Publication Date: 6 August 2025

1. INTRODUCTION

As a modern, forward-looking business, Izwe Loans Kenya Limited (Izwe) recognises at senior levels the need to ensure that its business operates smoothly and without interruption for the benefit of its customers, shareholders and other stakeholders.

In order to provide such a level of continuous operation, Izwe Loans Kenya Limited has implemented an Information Security Management System (ISMS) in line with the International Standard for Information Security, ISO/IEC 27001.

The operation of this ISMS has many benefits for the business, including:

  • Protection of revenue streams and company profitability
  • Ensuring the supply of goods and services to customers
  • Maintenance and enhancement of shareholder value
  • Compliance with legal and regulatory requirements

Commitment to the delivery of information security extends to senior levels of the organisation and will be demonstrated through the information security policy and the provision of appropriate resources to establish and develop the ISMS.

Top management will also ensure that a systematic review of performance of the programme is conducted on a regular basis to ensure that information security objectives are being met and relevant issues are identified through the audit programme and management processes.

A risk management approach and process will be used which is line with the requirements and recommendations of ISO/IEC 27001. Risk management will take place at several levels within the ISMS, including:

  • Assessment of risks to the achievement of our information security objectives
  • Regular information security risk assessments within specific operational areas
  • Assessment of risk as part of the business change management process
  • At the project level as part of the management of significant change

We would encourage all employees and other stakeholders in our business to ensure that they play their part in delivering our information security objectives.

2. INFORMATION AND SECURITY OBJECTIVES

Based on the requirements and issues set out in this document, the following major objectives are set for information security:

  • Enhance Customer Data Protection
  • Improve Access Control Compliance
  • Increase Staff Security Awareness
  • Strengthen Incident Response Readiness
  • Expand Risk Assessment Coverage
  • Ensure Business Continuity Readiness

3. ROLES AND RESPONSIBLITIES

3.1  Chief Operating Officer (COO)
The CEO is responsible for the Information Security programmes of the organisation.

3.2 Executive Management
The Executive Management has the following responsibilities:

  • Communicate the importance of meeting the objectives and the need for continual improvement throughout the organisation.
  • Ensure that information security requirements are determined and are met with the aim of minimising risk and maintaining effective controls for Izwe Loans Kenya Limited and for our customers.
  • Members of Top Management comply with the Information Security Policies

3.3 IT Ops and Security Officer
The IT and Security Officer has the following responsibilities:

  • Ensure that security controls are in place and documented.
  • Responsible for the maintenance and support of the Information Security Management System
  • Manage the day-to-day maintenance of controls, including:
  • Access control (user account lifecycle)
  • Testing and implementing security patches
  • Software operation e.g., IDS, IPS, firewalls, DLP
  • System and network hardening
  • Remote access
  • Cryptographic key management
  • Log management
  • Identify and manage information security incidents according to a process.
  • Operation of processes such as incident and change management
  • Provision of technical expertise in matters of information security
  • Implementation of technical controls
  • System administration e.g., user creation, backups
  • Security monitoring e.g., network intrusions

3.4 Izwe Loans Kenya Limited User
Izwe Loans Kenya Limited users have the following main responsibilities:

  • Ensure they are aware of and comply with all information security policies of the organisation relevant to their business role.
  • Report any actual or potential security breaches.
  • Contribute to risk assessment where required.

4. EXCEPTION

  • All waivers and exceptions to any portion of this policy must be duly approved by Executive Management of Izwe Loans Kenya Limited.