CORPORALABS

Information Security Policy

Objective

CORPORALABS has as one of its objectives to safeguard Information Security, whether personal or not, and to this end establishes an Information Security Management System (ISMS) aimed at reducing the risks associated with it and with Cybersecurity, ensuring that information is accessible only to those users who have a legitimate need to perform their functions, that it is protected, available and used for the purposes for which it was obtained.

Strategic objectives

  • Minimise the risks of loss of confidentiality, integrity and availability of information received, generated, processed and stored by CORPORALABS.
  • Support the company's areas in securing the information assets that support business operations and information containing personal data.
  • Raise awareness among employees regarding information security in the performance of their duties.
  • Maintain an Information Security and Cybersecurity programme that supports the organisation's strategic objectives and new business projects.
  • Comply with legal requirements, commitments made to customers and suppliers, and any regulations, internal rules or guidelines to which the company is subject.
  • Continuously improve the Information Security Management System.
  • Promote awareness and training in information security.
  • Ensure the ability to respond to emergency situations, restoring the operation of critical services in the shortest possible time.

Scope

The Information Security Policy concerns all users and applies to all information created, processed or used by CORPORALABS, regardless of the medium, format, presentation or location in which it is found.

All security measures adopted are aimed at protecting the information and the information systems that support it, including applications, operating system resources, telecommunications networks and media, and computer equipment, whether managed by CORPORALABS or by companies or personnel expressly authorised for this purpose, such as those who have signed a service provision or data processing contract with CORPORALABS, or legally authorised transferees.

Security scenarios

The Information Security and Cybersecurity Policy is focused on ensuring the following three major scenarios:

Confidentiality

Ensuring that critical, sensitive, private or personal information managed by the organisation is not stolen or accessed by unauthorised persons.

Availability

Minimising the impacts that prevent the services provided by the organisation from being accessible and usable.

Integrity

Ensuring the integrity of information systems, avoiding corruption of data or systems that affects the accuracy or integrity of information and its processing, and which could also compromise the availability of services.

Development and review

The Information Security Policy shall be developed through regulations, procedures and security instructions addressing specific aspects, and shall be reviewed at least once a year, and whenever significant changes occur in the organisation, in order to ensure that it remains appropriate to the strategy and needs of the organisation itself.

Management System

This policy applies at all CORPORALABS workplaces and is implemented within the framework of an Information Security Management System in accordance with ISO/IEC 27001:2022.

Management commitment

The Management of CORPORALABS approves and endorses this Policy, undertakes to provide the necessary resources for its compliance and for the continuous improvement of the Information Security Management System, and disseminates its contents to all personnel and interested parties as appropriate.

Approved by the Management of CORPORALABS — 17/06/2026