logo
En | ع
  • Home
  • Services
  • Partners
  • Financing products
  • Accounts
  • Media
  • About
  • Financial statement
  • Connect us
phone call
(+967) 8 000 644
E-mail : info@bank-bindowal.com
My Image
ساعات العمل
( 12.00 PM - 8.00 AM )
( 8.00 PM - 4.00 PM )
Website designed by Arab WereDos . All rigths reserved .
Policy and privacy Terms and Conditions
En | العربية
bin dowal logo
My Image
 Home Services Partners Financing products Accounts Media Financial statement About Connect us
    My Image

Information Security Policy

  1. Information security is a holistic discipline, meaning that its application, or lack thereof, affects all facets of Bin Dowal Islamic Microfinance Bank. The goal of the Bin Dowal Islamic Microfinance Bank Information Security Program is to protect the Confidentiality, Integrity, and Availability of the data employed within Bin Dowal Islamic Microfinance Bank while providing value to the way we conduct business. Protection of the Confidentiality, Integrity, and Availability are basic principles of information security, and can be defined as:
    1. Confidentiality – Ensuring that information is accessible only to those entities that are authorized to have access, many times enforced by the classic “need to know” principle.
    2. Integrity – Protecting the accuracy and completeness of information and the methods that are used to process and manage it.
  2. As a modern, aspirant, forward-looking business, Bin Dowal Islamic Microfinance Bank recognizes at senior levels the need to ensure that its business operates smoothly and without interruption for the benefit of its customers, shareholders and other stakeholders.
  3. Bin Dowal Islamic Microfinance Bank has recognized that our business information is a critical assets and as such our ability to manage, control, and protect this assets will have a direct and significant impact on our future success.
  4. In order to provide such a level of continuous operation, Bin Dowal Islamic Microfinance Bank will be implementing an Information Security Management System (ISMS) in line with the International Standard for Information Security. This standard defines the requirements for IT based on internationally recognized best practice.
  5. The operation of the IT has many benefits for the business, including:
    1. Protection of revenue streams and Bin Dowal Islamic Microfinance Bank profitability;
    2. Ensuring the supply of secure products and services to customers;
    3. Maintenance and enhancement of shareholder value; and
    4. Compliance with legal and regulatory requirements
  6. This document defines the information security policy of Bin Dowal Islamic Microfinance Bank, and establishes the framework from which other information security policies may be developed to ensure that the Bin Dowal Islamic Microfinance Bank can efficiently and effectively manage, control and protect its business information assets and those information assets entrusted to Bin Dowal Islamic Microfinance Bank by its stakeholders, partners, customers and other third parties.
  7. Bin Dowal Islamic Microfinance Bank Information Security Program is built around the information contained within this policy and its supporting policies.

Purpose

  1. The purpose of the Bin Dowal Islamic Microfinance Bank Information Security Policy Statement is to describe the actions and behaviors required to ensure that due care is taken to avoid inappropriate risks to Bin Dowal Islamic Microfinance Bank, its business partners, and its stakeholders.

Scope

  1. Bin Dowal Islamic Microfinance Bank Information Security Policy Statement applies to all systems, people and processes that constitute the Bin Dowal Islamic Microfinance Bank is information systems or interacts with any Bin Dowal Islamic Microfinance Bank Information Resource., including board members, directors, employees, suppliers and other third parties who have access to Bin Dowal Islamic Microfinance Bank systems.
  2. The other documents that are relevant to this information security policy are supporting and provide additional information about how it is applied.

Management Commitment

  1. Bin Dowal Islamic Microfinance Bank and its Management are fully committed to protecting the confidentiality and integrity of production systems, facilities, and data as well as the availability of services in the Bin Dowal Islamic Microfinance Bank information systems by implementing adequate security controls.

Management Statement

  1. Managers at all levels are responsible for the safeguard of Bin Dowal Islamic Microfinance Bank information and shall provide reasonable actions to ensure adherence to information security policies and procedures.
  2. Each manager has the general responsibility for security within his areas of control.
  3. Each person should be held accountable for the information security of his job-related activities.

Policy Statement

  1. Bin Dowal Islamic Microfinance Bank maintains and communicates an Information Security Program consisting of topic-specific policies, standards, procedures and guidelines that:
    1. Serve to protect the Confidentiality, Integrity, and Availability of the Information Resources maintained within the Bin Dowal Islamic Microfinance Bank using administrative, physical and technical controls.
    2. Provide value to the way we conduct business and support institutional and overall operational strategy objectives.
    3. Comply with all regulatory and legal requirements, including:
      1. Data Security Standard,
      2. Information Security best practices,
      3. Contractual agreements,
      4. All other applicable Yemeni laws or regulations.
  2. The information security program is reviewed no less than annually or upon significant changes to the information security environment.

