Skip to main content
Icelandic Medicines Agency Frontpage
Icelandic Medicines Agency Frontpage

Icelandic Medicines Agency

Information Security Policy

The Icelandic Medicines Agency follows the Information Security Policy set out below.

The policy applies to the processing, handling and storage of all information and data owned by or in the custody of the Agency. The policy also applies to premises and equipment owned or managed by the Icelandic Medicines Agency. It takes into account laws and regulations on data protection and the information security management standard ISO 27001, and is also in accordance with the rules of the Icelandic Data Protection Authority No. 299/2001 on the security of personal data.

The policy of the Icelandic Medicines Agency is to:

  • Preserve and maximise information security with regard to confidentiality, integrity and availability

  • Identify and comply with requirements, laws and regulations applicable to information security management

  • Ensure due care in the recording of information and update it as needed

  • Ensure easy access to information and information systems for those who have the right and need for such access

  • Protect information and information systems against unauthorised access

  • Promote active security awareness among staff through education and training

  • Work continuously on improvements

  • Ensure management support through active management review and the setting of objectives

  • Apply risk-based thinking

  • Ensure effective internal control

The Information Security Policy is binding for the staff of the Icelandic Medicines Agency.

Entry into force and review

The policy is issued by the Executive Director of the Icelandic Medicines Agency following a proposal from the Agency’s Quality and Security Manager and approval by the Executive Board. The policy applies from the date of confirmation by the Executive Director, as reflected in the document approval process in the management system.

Icelandic Medicines Agency