Information Security Policy
The protection of information and the systems used to process it is of strategic importance to ACTA AE in order to achieve its short- and long-term goals and, at the same time, to safeguard the privacy of the citizens it serves.
Recognizing the critical importance of information and information systems to the execution of its operational functions, ACTA AE implements an Information Security Policy aimed at:
- to ensure the confidentiality, integrity, and availability of the information it manages;
- to ensure the proper functioning of information systems;
- promptly addressing incidents that could jeopardize ACTA AE’s business operations;
- to meet legal and regulatory requirements;
- Continuously improving the level of information security.
To this end:
- The organizational structures necessary for monitoring issues related to Information Security are defined.
- Technical controls are defined to restrict access to information and information systems.
- It specifies how information is classified according to its importance and value.
- It describes the necessary measures for protecting information during the stages of processing, storage, and transmission.
- It specifies the methods for informing and training ACTA AE employees and partners on information security issues.
- It specifies the procedures for responding to information security incidents.
- It describes the methods used to ensure the secure continuity of ACTA AE’s business operations in the event of information system malfunctions or disasters.
ACTA AE conducts assessments of risks related to Information Security at regular intervals and takes the necessary measures to address them. It implements a framework for evaluating the effectiveness of information security procedures, through which performance indicators are established, describes the methodology for measuring them, and generates periodic reports that are reviewed by management with the aim of continuously improving the system.
The Information Security Officer is responsible for reviewing and monitoring policies and procedures related to Information Security and for taking the necessary initiatives to eliminateall factors that could jeopardize the availability, integrity, and confidentiality of ACTA AE’s information.
All ACTA AE employees and associates with access to ACTA AE information and information systems are responsible for complying with the rules of the applicable Information Security Policy.
ACTA AE is committed to continuously monitoring and complying with the regulatory and legislative framework and to the ongoing implementation and improvement of the effectiveness of the Information Security Management System.