determine whether further measures are required and to identify opportunities for continuous improvement.
7. The Information Security Committee publishes an annual report on Parka's implementation of and performance against this policy.
8. Current and former employees, service providers, contractors and suppliers are prohibited from disclosing information about the internal affairs of Parka, its customers or other employees.
9. Parka promotes active information security awareness among employees, customers, service providers, contractors and suppliers. The conduct and working practices of Parka employees shall set an example in matters of information security.
10. Parka reviews this policy as circumstances require, and at a minimum every 2 years.
11. Parka will comply with ÍST ISO/IEC 27001:2022, Information security management systems, which forms the basis of the organisational and maintenance measures whose objective is to ensure the confidentiality, integrity and availability of data and information systems.
12. Parka's information security policy is described in further detail in the Information Security Management System.
Reykjavík, 02/10/2025 Freyr Ólafsson
This is an English translation of Parka's information security policy, the original of which was adopted in Icelandic on 02/10/2025.
