Information Security Policy
The Zalaris Information Security Policy outlines Zalaris’ overall policies for the protection of information from a wide range of threats, to ensure business continuity, minimise business risks and maximise return on investments and business opportunities.
This document covers Zalaris’ set of controls, including policies, processes, procedures, organisational structures and software and hardware functions implemented to ensure all information is secure.
The security policy provides Zalaris management with direction and support for information security, in accordance with business requirements and relevant laws and regulations.
The overall objectives are to protect:
- The financial assets Zalaris is managing.
- Zalaris’ ability to handle prioritised tasks and services for our clients.
- The integrity and confidentiality of the information Zalaris handles.
- Protection against illegal actions, accidents, and unintended incidents.
- Strict adherence to internal Zalaris processes (HR, legal requirements, etc).
The key security policies Zalaris enforces are:
- All information security-related work shall be an integral part of Zalaris’ ordinary operations and shall support Zalaris to achieve objectives for quality and effectiveness.
- Compliance with legislative, regulatory, statutory, and contractual requirements across all organisational units and countries where Zalaris is present or operates in at any time.
- Information security risks and mitigation actions and controls will be identified by performing structured risk analysis activities.
- All employees shall have the necessary knowledge and awareness, including being trained to act according to the information security policy in their daily work.
- Access control will be established in all information systems and physical premises to avoid unauthorised access.
- If an unwanted security breach occurs, all information security-related actions shall limit the damage and ensure a return to normal operation as soon as possible
- Change control will be executed according to defined procedures. Major changes to information resources will be tested and approved by authorised personnel. All major changes will be traceable.
- Proper management of security incidents, including business continuity, is critical to Zalaris due to the nature of Zalaris’ core business – HR and Payroll outsourcing.
At Zalaris, we consider information to be a very important asset. Information security covers actions and controls to protect assets, information and our ability to perform tasks, by securing:
- Confidentiality: Only personnel with job-related responsibilities will have access to confidential information.
- Integrity: Information and systems shall be correct and trustworthy.
- Availability: Information and systems shall be available to authorised users when needed on a need-to-know basis.



