Security Policy

 

1. The Organization’s Mission

Valpatek’s mission is to provide specialized professional services in technology and digital transformation, supporting its clients in defining, implementing, and evolving solutions that optimize their business processes and enhance the user experience.

We bring expertise, a personal touch, and a commitment to ensuring high-quality projects that are tailored to the actual needs of each organization.

To achieve its objectives, VALPATEK is committed to information security and to managing information appropriately, in order to provide all its stakeholders with the highest level of assurance regarding the security of the information it uses.

These systems must be managed with due diligence, taking appropriate measures to protect them against accidental or intentional damage that could affect the availability, integrity, or confidentiality of the information processed or the services provided.

The goal of information security is to ensure the quality of information and the continuous provision of services by taking preventive measures, monitoring daily operations, and responding promptly to incidents.

ICT systems must be protected against rapidly evolving threats that have the potential to impact the confidentiality, integrity, availability, intended use, and value of information and services. To defend against these threats, a strategy is required that adapts to changes in environmental conditions to ensure the continuous delivery of services. This means that departments must implement the minimum security measures required by the National Security Framework, as well as continuously monitor service delivery levels, track and analyze reported vulnerabilities, and prepare an effective incident response to ensure the continuity of services provided.

The various departments must ensure that ICT security is an integral part of every stage of the system’s life cycle, from its conception through its decommissioning, including development and procurement decisions as well as operational activities. Security requirements and funding needs must be identified and included in planning, requests for proposals, and bid documents for ICT projects.

Departments must be prepared to prevent, detect, respond to, and recover from incidents, in accordance with Article 8 of the ENS (Article 8. Prevention, Detection, Response, and Preservation).

 

2. Scope

This policy applies to all of the organization’s ICT systems and to all members of the organization involved in services and projects for the public sector that require the implementation of ENS, without exception.

 

3. Objectives

Based on the foregoing, Management has established the following information security objectives:

➔ Provide a framework to build resilience in order to ensure an effective response.
➔ Ensure the rapid and efficient restoration of services in the event of any physical disaster or contingency that could occur and jeopardize the continuity of operations.
➔ Prevent information security incidents to the extent that is technically and economically feasible, and mitigate the information security risks arising from our activities.
➔ Ensure the confidentiality, integrity, availability, authenticity, and traceability of information.

 

4. Development

To achieve these goals, it is necessary to:

➔ Continuously improve our information security system.
➔ Identify potential threats, as well as the impact on business operations that such threats could have if they were to materialize.
➔ To safeguard the interests of its key stakeholders (customers, shareholders, employees, and suppliers), its reputation, its brand, and its value-creation activities.
➔ Work closely with our suppliers and subcontractors to improve the delivery of IT services, service continuity, and information security, thereby increasing the efficiency of our operations.
➔ Evaluate and ensure the technical competence of staff, as well as ensure they are sufficiently motivated to participate in the continuous improvement of our processes, by providing appropriate training and internal communication so they can implement the best practices defined in the system.
➔ Ensure that facilities are in good condition and that appropriate equipment is available, so that they are consistent with the company’s activities, objectives, and goals.
➔ Ensure the ongoing analysis of all relevant processes, implementing the appropriate improvements in each case based on the results obtained and the established objectives.
➔ Structure our management system so that it is easy to understand. Our management system has the following structure:

Management of our system is entrusted to the IT Systems Manager, and the system will be available in our information system within a repository, which can be accessed based on the access profiles granted in accordance with our current access management procedure.

The documentation related to system security is organized into folders within the company’s Google Drive, divided into subfolders named after regulatory requirements and operational frameworks, which contain the various procedures, records, and evidence, with access restricted to company personnel, and unauthorized external personnel cannot access them.

The safety documentation is organized as follows:

● Security Policy.
● Safety regulations: documents that describe the use of equipment, services, and facilities.
● Specific documents: security documentation developed in accordance with the applicable CCN-STIC guidelines.
● Safety procedures: documents that detail how to operate the system’s components.

This policy complements the other policies, procedures, and documents currently in effect to implement our management system.

 

5. Professionalism and Safety of Human Resources

This Policy applies to all VALPATEK employees and external personnel who perform work within the company.

HR will include information security responsibilities in employee job descriptions, inform all newly hired staff of their obligations regarding compliance with the Information Security Policy, manage confidentiality agreements with staff, and coordinate user training related to this Policy.

● The Chief Information Security Officer (CISO) is responsible for monitoring, documenting, and analyzing reported security incidents, as well as for communicating with the Information Security Committee and the information owners.
● The Information Security Committee will be responsible for implementing the necessary means and channels to enable the Chief Information Security Officer (CISO) to handle reports of incidents and system anomalies. The Committee will also stay informed, oversee the investigation, monitor developments, and facilitate the resolution of information security incidents.
● The Head of Security Management (RGS) [CISO] will participate in drafting the Confidentiality Agreement to be signed by employees and third parties performing duties at VALPATEK, in advising on the penalties to be imposed for noncompliance with this Policy, and in handling information security incidents.
● All VALPATEK employees are responsible for promptly reporting any information security vulnerabilities and incidents they detect.

 

6. System Integrity and Updates

VALPATEK is committed to ensuring the integrity of the system through a change management process that allows for the control of updates to physical or logical elements by requiring authorization prior to their installation in the system. This assessment will be carried out primarily by the systems management team, which will evaluate the impact on system security before making the changes and will document and monitor any changes that are assessed as significant or that have implications for system security.

Through periodic security reviews, the security status of the systems will be assessed in relation to manufacturers’ specifications, vulnerabilities, and applicable updates, and we will respond promptly to manage risk based on their security status.

 

You can request the full policy by emailing dpo@valpatek.com

Approved on January 22, 2026, by Management

Valpatek
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.