Information Security Policy

Last update: 21/11/2024. Revision 00

UNATEC, a company dedicated to offering solutions based on custom software development, specializes in companies in the energy sector. It has decided to implement an Information Security Management System based on the ISO 27001 standard to preserve the confidentiality, integrity, and availability of information and protect it from a wide range of threats. This Management System aims to ensure the continuity of business lines, minimize damage, maximize return on investment and business opportunities, and support continuous improvement.

The management of UNATEC recognizes that information is an asset of high value to the organization and, therefore, requires adequate protection.

UNATEC’s management sets the following baseline objectives as the starting point and support for the objectives and principles of information security:

  • Protection of personal data and individuals’ privacy
  • Safeguarding the organization’s records
  • Protection of intellectual property rights
  • Documentation of the information security policy
  • Assignment of security responsibilities
  • Training and capacity-building for information security
  • Logging of security incidents
  • Management of business continuity
  • Management of changes related to security in the company

Through the development and implementation of this Information Security Management System, UNATEC’s management commits to the following:

  • Provide services compliant with legislative requirements by identifying the applicable legislation for the business lines developed by the organization within the scope of the Information Security Management System.
  • Establish and fulfill contractual requirements with stakeholders.
  • Define training requirements in security and provide the necessary training to stakeholders through the establishment of training plans.
  • Prevent and detect viruses and other malicious software by developing specific policies and establishing contractual agreements with specialized organizations.
  • Manage business continuity by developing continuity plans in line with internationally recognized methodologies.
  • Establish the consequences of violations of the security policy, which will be reflected in the contracts signed with stakeholders, suppliers, and subcontractors.
  • Act at all times with the utmost professional ethics.

This Policy provides the framework for the continuous improvement of the Information Security Management System and for setting and reviewing the objectives of the Information Security Management System. It is communicated throughout the organization via the document management system installed within the company, reviewed annually for its suitability, and exceptionally when special situations and/or substantial changes to the Information Security Management System occur, being available to the general public.