Information Security Requirements

  1. A clear definition of the requirements for information security within Bin Dowal Islamic Microfinance Bank will be agreed and maintained with the internal business and cloud service customers and subsequently all security activity is focused on the fulfilment of those requirements. Statutory, regulatory and contractual requirements will also be documented and input to the planning process. Specific requirements about the security of new or changed systems or services will be captured as part of the design stage of each project.
  2. It is a fundamental principle of the Bin Dowal Islamic Microfinance Bank Information Security Management System that the controls implemented are driven by business needs and this will be regularly communicated to all staff through team meetings and briefing documents.

Framework for Setting Objectives

  1. A regular cycle will be used for the setting of objectives for information security, to coincide with the budget planning cycle. This will ensure that adequate funding is obtained for the improvement activities identified. These objectives will be based upon a clear understanding of the business requirements, informed by the management review process during which the views of relevant interested parties may be obtained.
  2. Information security objectives will be documented for an agreed time period, together with details of how they will be achieved. These will be evaluated and monitored as part of management reviews to ensure that they remain valid. If amendments are required, these will be managed through the change management process.

Information Security Policy Areas

  1. Bin Dowal Islamic Microfinance Bank defines policy in a wide variety of information security-related areas which are described in detail in a comprehensive set of policy documentation that accompanies this overarching information security policy.
  2. Each of these policies is defined and agreed by one or more people with competence in the relevant area, with information security and, once formally approved by CEO, is communicated to an appropriate audience, both within and external to, the Bin Dowal Islamic Microfinance Bank.
  3. The table below shows the individual policies (detailed Polices) within the documentation set and summarizes each policy is content and the target audience of interested parties.

Policy Compliance

  1. This Policy shall take effect upon publication. Compliance is expected with all Bin Dowal Islamic Microfinance Bank policies and standards. Policies and standards may be amended at any time.

Compliance Tracking, Measuring, and Reporting

  1. The InfoSec Team will verify compliance to this Policy through various methods, including but not limited to, monitoring, business tool reports, internal and external audits, and feedback to the Policy document owner..
  2. The InfoSec must develop, test, review, maintain, and communicate a representation of the Bin Dowal Islamic Microfinance Bank-wide information security posture to Bin Dowal Islamic Microfinance Bank leadership. The InfoSec is authorized to initiate mechanisms to track the effective implementation of information security controls associated with this Standard and to produce reports measuring individual or Unit compliance to support Bin Dowal Islamic Microfinance Bank decision making.
  3. Periodic reviews will be conducted to ensure the appropriateness and the effectiveness usage of policies, Procedures, and Standards. These reviews may result in the modification, addition, or deletion of usage of policies, Procedures, and Standards to better suit Bin Dowal Islamic Microfinance Bank information security needs.

Exceptions

  1. Requests for exceptions to any of information security policies may be granted for Information Systems (on a case-by-case basis) with compensating controls in place to mitigate risk. Any Exceptions requests must be submitted to the IT or designee for review and approval pursuant to exception procedures

Non-Compliance

  1. The InfoSec is authorized to limit network access for individuals or Units not in compliance with all information security policies and related procedures. In cases where Bin Dowal Islamic Microfinance Bank resources are actively threatened.
  2. In cases of noncompliance with this Policy, the Bin Dowal Islamic Microfinance Bank may apply appropriate employee sanctions or administrative actions, in accordance with relevant administrative, and employment policies.
  3. An employee found to have violated this Policy may be subject to disciplinary action, up to and including termination of employment.
  4. Any supplier, vendor, consultant, or contractor found to have violated this Policy may be subject to sanctions up to and including removal of access rights, termination of contract(s), and related civil or criminal penalties.
  5. Additionally, the Bin Dowal Islamic Microfinance Bank may at its discretion seek legal remedies for damages incurred as a result of any violation. The Bin Dowal Islamic Microfinance Bank may also be required by law to report certain illegal activities to the proper enforcement agencies.

Review and Acceptance

  1. All Bin Dowal Islamic Microfinance Bank staff is responsible for review and acceptance of this Policy: Information Security Policy Statement.
  2. Any user who does not understand the implications of this Policy or how it may apply to them, should seek advice from their immediate line manager.
  3. Questions regarding any Bin Dowal Islamic Microfinance Bank Policies and Standards should be addressed in the first instance to the employee is immediate manager.
Website designed by Arab Ware Dos . All rigths reserved.
Policy and privacy Terms and Conditions    Terms and Conditions from mobil app    Information security policy mobil app   Data Privacy   Frequently asked question
Privacy Policy of Bin Dowal Mobile Banking Application   Terms and Conditions of Bin Dowal Mobile Banking Application