Information Security Policy

SMS Europa’s management is aware that its business processes depend heavily on information systems and the information they store, as well as on communications. The mission of the Information Security Policy is to establish comprehensive security guidelines for the organization and to protect its information assets. For this reason, SMS Europa has integrated information security into its overall management framework and has established an Information Security Management System (ISMS).

All users of the SMS Europa information system must fulfill a series of duties and obligations regarding information security, regardless of their job role and/or hierarchical position, and regardless of their level of access—both with respect to the handling of their own tools, data, and information, and in relation to other entities. Likewise, every user (both internal and external) must comply with the requirements of the Security Policy:

  • Confidentiality: The information processed by SMS Europa will be accessible only to authorized individuals, upon verification of their identity, at the designated time and through the designated channels.
  • Integrity: The information processed by SMS Europa will be complete, accurate, and valid, and its content will be that provided by the data subjects without any manipulation.
  • Availability: The information processed by SMS Europa will be accessible and usable by authorized and identified users at all times, and its continued availability is guaranteed in the event of any foreseeable contingency.
  • Authenticity: The information processed by SMS Europa will be verified, and the actual identity of the assets and/or parties and/or the authorization by the authorizing parties will be confirmed, along with the verification of these three aspects.
  • Traceability: The information processed by SMS Europa serves to certify that an entity’s actions can be attributed exclusively to that entity.
  • Compliance: SMS Europa will ensure compliance with all applicable laws. Specifically, this includes current regulations regarding the processing of personal data.

Through this Policy, Management assumes responsibility for supporting and promoting the implementation of the organizational, technical, and control measures necessary to comply with the security guidelines described herein.

In this regard, this Security Policy will be maintained, updated, and adapted to the organization’s objectives, in alignment with the organization’s strategic risk management framework. To this end, it will be reviewed at scheduled intervals or whenever significant changes occur, to ensure that it remains appropriate, adequate, and effective. Changes and modifications will be approved and implemented by SMS Europa Management.

Version: 05.00

Date: July 21, 2026