Dynamics Plus · Policy

Information Security Policy

DYN-POL-013|Version 1.0|Public|Effective 24 June 2026

Dynamics Plus Max IT Solutions LLC

1. Purpose and Scope

Dynamics Plus builds and operates asset lifecycle management software for clients who trust us with data about their buildings, their communities and their people. This policy is the top-level policy of our Information Security Management System (ISMS) and meets ISO/IEC 27001:2022 clause 5.2 and Annex A controls 5.1 and 5.2.

The ISMS covers the design, development, delivery and support of the Dynamics Plus platform and the client data processed through it. Dynamics Plus is a fully remote organisation with no company-controlled premises or data centres. The policy applies to all employees, Associate Consultants and third parties with access to company systems or data.

2. Our Commitments

  • Protecting information. We protect the confidentiality, integrity and availability of client data, personal data, source code and company information through access control, encryption in transit and at rest, and controlled change to production systems.
  • Meeting requirements. We satisfy the legal, regulatory and contractual requirements that apply to us, and treat security commitments in client contracts as binding.
  • Managing risk. Risks are assessed and recorded with named owners. Residual risk is accepted in writing by the CEO and CTO jointly for Critical and High risk, and by the CTO for Medium and Low risk.
  • Responding to incidents. Everyone must report a suspected security incident immediately.
  • Building awareness. Everyone receives security awareness training on joining and at least annually.
  • Improving continually. We improve the ISMS through internal audit, management review and corrective action.
  • Providing resources. Management provides the people, time and budget the ISMS needs.

Measurable security objectives are set under this policy, approved by the CEO and reviewed quarterly.

3. Responsibilities

The CEO holds ultimate accountability for the ISMS. The CTO runs it day to day. The Information Security Lead maintains its documentation, training and audits. Everyone follows company security policies and reports incidents. Where one person holds more than one role, they do not review or approve their own work.

4. Legal Requirements

  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
  • UAE Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes
  • UAE Federal Decree-Law No. 33 of 2021 on the Regulation of Employment Relations

5. Availability and Review

This policy is classified Public and is published so that clients, prospective clients, auditors, regulators and other interested parties can read it. Supporting policies and the Statement of Applicability are classified Internal and are provided on request where there is a legitimate interest, at the CEO's discretion.

The policy is reviewed at least annually by the CEO and CTO, and sooner on any material change.

Information Security Policy | DYN-POL-013 | v1.0 | Public