Information Security Management High-level Policy Statement
Tropical General Investments (TGI) Group and its member companies are committed to protecting the confidentiality, integrity, and availability of all information assets essential to its business operations, stakeholder interests, and compliance obligations.
To achieve this, top management has established this Information Security Management System (ISMS) policy which; Is appropriate to the purpose of TGI Group as a diversified multinational conglomerate operating across agribusiness, FMCG, pharmaceuticals, industrial chemicals, home and personal care sectors. This policy supports the Group’s strategic goals of sustainable growth, innovation, and regulatory compliance. The Management of TGI Group is committed to ensure that:
- The confidentiality of information is protected to prevent disclosure of valuable or sensitive information.
- Information is available to authorized users to meet clients’ and business’ requirements.
- The integrity of information is maintained to ensure its accuracy and completeness.
- The Group adheres to relevant laws and industry standards to ensure compliance and build trust with customers, partners, and regulators
- Emphasises a commitment to the continual improvement of the ISMS by incorporating lessons learned from audits, incidents, management reviews, and technological advancements.
- The Group fosters a culture of security awareness and proactive risk management across all departments and locations under the ISMS scope.
- Appropriate resources are allocated to implement, operate and review an effective Information Security Management System.
- Information Security education, awareness and training will be made available to users to ensure responsible participation.
- All breaches of information security, actual or suspected, will be reported and all users must understand their roles and responsibilities in handling incidents.
- Commits to satisfying all applicable statutory, regulatory, and contractual requirements related to information security.
The Information Security Policies will be provided and made available to all relevant stakeholders.
The review of the Information Security Policy and related documents shall be performed periodically to take account of applicable local, statutory, regulatory, and customer requirements and any changes in business activity