In a constantly evolving technological environment, where information technology and communications are facilitating a new paradigm for work organization and where threats to information systems are ever-present and constantly evolving, we at the P4Q Group (hereinafter, P4Q) we consider it necessary to implement the ISO/IEC 27001:2022 standard in order to conduct our business activities while maintaining high security standards that protect the confidentiality, integrity, availability, and legal compliance of all information processed. Furthermore, P4Q establishes information security objectives aligned with its business strategy and expresses its commitment to the continuous improvement of its Information Security Management System (ISMS), promoting the periodic review of implemented controls, risk management, and continuous adaptation to business needs and the threat landscape, in accordance with the following guidelines:
- Confidentiality: The information processed by P4Q will be known exclusively by authorised persons, after identification, at the time and by the means authorised.
- Integrity: The information processed by P4Q will be complete, accurate and valid, and its content will be provided by those affected without any type of manipulation.
- Availability: The information processed by P4Q will be accessible and usable by authorized and identified users at all times, guaranteeing its own persistence in the event of any foreseen eventuality.
- Legality: P4Q will guarantee compliance with all applicable legislation and, in particular, the regulations in force related to the processing of personal data and information security.
The Management of P4Q, through the approval of this Policy, is committed to improving the level of maturity of information security and privacy in internal processes, implementing an Information Security and Privacy Management System that allows improving the following functions or pillars of cybersecurity:
- Identification: Understanding the current context, identifying possible threats that may materialize and that may be detrimental to P4Q.
- Protection: Establishing the appropriate technical and organizational security measures to guarantee the work of P4Q, limiting or containing the impact of a possible cybersecurity event.
- Detection: Defining the appropriate activities to identify and discover the occurrence of a cybersecurity event.
- Answer: Establishing appropriate activities to take action in the event of a security incident affecting information.
- Recovery: Promoting appropriate activities to maintain resiliency plans and restore any service or system that is affected by an incident.
Consequently, P4Q maintains the following application guidelines to be taken into account within the framework of the Information Security and Privacy Management System:
- The protection of personal data and the privacy of individuals.
- The safeguarding of the organization’s records.
- The protection of intellectual property rights.
- Documentation of information security and privacy regulations.
- The assignment of information security and privacy responsibilities.
- Education and training for information security and privacy.
- The registration of information security incidents.
- Business continuity management.
- The management of any changes that may occur in relation to information security and privacy.
