Information Security Management System Policy

6 October 2025

The Mediafon Group's operational management and development strategy is based on a focus on information security in accordance with the requirements of the ISO/IEC 27001:2022 and ISO/IEC 27001:2022/AMD1:2024 standards. The Mediafon Group specialises in the development of IT and telecoms products and the provision of services, and, in addition to standard IT and VoIP products and services, it also offers artificial intelligence products and a mobile signature service package. In order to ensure the quality of operational management and service provision, successful and targeted development, and a stable and competitive market position, the Group undertakes to:

  • to conduct its operations in accordance with EU legislation governing the business sector and other requirements which the organisation undertakes to comply with, with a view to ensuring compliance with the requirements of the ISO/IEC 27001:2022 and ISO/IEC 27001:2022/AMD1:2024 standards;
  • to continuously improve the effectiveness of the management system, taking into account operational results and feedback from customers, partners and employees;
  • to continuously improve ongoing relationships with its partners and suppliers;
  • encourage staff to enhance their qualifications;
  • When planning activities and analysing risks, assess the potential impact on information security, the consequences of possible incidents for the company's and the client's operations, requirements, reputation or financial losses;
  • introduce innovations and seek solutions to improve the quality of service provision;
  • Effectively manage cyber security incidents and actively participate in their resolution;
  • Set measurable information security objectives each year, linked to the company's strategic goals, and review the relevance and suitability of the information security policy;
  • Implement climate change initiatives and manage the sustainability strategy;
  • Implement preventive measures for events and incidents;
  • Continuously improve the effectiveness of the information security management system, taking into account operational results, staff suggestions, and feedback from customers and partners.

Scope

This policy applies to all the Company's divisions, employees, partners, contractors and other third parties who have access to the Company's information or information systems.

Review

This policy is reviewed at least once a year or whenever there are changes to the Company's operations, legal requirements or information security circumstances.

Approved by

Company Managing Director
MEDIAFON, a private limited company Tomas Jančys
Mediafon Technology, UAB Jonas Bačinskas
Mediafon Datapro, UAB Bronius Skudutis
Mediafon Carrier Services, UAB Tomas Jančys

enltesfrar