Abrir menu
GL | ES | EN

Information Security Management System Policy

1. Introduction

Grupo ALDABA, aware that the security of information related to our clients, staff, and suppliers is a highly valuable resource, has established an Information Security Management System (ISMS) in accordance with ISO 27001 requirements to ensure the continuity of information systems, minimize risks of damage, and ensure compliance with established objectives.

 

2. Purpose

The Information Security Management System (ISMS) Policy aims to establish the necessary framework for protecting information resources against internal or external, deliberate or accidental threats, and to define the guidelines and general principles for information protection, enabling Grupo ALDABA to safeguard the confidentiality, integrity, and availability of the Organization’s information and that of its interested parties.

 

3. Scope

This Policy must be complied with as a minimum requirement, without prejudice to the existence of more restrictive policies and ongoing improvements to security wherever possible. It applies to and is mandatory for all employees, contractors, suppliers, and third parties with access to Grupo ALDABA’s systems and data, even after their relationship with the company has ended, as well as for all services provided by the Organization that rely on Information and Communication Technologies.
This Policy covers all information, regardless of its format or storage medium, that is owned by the Organization or entrusted to it by third parties. This Policy is implemented, maintained up to date, and communicated to all staff. It is also publicly available.

 

4. Management Commitment

The Management of Grupo ALDABA, aware of the importance of information security for successfully achieving its business objectives, is committed to fully supporting the Information Security Management System (ISMS) in accordance with ISO 27001. Specifically, it commits to:

  • Promoting awareness and dissemination of information security so that all members of the Organization understand its importance and their responsibilities.
  • Providing adequate resources to achieve information security objectives.
  • Requiring compliance with this Policy, applicable legislation, and regulatory requirements related to information security.
  • Meeting ISO 27001 requirements and ensuring continuous improvement of information security, including periodic reviews of the ISMS Policy, objectives, and responsibilities.
  • Establishing objectives and targets focused on evaluating information security performance and continuous improvement in activities governed by the Management System.
  • Implementing and maintaining this Policy, communicating it to all staff, and making it publicly available.

 

5. Objectives

Grupo ALDABA will implement all necessary measures to comply with applicable regulations on general security and IT security, including IT policies, the security of buildings and facilities, and the behavior of employees and associated third parties in the use of IT systems.
These measures must ensure the confidentiality, integrity, and availability of information, which are essential to:

  • Comply with current legislation on information systems.
  • Ensure the confidentiality of data managed by Grupo ALDABA.
  • Ensure the availability of information systems, both in customer services and internal management.
  • Guarantee responsiveness to emergencies by restoring critical services as quickly as possible.
  • Prevent unauthorized alterations to information.
  • Promote awareness and training in information security.

 

6. Responsibilities

The effectiveness and implementation of the Information Security Management System are the direct responsibility of the Information Security Committee, which is responsible for approving, disseminating, and ensuring compliance with this Security Policy.
On its behalf, an Information Security Management System Manager has been appointed, with sufficient authority to play an active role in the ISMS, overseeing its implementation, development, and maintenance.

The Information Security Committee will develop and approve the risk analysis methodology used within the ISMS.

Version 1.0, approved on February 20, 2025