Computer Design, in providing its IT infrastructure design and development services, software development, and Cloud service delivery, has as its primary objective attention to Client needs and the satisfaction of such requirements as a guiding value in the management of business activities. Furthermore, Computer Design considers the security of its own information and that of its clients to be of fundamental importance.
In this perspective, the ability to transfer know-how to the client’s organization is fundamental both to facilitate the complete utilization of our services and to produce within the client’s organization that real change which is the objective of every reorganization or improvement intervention, also from an information security perspective.
To achieve these objectives, we have adopted an internal procedure control system based on the reference Standards UNI ISO 9001:2015 and ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, and NIS2 directive.
Design activities and professional services in the IT field constitute the strengths of our structure and can be activated either upon specific client request or following a careful analysis of client and market needs.
Our objective can be fundamentally centered on five different directions:
- Conduct and support the development of the Client’s business strategies and objectives, providing the most appropriate technical solutions for the resources required by the innovation processes underlying such strategies;
- Bridge the gaps and deficiencies that hinder the alignment of business processes with client expectations and the effectiveness and efficiency standards established by the company.
- Support the client’s organization from an IT perspective in order to ensure its correct functioning and efficiency
- Involve stakeholders (Clients, Suppliers, Employees, Collaborators, Public Institutions, Associations) regarding the activities carried out, with the purpose of safeguarding the quality of services offered, the health and safety of personnel, human dignity, the administrative protection of the company, information security, and the correct processing of personal data.
- Constantly monitor and evaluate risks and opportunities related to business activities, with consequent implementation of any necessary actions.
- Fully comply with the indications of current and binding regulations, also in terms of personal data processed by Cloud services.
- All management has the responsibility to protect the personal data of its Clients stored in the Cloud.
- Increase, within its personnel, the level of awareness and competence on security issues.
- Information security is considered by the Organization an autonomous and transversal strategic priority. It plays a fundamental role as it enables the construction of a more secure and resilient digital ecosystem, protecting critical infrastructures and contributing significantly to the reduction of risks connected to cyber attacks.
COMPUTER DESIGN SRL is guided in this journey by reference values such as:
- Client Orientation
- Reliability in service delivery
- Competence
- Constant pursuit of innovation
- Confidentiality
- Integrity
- Availability
For the NIS2 directive, the following strategic objectives are taken into consideration:
- Adoption and maintenance of minimum security measures defined by ACN;
- Definition and monitoring of security KPIs (e.g., average detection and response times, incident reduction, internal audits);
- Implementation of timely incident notification processes to the CSIRT;
- Integration of IT risk management in contracts with highly critical and critical suppliers;
- Execution of internal and external audits, with traceability of evidence;
- Periodic reporting to governance on the level of compliance and residual risk.
The Organization commits to ensuring the continuous improvement of the ISMS and the achievement of the identified strategic objectives also through adequate resources. The definition of objectives is carried out in coordination with budget planning; therefore, funding is proportionate to the achievement of planned objectives.
The implementation of this Policy is planned, achieved, and verified through the implementation of an operational Integrated Management System compliant with the UNI ISO 9001:2015 and ISO/IEC 27001:2022 standard and ISO/IEC 27017:2015, ISO/IEC 27018:2019 guidelines and NIS2 directive with the full involvement and support of Management.
To achieve its objectives, COMPUTER DESIGN:
- Employs personnel with high professionalism and technical preparation, in constant training growth;
- Rigorously selects its suppliers, carefully analyzing the market and its innovative products;
- Complies with safety regulations, focusing its attention on personnel and the workplace;
- Complies with information security regulations, focusing its attention on aspects related to the New European Regulation on Privacy;
- Is prepared to adapt the company structure following regulatory updates;
- Focuses on attention to detail, flexibility, efficiency, and transparency to obtain complete satisfaction of client needs.
COMPUTER DESIGN assumes the following general commitments:
- Evaluate the quality of the product and service offered, ascertaining the level of Client satisfaction;
- Monitor activities that affect the Management System in order to identify non-conformities:
- Of the product
- Of the process
- Of the service
- Of Security
- Measure the cost of non-quality and activate appropriate corrective actions;
- Verify quality and security objectives during Management Review, evaluating processes and their effectiveness by undertaking improvement actions;
- Analyze the internal and external context in which COMPUTER DESIGN operates, taking into consideration the expectations and needs of stakeholders;
- Plan business strategies based on risk and opportunity analysis;
- Plan meetings with personnel to inform them about the Management System and actively involve them in order to promote continuous improvement of the product, service, and security;
- Verify ecological transition objectives.
Date: 2025-12-12