Skip to content

Executive Support Letter

Purpose. A statement from Soon's top management demonstrating leadership and commitment to the ISMS (ISO/IEC 27001 clause 5.1), communicated to the team and interested parties.

Information security within Soon

As a modern, forward-looking business, Soon recognizes at senior levels the need to ensure that its business operates smoothly and without interruption for the benefit of its customers, shareholders and other stakeholders.

In order to provide such a level of continuous operation, Soon has implemented an Information Security Management System (ISMS) in line with the International Standard for Information Security, ISO/IEC 27001.

The operation of this ISMS has many benefits for the business, including:

  • Protection of revenue streams and company profitability
  • Ensuring the supply of goods and services to customers
  • Maintenance and enhancement of shareholder value
  • Compliance with legal and regulatory requirements

An Information Security Policy is available in electronic form and will be communicated within the organization and to all relevant stakeholders and interested third parties.

Commitment to the delivery of information security extends to senior levels of the organization and will be demonstrated through the information security policy and the provision of appropriate resources to establish and develop the ISMS.

Top management will also ensure that a systematic review of performance of the programme is conducted on a regular basis to ensure that information security objectives are being met and relevant issues are identified through the audit programme and management processes.

A risk management approach and process will be used which is in line with the requirements and recommendations of ISO/IEC 27001. Risk management will take place at several levels within the ISMS, including:

  • Assessment of risks to the achievement of our information security objectives
  • Regular information security risk assessments within specific operational areas
  • Assessment of risk as part of the business change management process
  • At the project level as part of the management of significant change

We would encourage all employees and other stakeholders in our business to ensure that they play their part in delivering our information security objectives.

Yours sincerely,

TODO(owner): name and role of top management signatory — letter is unsigned.

  • docs/05-leadership/isms5-informationsecuritypolicy.md — Information Security Policy

Change log

Version Date Author Comments
0.1 2025-06-07 Olaf Jacobson First draft document
0.2 2026-07-18 Andrea Cardinali Cleaned conversion artifacts, fixed title, flagged missing signatory (ISMS overhaul)