ASPERIS SECURITY, S.L. as a “Cybersecurity company specialising in the offensive field, with the capacity to integrate defensive solutions, providing a comprehensive solution to organisations.”. It has implemented an information security management system within the organisation, whose main objective is to achieve the business objectives and the satisfaction of its clients while guaranteeing information security at all times through established processes founded on a process of continual improvement, guaranteeing the continuity of the information systems, minimising the risks of damage and ensuring the fulfilment of the objectives set in order to ensure at all times the confidentiality, integrity and availability of the information.
Our pillars in the provision of our services are:
- Information security in accordance with the strictest banking/medical standards
- General and evolving monitoring of privacy regulation
- Use of approved data exchange protocols and distribution channels
- Latest generation technology
- Technical team focused on needs
To this end, it assumes its commitment to information security in accordance with the reference standard ISO/IEC 27001:2022, and therefore General Management establishes the following principles:
- Competence and leadership on the part of management as a commitment to developing the Information Security Management System.
- To determine the internal and external interested parties that are relevant to the Information Security management system and to comply with their requirements.
- To understand the context of the organisation and to determine its opportunities and risks with respect to information security as a basis for the planning of actions to address them, accept them or treat them.
- To strive to guarantee the satisfaction of our clients, including the parties interested in the results of the company, in everything relating to the performance of our activities and their impact on society.
- To establish objectives and targets focused on the evaluation of performance in the field of Information Security, as well as on continual improvement in our activities, governed by the Management System that develops this policy.
- Compliance with the requirements of the applicable and regulatory legislation for our activity, the commitments made with clients and interested parties and all those internal rules or courses of action to which the company is subject.
- To ensure the confidentiality of the data managed by the company and the availability of the information systems, both in the services offered to clients and in internal management, preventing improper alterations to the information.
- To ensure the capacity to respond to emergency situations, restoring the operation of critical services in the shortest possible time.
- To establish the appropriate measures for the treatment of the risks arising from the identification and evaluation of assets.
- To motivate and train all the personnel who work in the organisation, both for the correct performance of their job and to act in accordance with the requirements imposed by the reference Standard, providing a suitable environment for the operation of the processes.
- Maintenance of fluid communication both internally, between the different levels of the company, and with clients.
- To evaluate and guarantee the technical competence of the personnel for the performance of their duties, as well as to ensure their adequate motivation for their participation in the continual improvement of our processes.
- To guarantee the correct state of the facilities and the equipment that is appropriate, in such a way that they are in correspondence with the activity, objectives and targets of the company.
- To guarantee an analysis on a continuous basis of all the relevant processes, establishing the pertinent improvements in each case, on the basis of the results obtained and the objectives established.
These principles are assumed by General Management, which provides the necessary means and equips its employees with sufficient resources for their fulfilment, setting them out and making them publicly known through this Information Security Policy.