Quality and Information Security Policies
- About
- Accreditations and Affiliations
- Behavior Policy
- Certification Mark Use Policy
- Certification Process
- Code of Ethics
- Complaint and Appeal Policy
- Digital Trust: Building a Secure Future
- PECB Code Of Ethics Violation Policy
- PECB Digital Badges
- PECB Leadership
- PECB Policy Regarding Canadian and International Economic Sanctions and the Countries Impacted
- PECB Store Customer License Agreement
- Quality and Information Security Policies
- Refund Policy
- Statement of Impartiality
- The Value of PECB Certification
- Violation of PECB Brand and Fraud Reporting Policy
Quality Policy
It is the policy of our organization to:
- Define and meet our customer’s requirements.
- Ensure that our Policies and Procedures are clear and concise to reflect what we actually do.
- Monitor and analyze performance metrics, making any necessary changes or adjustments to customer programs, customer satisfaction, the Quality Management System, and/or any related entities as appropriate.
- Educate all employees about the linkages between their jobs and Customer satisfaction.
- Ensure effective Customer and internal communication.
- Foster a team approach to problem solving and preventive action by empowering all employees to be quality ambassadors.
- Integrate organization’s Quality Management system into the Company’s culture and daily practices, establishing a long-term commitment to quality, continuous improvement, and customer satisfaction.
- Meet and/or exceed our customer’s expectations through continuous improvement.
- Guarantee that organization’s top management meets regularly with the Quality Management representative to review and ensure the effectiveness of the Quality Management System.
Information Security Policy
It is the commitment of our organization to:
- Protect the confidentiality, integrity, and availability of information throughout its lifecycle, regardless of how it is created, processed, communicated, stored, transmitted, retained, or disposed of.
- Protect PECB information and information systems against unauthorized access, disclosure, alteration, misuse, loss, destruction, or other security threats.
- Ensure that information is accurate, complete, reliable, and available to authorized users when required.
- Identify, assess, monitor, document, and appropriately treat information security risks in accordance with PECB’s risk-management approach.
- Apply the principles of least privilege, need-to-know, segregation of duties, and security and privacy by design and by default.
- Ensure that information security requirements are integrated into business processes, projects, systems, products, services, and relationships with relevant third parties.
- Ensure that employees, contractors, consultants, vendors, and other relevant third parties understand and fulfill the information security responsibilities applicable to their roles.
- Provide appropriate information security awareness and training and promote individual responsibility and accountability for protecting information.
- Identify, report, assess, and respond effectively to information security events and incidents, including taking appropriate corrective actions where necessary.
- Maintain appropriate business continuity, resilience, backup, recovery, and availability measures to support critical information and systems.
- Comply with applicable legal, regulatory, contractual, data protection, and accreditation requirements and prevent activities that could place PECB in breach of such obligations.
- Regularly review, monitor, and continually improve PECB’s Information Security Management System, controls, and practices to strengthen security, resilience, and trust.