Information Security Policy
INTRODUCTION
The General Information Security Policy of IT Peers – Information Technology Services, S.A. (ITPEERS) provides a common framework for all departments and business units, enabling the adoption of organizational security standards and effective practices in information security management. This Information Security Policy serves as the foundation for the information security management system, in compliance with the international standard ISO/IEC 27001:2022, EU regulations, and specific national legislation and recommendations regarding information security. By establishing its Information Security Management System (ISMS), ITPEERS adopts this policy, the commitments defined therein, integrates ISMS requirements into the organization’s processes, and ensures that the necessary resources for its implementation are available. ITPEERS is responsible to its stakeholders for acting appropriately in relation to information security management, as well as for monitoring and evaluating the implementation of the ISMS. This document outlines the general principles to be applied by each department and business unit of ITPEERS and the information assets they manage. It is structured as follows:
- Audience
- Information Value
- Importance of Information Security
- Responsibility for Information Security
- Maintenance and Communication of Security Policies
- Continuous Improvement of the Information Security Management System
- Information Security Management System Model
AUDIENCE
The ITPEERS Information Security Policy is intended for all stakeholders (employees, clients, and suppliers) and is available for consultation in the Public Information Security Management System (ISMS). All stakeholders must be aware of and act in accordance with the ITPEERS Information Security Policy and other related Information Security documents, as applicable and appropriate. Any stakeholders covered by the ISMS who deliberately violate this or other policies are subject to sanctions and other actions, which may include the possible termination of contracts for just cause and/or reporting to police or judicial authorities in cases that indicate criminal activity.
INFORMATION VALUE
Information can take various forms (printed or written on paper, stored electronically, transmitted by mail or electronic means, among others) and must be appropriately protected, regardless of its medium, use, or format. Information security should be proportionate to its importance and value. The information security officer or the business unit managers with delegated authority may grant access to information to the relevant stakeholders. Access to information is a fundamental component for the operation of ITPEERS, which relies on the availability of its infrastructures and information systems. Security in the handling and transmission of information is therefore vital to maintaining operational efficiency. Any service interruption, information leakage to unauthorized parties, or unauthorized data modification may lead to a loss of trust and/or breach obligations to stakeholders. To achieve ITPEERS’ information security objectives, departments and business units depend on the correct and expected functioning of their information systems. However, this is only possible through the continuous identification of risks to which ITPEERS’ assets are exposed, as well as the implementation of controls and security mechanisms aimed at the correct and controlled use of such assets. Information security is a fundamental prerequisite for the success of ITPEERS’ services, and it is the responsibility of all employees, suppliers, and other parties to proactively contribute to the protection or controlled sharing of sensitive information by any means, including verbal communication.
IMPORTANCE OF INFORMATION SECURITY
The information managed by ITPEERS, along with its support processes, systems, applications, and networks, are valuable assets for the company. Breaches of confidentiality, integrity, or availability may lead to a loss of credibility in ITPEERS’ services and, consequently, impact relationships with clients and suppliers. Information security must be applied throughout all phases of the ISMS lifecycle: controlling the operations of input, collection, processing, storage, transfer, interaction, retrieval, and destruction of information is an integral part of ITPEERS’ information system. It is essential to ensure the continuous and balanced maintenance of a high level of quality and security, preventing inherent risks from materializing, mitigating them, limiting potential damages resulting from the exploitation of vulnerabilities and security incidents, and ensuring that business operations function as expected over time. Threats to information security are constantly evolving, which requires the continuous adaptation of security measures to keep pace with technological, legislative, and/or social changes. Security measures should be technically and economically feasible and should not unduly limit ITPEERS’ productivity and efficiency. Residual risk is approved by management and by business unit managers who have operational responsibilities over the associated assets. The Information Security Policy described in this document aims primarily to establish ITPEERS’ overall information security guidelines. In this context, the Policy provides guidance for effective information security management in the following areas:
- People Management: Information security applies to all ITPEERS employees and should be implemented across all departments and business units, with responsibilities clearly defined for each role.
- Risk Management: All systems (existing or planned) must maintain a security level appropriate to the risk ITPEERS is willing to assume. Risk analysis should translate technical concerns in a way that is easily understood by the business.
- Definition of Responsibilities: Responsibility for the quality, access, use, and protection of information within systems lies with the data owners. ITPEERS is responsible for defining the rules and procedures that implement the information security levels set by information owners and for monitoring their effectiveness.
- Security Rules: Security policies should define the objectives to be achieved for all information systems, regardless of their environment.
- Security Procedures: Development of detailed procedures that define “what” and “how” to achieve the desired security level.
- Proper Future Operation of Information Systems: Information system operations must be properly documented to ensure that it is always possible to verify “who” does “what” and “when.”
