At Nexmart, as a company dedicated to the development of IT solutions, we recognize the importance of protecting the information of our customers, partners, and employees. In accordance with the ISO 27001 standard, we have adopted the following Information Security Policy to ensure the confidentiality, integrity, and availability of all the data we manage.
The Information Security Policy is based on the following principles, commitments, and objectives:
Confidentiality: Ensure that only authorized individuals can access information or services.
Integrity: Ensure that information or services are presented accurately and correctly.
Availability: Meet service requirements.
Compliance with information security measures, whether documented or undocumented.
Compliance with customer, legal, and regulatory requirements relating to information security.
Continuous improvement.
Leadership: Ensure that individuals responsible for people and processes act as role models.
People’s involvement: All individuals have the autonomy and opportunity to participate in the Organization’s operations.
Mutually beneficial relationships with customers and suppliers, fostering long-term relationships based on trust.
A process-based approach:
Process-oriented approach: Customer focus, improved internal communication, and teamwork.
System approach to management: Interrelationships between processes.
Fact-based decision-making: We measure, analyze, and make decisions to drive improvement.
This policy is aligned with the Organization’s strategy and provides the framework for defining information security objectives.
All employees and subcontractors are responsible for implementing and complying with this policy.
In the event of non-compliance, disciplinary and sanctioning procedures may be initiated.
This policy is further developed through the information security regulations.
This policy is reviewed at least annually and whenever deemed necessary in response to changes in information security risks.
This policy, together with the relevant regulations, procedures, and instructions, is made available, as appropriate, to employees and other interested parties.
Version Control
Versión: 0 / Approval Date: 21 May 2024
Versión: 0 / Approval Date: 5 May 2025
Versión: 0 / Approval Date: 24 August 2026