Information Security Policy
RPE 01 01 / Rev:0 / November 2025
The Company Management of NPS SEGURIDAD declares its commitment to protecting and securely managing information, considering security an essential pillar for the sustainable development of our activities, our clients’ trust, and compliance with legal, regulatory and contractual requirements.
The main objective of this policy is to preserve information and the systems that process it against any internal or external threat, whether intentional or accidental, ensuring its confidentiality, integrity and availability.
Fundamental Principles
A. Confidentiality
Information will only be accessible to duly authorised persons. Technical and organisational measures will be applied to
prevent unauthorised access, information leaks or improper disclosure, ensuring the protection of personal and
corporate data.
B. Integrity
Information must be kept complete, accurate and protected against unauthorised modifications. It will be ensured that data and
documents always faithfully reflect reality, and that any change is recorded and traceable.
C. Availability
Information and systems must be available when needed for the performance of business functions. Backup mechanisms,
disaster recovery and business continuity measures will be adopted to ensure timely access to
critical information.
This policy applies to all persons who handle company information: employees, contractors, suppliers, clients and
business partners, as well as to all systems, devices and media where information is stored, processed or transmitted.
The main objectives of this policy are:
– Protect information assets against internal and external threats.
– Comply with current legislation on data protection and security.
– Promote staff security awareness and training.
– Ensure proper management of security incidents and their timely reporting.
– Maintain and continuously improve the Information Security Management System (ISMS) (SGSI).
Management assumes responsibility for implementing and maintaining the measures necessary to ensure information security,
as well as providing adequate resources for this purpose.
Each member of the organisation is obliged to comply with internal rules and to act responsibly and confidentially
when handling information.
The policy will be reviewed periodically to ensure it remains appropriate to organisational, technological or regulatory changes, and its
effectiveness will be assessed within the system’s continuous improvement process.
With this Policy, the company reaffirms its commitment to the confidentiality, integrity and availability of information,
ensuring a secure, reliable environment aligned with the principles of transparency and trust towards our clients,
employees and partners.
In Málaga, on 4 November 2025.
The Management of NAPAU SISTEMAS S.L.