- Doing the Right Thing: Information security is a responsibility assumed by ITPEERS.
- Knowing What is Happening: The implementation of controls addressing the risks to which the business is exposed is only effective if the controls are properly monitored to assess whether they meet the defined objectives. Additionally, timely response actions must be defined in cases where controls fail or are not operational.
INFORMATION SECURITY MODEL
The ITPEERS Information Security Model is based on the following commitments:
- Confidentiality: ensuring that information is accessible only to individuals duly authorized for that purpose;
- Integrity: safeguarding the accuracy of information and processing methods, ensuring that information has not been manipulated or altered;
- Availability: ensuring that authorized users have access to information whenever necessary.
All existing security mechanisms at ITPEERS address the confidentiality, integrity, and availability of information and are governed by a regulatory framework consisting of security policies, standards, and procedures, structured in accordance with the ISMS Manual.
The document “General Information Security Policy” primarily aims to define the value of Information Security for ITPEERS and describe its importance.
INFORMATION SECURITY OBJECTIVES AT ITPEERS
The fundamental objectives of information security at ITPEERS are briefly described as follows:
1. Data Confidentiality
- Ensure that critical information of the company, clients, and suppliers is accessible only to duly authorized individuals.
- Implement access control mechanisms, encryption, and privilege management.
2. Information Integrity
- Protect data against unauthorized or accidental modifications.
- Define safeguarding policies, version management, and validation of changes in critical systems.
3. Service and System Availability
- Ensure that information and systems are available whenever needed to support the company’s activities.
- Implement continuity plans, redundancy, and disaster recovery measures adjusted to the risk and impact of business processes.
4. Legal and Regulatory Compliance
- Ensure compliance with applicable laws and regulations (e.g., GDPR, labor laws, client requirements, etc.).
- Monitor regulatory changes and adjust internal policies accordingly.
5. Information Security Risk Management
- Identify, assess, and address risks related to threats to information.
- Reduce the likelihood and impact of security incidents.
6. Awareness and Training
- Promote a culture of information security among all employees.
- Ensure that everyone is familiar with policies, procedures, and best practices.
7. Incident Response
- Establish effective processes for detecting, responding to, and mitigating security incidents.
- Minimize impact on clients, operations, and reputation.
8. Continuous Improvement of the ISMS
- Regularly review implemented controls and policies.
- Use audits, metrics, and performance indicators to assess and strengthen the effectiveness of the system.
RESPONSIBILITY FOR INFORMATION SECURITY
The Information Security Policy is implemented across all departments and business units of ITPEERS, in collaboration with IT. Information Security Policies define the control objectives and how they should be applied across all ITPEERS departments. Top management is committed to meeting applicable information security requirements and continuously improving the ISMS. The management and coordination structure for the implementation of the ISMS is led by the Information Security Officer and their designated backup.
MAINTENANCE AND COMMUNICATION OF SECURITY POLICIES
Information security policies and standards must be reviewed annually to ensure they remain relevant and appropriate for ITPEERS, and they must be communicated to all employees within their scope of application. In this regard, procedures for their review and dissemination should be defined as follows:
- Ensure that policies are observed and reviewed, if necessary, to remain appropriate to ITPEERS’ reality;
- Ensure that all documentation is available to all employees within its scope of application.
Effective communication of information security policies and standards must also be ensured so that all employees are aware of their individual responsibilities regarding information security.
CONTINUOUS IMPROVEMENT OF THE INFORMATION SECURITY SYSTEM
Continuous improvement means that the ISMS is not static; it is always evolving, “learning” from audits, risks, incidents, and feedback to ensure that security keeps pace with technological and business changes. In the context of ISO 27001, continuous improvement should follow the following cycle:
1. Planning (Plan)
- Identify risks, legal requirements, and security objectives.
- Define policies, controls, and responsibilities.
2. Implementation (Do)
- Implement the defined controls (technological, organizational, physical).
- Promote regular training and awareness among employees.
3. Monitoring (Check)
- Measure and monitor the effectiveness of controls (KPIs, internal audits, incident reports).
- Collect feedback from stakeholders and clients.
4. Action/Correction (Act)
- Correct identified failures and implement preventive and improvement actions.
- Review and update security policies, processes, and controls, producing new versions as needed.
AUDIT PROGRAM AND SCOPE
An audit plan has been established to verify compliance with processes and procedures. The Information Security Officer is responsible for the audit program.
INFORMATION SECURITY MANAGEMENT SYSTEM MODEL
All existing information security mechanisms at ITPEERS aim to ensure the confidentiality, integrity, and/or availability of information and must be governed by a regulatory framework consisting of detailed policies, processes and procedures, and information security plans. The structure is as follows:
- Information Security Policy;
- Detailed Information Security Policies;
- Processes and Procedures;
- Plans.