Management Policy

This English text is a translation provided for convenience. The Bulgarian original is the authoritative version and governs in the event of any discrepancy. See the Bulgarian documents for the binding text.

1. This policy commits the management of Hi Computers EOOD (“the Organisation”) to achieving the defined objectives for quality, information security and the provision of internal IT services across all areas and at all levels of the organisation's structure, in accordance with the established and continuously improved processes, methods, techniques, mechanisms and management regulations relating to the supply, sale and support of complex information security solutions, including software and specialised information security hardware.

2. An Integrated Management System for quality, information security and internal IT services has been implemented, is operating and is continuously improved within the organisation, in accordance with the requirements of ISO 9001:2015, ISO/IEC 27001:2022 and ISO/IEC 20000-1:2018, together with a set of good practices from ISO/IEC 27002:2022.

3. The management of the Organisation declares the application of this Policy in order to ensure that the requirements, expectations and needs of its clients and other interested parties are satisfied, while ensuring the confidentiality, integrity, availability, authenticity and non-repudiation of the information it manages and the controlled protection of information resources, assets and flows from direct and indirect threats, by means of:

4. Considering and meeting clients' requirements in respect of their needs, through the high quality of the products and services offered, including the consistent fulfilment of the agreed service levels in the provision of internal IT services (internal SLAs). Ensuring that quality is a priority in the work of all employees of the Organisation and placing it at the foundation of all market and functional strategies;

5. Optimising and continuously improving the organisation's processes - for adequacy, suitability and conformity with regulated requirements, on the basis of continuous improvement and development;

6. Identifying and complying with legislative and regulatory requirements and with the business requirements accepted in contractual obligations;

7. Achieving business resilience and continuity, through the quality and availability of the internal IT service offered;

8. Increasing the effectiveness of processes by introducing automated methods that would prevent possible errors;

9. Continuously improving the internal IT services provided by the company, through management of information security risks and of the risk acceptance criteria;

10. Conducting targeted staff training to raise qualifications and motivation for consistent and measurable improvements in day-to-day work;

11. Providing the necessary infrastructure, working environment and technological equipment for the efficient running of processes;

12. Regular review of the methodology, approaches and criteria for identifying, analysing, evaluating, treating and accepting risks within the organisation, as regulated in the methodology adopted in the risk management procedure;

13. Maintaining and periodically testing a framework of business continuity plans;

14. Maintaining a system of rules for reporting, managing and investigating weaknesses and/or incidents relating to information security;

15. Maintaining an up-to-date statement of applicability;

16. Applying generally accepted standards and good practices for the purposes of the quality of products and services, information security and internal IT services within the organisation.

17. The management of the Organisation continuously monitors the effectiveness and efficiency of the established objectives for quality, information security and internal IT services, through periodic review and commensurate assessment. To achieve these objectives, conditions have been created for strict compliance with the requirements of the IMS and for the active participation of management and operational staff in its development and improvement.

18. As Manager of the company, I DECLARE my personal involvement and responsibility for providing resources for the development, maintenance, periodic review and continuous improvement of the effectiveness of the implemented IMS.

19. MANAGER: Konstantin Veselinov

20. Date: 29 February 2024