1Introduction

The doValue Group is fully aware of the importance of information security in today’s environment, where businesses are increasingly reliant on their IT assets.

The information security management policy is a document designed to set out the doValue Group’s commitment to information protection.

All doValue Group employees, as well as suppliers and relevant third parties, must comply with this policy when accessing and using the doValue Group’s systems or when processing and handling company information.

This policy forms the basis of the Information Security Policy Framework and is set out in detail in procedures and technical instructions which elaborate in depth on each of the guidelines, activities, principles and responsibilities described in this policy.

2General objectives of information security

The aim of this policy is to provide an appropriate level of protection for the information technology (IT) assets and services provided to the doValue Group’s customers, commensurate with and consistent with the value that the information holds for the doValue Group and its customers.

To this end, Grupo doValue is committed to the following objectives relating to information security:

  • To regard information and the IT systems in which it is contained as strategic assets, thereby demonstrating its commitment to achieving the required security levels and maintaining the confidentiality, integrity, authenticity and availability of the data and information, as well as of the systems in which they are contained, in the course of carrying out its duties.
  • To establish global and local governance structures and mechanisms designed to support the effective implementation and ongoing monitoring of information security within the doValue Group and all its operating entities.
  • To establish an Information Security Committee to set out guidelines for preserving, safeguarding and strengthening the security of IT assets, thereby improving the quality of the services provided.
  • To promote the implementation of the necessary measures to ensure compliance with current legislation on information security.
  • To promote the implementation of appropriate security measures to enable the timely and effective management of security incidents that may affect doValue’s IT assets.
  • To promote ongoing training and awareness-raising initiatives on information security for all employees of the doValue Group, ensuring that this policy and any related documents are disseminated.
  • To develop an Information Security Management System (ISMS) based on international information security standards and best practices, in order to identify, quantify, prioritise and address risks, as well as to assess and review the implementation of this policy.
  • To ensure that mechanisms are in place to guarantee the continuity of the organisation’s critical activities in the event of contingencies affecting IT systems, enabling these systems to be restored within defined and acceptable timeframes.

3 Principles of the Information Security Policy

To achieve the aforementioned objectives, the doValue Group adheres to the following guiding principles:

Information Security Organisation

Establish a clear organisational structure for the management of information security across the Group.

Classification and processing of information

Define appropriate classification and handling levels based on the value and sensitivity of the information.

Authorisation at access points

To ensure that access to systems and information is granted only to authorised personnel.

Liability

Assign clear responsibilities for information security at all levels of the organisation.

Risk management

To identify, assess and manage information security risks on an ongoing basis.

Coordination

To coordinate security-related activities amongst the Group’s various departments and entities.

Safety in design

To embed security from the earliest stages of the design of systems, processes and services.

Physical and environmental safety

To protect facilities and equipment from physical and environmental threats.

Regulatory compliance

To ensure compliance with applicable legal, regulatory and contractual requirements relating to safety.

Security incident management

To detect, manage and respond effectively to information security incidents.

Business continuity

To ensure the continuity of critical operations in the event of incidents affecting the systems.

If you have any queries or would like to report a security incident, please email seguridad.informacion@altamiraam.com.