{"id":15944,"date":"2025-02-14T17:18:30","date_gmt":"2025-02-14T17:18:30","guid":{"rendered":"https:\/\/compucycle.com\/?page_id=15944"},"modified":"2026-02-16T12:35:09","modified_gmt":"2026-02-16T18:35:09","slug":"quality-environmental-health-and-safety-and-information-security-policy","status":"publish","type":"page","link":"https:\/\/compucycle.com\/quality-environmental-health-and-safety-and-information-security-policy\/","title":{"rendered":"\u00a0Quality, Environmental, Health and Safety, and Information Security Policy\u00a0"},"content":{"rendered":"\n<h1>\n\t\t\tQuality, Environmental, Health and Safety, and Information Security (QEHSIS) Policy\t<\/h1>\n\t<p>CompuCycle is committed to providing solutions for the responsible, effective management and removal of end-of-life electronic assets in a manner protecting the environment, worker health and safety, our clients, and our community and protecting the confidentially, integrity and availability of information of CompuCycle and our interested parties. As a leading provider of IT recycling, privacy protection and security, and disposal services, we recognize the importance of responsible waste management, ensuring the safety and well-being of our employees, and minimizing the environmental impact of our business activities. Our goal is to provide secure, sustainable, and compliant IT recycling services while adhering to regulatory standards and industry best practices.<\/p>\n\t<h3><strong>1. Purpose<\/strong><\/h3>\n<p>To establish CompuCycle&#8217;s commitment to an Integrated Management System that ensures:<\/p>\n<ul>\n<li><strong>Quality<\/strong> of our services and processes,<\/li>\n<li><strong>Environmental<\/strong> stewardship and regulatory compliance,<\/li>\n<li><strong>Health &amp; Safety<\/strong> for employees, contractors, and visitors, and<\/li>\n<li><strong>Information Security<\/strong> of our data and systems.<\/li>\n<\/ul>\n<p>By integrating these disciplines under a single QEHSIS framework, we align with ISO 9001, 14001, 45001, and 27001 Annex A controls to drive continual improvement, risk reduction, and compliance.<\/p>\n<h3><strong>2. Scope<\/strong><\/h3>\n<p><em>This policy applies to:\u00a0<\/em><\/p>\n<ul>\n<li>All CompuCycle offices (Houston HQ, Houston SHRED, and any third-party data centers).<\/li>\n<li>All employees, contractors, and visitors.<\/li>\n<li>All processes, products, services, and IT systems managed by CC.<\/li>\n<\/ul>\n<h3><strong>3. Principles &amp; Commitments\u00a0<\/strong><\/h3>\n<p><strong>1. Customer Focus &amp; Quality:<\/strong><\/p>\n<ul>\n<li>Deliver services that meet or exceed customer requirements.<\/li>\n<li>Monitor key quality metrics (e.g., ticket resolution times, error rates) and drive corrective actions.<\/li>\n<\/ul>\n<p><strong>2. Environmental Responsibility: <\/strong><\/p>\n<ul>\n<li>Prevent pollution and minimize environmental impact (e-waste recycling, energy efficiency).<\/li>\n<li>Comply with all applicable environmental laws and regulations.<\/li>\n<\/ul>\n<p><strong>3. Health &amp; Safety: <\/strong><\/p>\n<ul>\n<li>Provide a safe workplace through hazard identification, risk assessments, and incident reporting.<\/li>\n<li>Ensure all personnel receive appropriate H&amp;S training and use required PPE.<\/li>\n<\/ul>\n<p><strong>4. Information Security: <\/strong><\/p>\n<ul>\n<li>Protect the confidentiality, integrity, and availability of CC&#8217;s information assets.<\/li>\n<li>Implement and maintain ISO 27001 controls (Access Control, Cryptography, Incident Management, etc.).<\/li>\n<\/ul>\n<p><strong>5. Integrated Risk Management: <\/strong><\/p>\n<ul>\n<li>Identify, assess, and treat risks holistically across Q\/E\/HS\/IS domains.<\/li>\n<li>Utilize a single Risk Register to capture all significant risks and treatment plans.<\/li>\n<\/ul>\n<p><strong>6. Continuous Improvement: <\/strong><\/p>\n<ul>\n<li>Conduct regular management reviews, internal audits, and performance evaluations.<\/li>\n<li>Leverage lessons learned from incidents and tests to improve the QEHSIS system.<\/li>\n<\/ul>\n<p><strong>7. Compliance &amp; Legal Requirements: <\/strong><\/p>\n<ul>\n<li>Comply with all relevant statutory, regulatory, and contractual obligations across quality, environmental, health &amp; safety, and information security.<\/li>\n<\/ul>\n<h3><strong>4. Roles &amp; Responsibilities<\/strong><\/h3>\n<table  data-tablesaw-minimap>\n\t\t\t<thead>\n\t\t<tr>\n\t\t\t<th id=\"pp-table-col-1\" scope=\"col\" data-tablesaw-sortable-col>\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\tRole\t\t\t\t\t\n\t\t\t\t\t<\/th><th id=\"pp-table-col-2\" scope=\"col\" data-tablesaw-sortable-col>\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\tResponsibility\t\t\t\t\t\n\t\t\t\t\t<\/th>\t\t<\/tr>\n\t<\/thead>\n\t\t<tbody>\n\t\t<tr data-row-index=\"1\"><td>Hamza Haroon &#8211; COO &#038; Main Security Contact (Sponsor)<\/td><td>\u2022 Approve and resource the QEHSIS Policy and IMS Manual.<br \/>\n\u2022 Review integrated performance metrics and audit findings. <br \/>\n\u2022 Ensure top-management commitment to continual improvement.