Policy Statement
The Information Security Management System (ISMS) Policy Statement reflects the Financial Intelligence Authority's commitment to protecting information assets, strengthening risk management, and ensuring operational resilience. The Authority is dedicated to continually improving its information security practices in line with ISO/IEC 27001:2022 to safeguard the confidentiality, integrity, and availability of information while supporting its regulatory mandate and stakeholder trust.
To achieve this commitment, the Financial Intelligence Authority of Uganda has established an Information Security Management (ISMS) and is dedicated to its continual improvement through the commitment to:
1. Act as a responsible conservator of information assets entrusted to its care.
2. Ensure the protection from loss of confidentiality, integrity, and availability of its critical information assets including any information that it may store, process, or transmit in the delivery of service.
3. Establish, implement, maintain and continually improve an information security management system in accordance with the requirements of ISO/IEC 27001:2022 Standard.
4. Ensuring that compliance with all relevant regulatory and legal requirements and contractual obligations is continuously monitored and maintained.
5. To support the Information Security Management System, a number of policies and procedures have been developed that adhere to the requirements of this policy. These are approved and made available to staff and other interested parties as appropriate.
6. To ensure the implemented management system meets the desired objectives, FIA management has approved a performance measurement process that will ensure that continued monitoring and evaluation of the performance of the ISMS and that it is reported to management for decisions to be made in a timely manner.