Integrated management policy
YMANT SERVICIOS INFORMÁTICOS, S.Lprovides IT systems management, including advice and consultancy for implementing and maintaining these systems, on-site and remote support for systems and users, and implementation of enterprise resource planning (ERP) systems. It works to integrate these services to comprehensively cover all of a company's IT needs.
Our extensive experience installing and maintaining IT systems for large companies gives us the assurance needed to offer high-quality services. We implement measures, controls, procedures and actions to protect all assets, including information and supporting processes, systems and networks, establishing policies, practices, procedures, organisational structures and software functions.
The Quality, Environmental and Information Security Policy is based on the following principles, and Management is committed to:
- Understanding stakeholders' needs and meeting their requirements, always seeking to exceed their expectations.
- Ensuring compliance with legislation and regulations applicable to quality and environmental processes, applying legal compliance to company activities and to customer and stakeholder requirements, including beyond legal minimums where economically and technologically feasible.
- Promoting employee training and awareness to improve their performance within the organisation and ensure their involvement in achieving the objectives and targets set.
- Considering management aspects as an integral part of planning processes, periodically establishing programmes, objectives and targets that ensure compliance with policy requirements and continually improve the effectiveness of the management system.
- Minimising environmental impact and preventing pollution that may arise from our activities by promoting all employees' awareness of environmental issues related to their daily work.
- Applying good practices for pollution control and environmental preservation.
- Designing preventive control measures to determine the degree of implementation of the environmental management system.
- Protecting the company's information resources and the technology used to process them against internal or external, deliberate or accidental threats, to ensure the confidentiality, integrity, authenticity, traceability, availability, legality and reliability of information.
- Continual improvement must be present in all processes.
- Protecting information appropriately regardless of how it is presented, stored or communicated.
- Protecting the company's information resources and the technology used to process them against internal or external, deliberate or accidental threats, to ensure the confidentiality, integrity, authenticity, traceability, availability, legality and reliability of information.
- Establishing methods for reporting, managing and recording incidents relating to Information Security Management Systems (ISMS).
- Defining a strict policy for backing up and storing information relevant to the company. Storage is the responsibility of qualified staff tasked with preserving and maintaining these backups in perfect condition, thereby safeguarding our competitiveness and autonomy.
- Ensuring appropriate management of access to our systems through an identification and authentication system. This both restricts third-party access and enables employees to work in a fully secure environment.
- Defining rules of conduct that ensure an appropriate balance between users' needs, security requirements and compliance with current laws.
Management extends this commitment to all stakeholders so that they follow this policy's guidelines, which will be reviewed periodically to ensure they remain appropriate to the organisation's activities.
January 2025