<\/td><\/tr><tr data-row-index=\"2\"><td>Nidhi Shah &#8211; QEHSIS Manager (Delegate Approver)<\/td><td>\u2022 Maintain the integrated IMS Manual and QEHSIS Policy. <br \/>\n\u2022 Coordinate management reviews across all four domains.<br \/>\n\u2022 Chair the QEHSIS Steering Committee. <br \/>\n\u2022 Liaise with external auditors.<\/td><\/tr><tr data-row-index=\"3\"><td>CommTech ISMS Team<\/td><td>\u2022 Lead Information Security aspects (ISO 27001 Annex A). <br \/>\n\u2022 Support integrated risk assessments and treatment plans. <br \/>\n\u2022 Facilitate cross-domain audits and corrective actions.<\/td><\/tr><tr data-row-index=\"4\"><td>Quality Assurance Lead<\/td><td>\u2022 Monitor service delivery metrics and quality objectives. <br \/>\n\u2022 Drive corrective\/preventive actions for non-conformities. <br \/>\n\u2022 Conduct supplier quality assessments.<\/td><\/tr><tr data-row-index=\"5\"><td>Environmental Officer<\/td><td>\u2022 Track environmental objectives (energy, waste, recycling). <br \/>\n\u2022 Manage environmental permits and compliance. <br \/>\n\u2022 Investigate spills or pollution incidents.<\/td><\/tr><tr data-row-index=\"6\"><td>H&#038;S Coordinator<\/td><td>\u2022 Perform workplace inspections and risk assessments.<br \/>\n\u2022 Report and investigate H&#038;S incidents.<br \/>\n\u2022 Perform workplace inspections and risk assessments.<\/td><\/tr><tr data-row-index=\"7\"><td>BC\/DR &#038; NOC Teams<\/td><td>\u2022 Own business continuity and disaster recovery planning.<br \/>\n\u2022 Execute quarterly DR tests and monthly backup restores.<br \/>\n\u2022 Report integrated test results to the QEHSIS Steering Committee.<\/td><\/tr><tr data-row-index=\"8\"><td>Facilities Manager<\/td><td>\u2022 Ensure physical security, environmental controls (HVAC, fire suppression, leak detection). <br \/>\n\u2022 Coordinate emergency drills and evacuation exercises.<\/td><\/tr><tr data-row-index=\"9\"><td>Asset Owners &#038; Business Unit Leads<\/td><td>\u2022 Identify and classify risks within their domain. <br \/>\n\u2022 Set domain-specific objectives (e.g., quality targets, H&#038;S KPIs, security metrics).  <br \/>\n\u2022 Review and approve domain control implementations.<\/td><\/tr><tr data-row-index=\"10\"><td>All Employees &#038; Contractors<\/td><td>\u2022 Adhere to this policy and related procedures. <br \/>\n\u2022 Report hazards, incidents, or security events immediately.  <br \/>\n\u2022 Participate in required QEHSIS training and drills.<\/td><\/tr>\t<\/tbody>\n<\/table>\n\t<h3><strong>5. Integrated Risk Management &amp; Objectives<\/strong><\/h3>\n<ul>\n<li><b>Risk Register: <\/b>A consolidated log of risks across Quality, Environment, H&amp;S, and InfoSec, maintained in ITGlue under &#8220;RiskTreatmentPlan_CC_v1.0.docx.&#8221;\u00a0<\/li>\n<li><b>Objectives &amp; KPIs: <\/b>Published annually; progress tracked in BrightGauge dashboards (Quality metrics, environmental KPIs, incident rates, security incidents).\u00a0<\/li>\n<\/ul>\n<h3><strong>6. <\/strong><b>Continual Improvement &amp; Review<\/b><\/h3>\n<ul>\n<li><strong>Management Review:<\/strong> Quarterly multi-domain review chaired by Nidhi Shah.<\/li>\n<li><strong>Internal Audits:<\/strong> Annual audits covering all four domains, coordinated by the QEHSIS Manager.<\/li>\n<li><strong>Corrective Actions:<\/strong> Logged and tracked in ConnectWise PSA under &#8220;QEHSIS_NonConformity&#8221; tickets.<\/li>\n<\/ul>\n<h3><strong>7. <\/strong><b>Policy Availability and Communication<\/b><\/h3>\n<ul>\n<li><strong>Location:\u00a0<\/strong><\/li>\n<\/ul>\n<p>SharePoint \u2192 Documentation \u2192 QEHSIS \u2192 &#8211; A.5.2.1-P QEHSIS_Policy_2.0.docx &#8211; IMS_Manual_CC_v1.0.docx &#8211; Organizational_Roles_CC.xlsx\u00a0<\/p>\n<ul>\n<li><strong>Awareness:<\/strong> All staff receive QEHSIS induction training during onboarding and annual refresher sessions.\u00a0<\/li>\n<\/ul>\n\n","protected":false},"excerpt":{"rendered":"<p>Quality, Environmental, Health and Safety, and Information Security (QEHSIS) Policy CompuCycle is committed to providing solutions for the responsible, effective management and removal of end-of-life electronic assets in a manner protecting the environment, worker health and safety, our clients, and our community and protecting the confidentially, integrity and availability of information of CompuCycle and our&hellip;<\/p>\n","protected":false},"author":4,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","content-type":"","footnotes":""},"class_list":["post-15944","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/pages\/15944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/comments?post=15944"}],"version-history":[{"count":11,"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/pages\/15944\/revisions"}],"predecessor-version":[{"id":18390,"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/pages\/15944\/revisions\/18390"}],"wp:attachment":[{"href":"https:\/\/compucycle.com\/wp-json\/wp\/v2\/media?parent=15944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}