LEGALIDAD
This Information Security Policy is established to protect the confidentiality, integrity, and availability of the information assets of Sentisis. It complies with the ISO/IEC 27001 standard and applies to all employees, contractors, and third-party users who access or use the information assets of Sentisis.
The purpose of this policy is to ensure the protection of information assets from all threats, whether internal or external, deliberate or accidental. It aims to ensure compliance with all applicable laws, regulations, and contractual obligations.
The policy establishes a framework for setting, reviewing, and achieving information security objectives and defines the responsibilities of employees, contractors, and third-party users in protecting the information assets of Sentisis.
Additionally, the policy aims to promote awareness, educate employees, and guide decision-making processes related to information security within the organization.
Sentisis, a company dedicated to converting all available information into useful insights that translate into relevant solutions and concrete actions that allow our clients to anticipate and lead their markets, has decided to introduce an Information Security Management System , to improve the services provided to its clients.
This policy applies to all information assets owned, leased, handled or otherwise controlled by Sentisis including information stored on physical or electronic media, information transmitted over networks or through any communication channels, and information processed or handled by employees, contractors, or third-party users.
The primary objectives of this policy are to protect the confidentiality of information to prevent unauthorized disclosure, ensure the integrity of information to prevent unauthorized modification, and ensure the availability of information to authorized users when needed.
Additionally, the policy seeks to ensure compliance with applicable laws, regulations, and contractual obligations such as the General Data Protection Regulation (GDPR), the Spanish Data Protection Act (LOPDGDD),Law 10/2021 on Remote Work, etc.. while continuously improving the information security management system (ISMS).
Sentisis Management is responsible for providing leadership and commitment to information security. They ensure that adequate resources are available to implement and maintain the information security management system and review and approve information security policies and procedures.
The Information Security Management System Responsible (ISMS Responsible) is responsible for developing, implementing, and maintaining the information security management system. This includes conducting risk assessments, implementing appropriate controls, and reporting on the effectiveness of the information security management system to senior management.
Employees, contractors, and third-party users are responsible for complying with this policy and all related information security procedures. They must report any suspected information security incidents or vulnerabilities to the ISMS Responsible and participate in information security training and awareness programs.
Aligned with our commitment to safeguarding information assets and maintaining the integrity of our operations, we have established a comprehensive set of security measures. These measures encompass a range of strategies and technologies aimed at protecting our systems, data, and resources from potential threats, ensuring the confidentiality, integrity, and availability of information critical to our business.
Sentisis is committed to the principle of continuous improvement in its information security management practices. Regular assessments and reviews are conducted to identify areas for enhancement in the ISMS. Feedback from audits, incident reports, and employee suggestions are systematically evaluated to implement improvements. Metrics and performance indicators are monitored to measure the effectiveness of information security controls and to identify opportunities for refinement. Continuous improvement efforts ensure that the ISMS remains effective, responsive to emerging threats, and aligned with the strategic objectives of Sentisis.
Sentisis reserves the right to audit and/or monitor employee activities and information handled through information systems.
All employees are expected to adhere to the Information Security Policy and Topic-Specific Policies, and failure to comply will result in appropriate disciplinary measures proportional to the violation committed.