Security policy
INFORMATION SECURITY MANAGEMENT SYSTEM POLICY
Ecomanagement Tecnology (ECOMT), aware that the security of information relating to our clients is a highly valuable resource, has established an Information Security Management System in accordance with the requirements of the ISO/IEC 27001:2022 standard to ensure the continuity of information systems, minimize the risk of damage and ensure compliance with the objectives set.
This Policy is established in order to guide the management of the organization. This guidance is set out in the following directives:
The objective of the Security Policy is to set the framework of action necessary to protect information resources against threats, whether internal or external, deliberate or accidental, in order to ensure compliance with the confidentiality, integrity and availability of the information.
The effectiveness and application of the Information Security Management System is the direct responsibility of the Information Security Committee, which is responsible for the approval, dissemination and compliance of this Security Policy. On its behalf and representation, an Information Security Management System Manager has been appointed, who has sufficient authority to play an active role in the Information Security Management System, overseeing its implementation, development and maintenance.
The Information Security Committee will develop and approve the risk analysis methodology used in the Information Security Management System.
Any person whose activity may be directly or indirectly affected by the requirements of the Information Security Management System is obliged to strictly comply with the Security Policy.
At ECOMT, all necessary measures will be implemented to comply with the applicable regulations regarding security in general and IT security, relating to IT policy, the security of buildings and facilities, and the behavior of employees and third parties associated with ECOMT in the use of IT systems.
The measures necessary to guarantee information security through the application of standards, procedures and controls must make it possible to ensure the confidentiality, integrity and availability of the information, which are essential to:
- Comply with current legislation regarding information systems.
- Ensure the confidentiality of the data managed by ECOMT.
- Ensure the availability of information systems, both in the services offered to clients and in internal management.
- Ensure the integrity of information systems, so that they are accurate and reliable and have not been modified accidentally or intentionally by unauthorized third parties.
- Ensure responsiveness to emergency situations, restoring the operation of critical services in the shortest possible time.
- Prevent improper alterations to the information.
- Promote awareness and training in information security.
PSI V1
JUNE 2024