Document type
Document type: Public
Purpose
The purpose of this document is to establish the criteria applied at INNOVATION DRIVES CHANGE, S.L. to protect information system assets and preserve their integrity and privacy.
Information Security Policy
The Information Security Policy of INNOVATION DRIVES CHANGE, S.L., based on the ISO 27001 and ENS High standards, is intended to protect its information assets and the technology used to process them against internal or external threats, whether deliberate or accidental, in order to ensure their integrity, availability, and confidentiality and safeguard the Company's objectives.
INNOVATION DRIVES CHANGE, S.L. recognizes that information is a critical and highly important factor in the performance of its business. It therefore establishes policies, procedures, and controls to provide a secure environment for processing the information of the company, its clients, collaborators, and stakeholders, protecting the confidentiality, integrity, and availability of its information assets according to their value, classification, and level of risk exposure.
INNOVATION DRIVES CHANGE, S.L. is committed to continuously and proactively managing risks related to the security of its information at a level that is appropriate and proportionate to the risk being addressed. To this end, it establishes, implements, operates, and continuously improves the Information Security Management System —ISMS— under the leadership of Senior Management. The system provides a systematic approach that is audited internally and externally for risk management and the adoption of best practices and standards for information security management, in fulfillment of our statement of values and our commitment to the client within the applicable legal, regulatory, and contractual framework.
Information security objectives
The information security objectives are:
- Manage information security risks by defining and implementing the necessary technical and organizational controls to reduce them to the acceptable risk level established by the Firm.
- Foster a culture of information security among employees, collaborators, partners, and clients, and raise awareness of good practices and secure behavior for handling and protecting information.
- Maintain the confidence of clients and collaborators in the secure handling of information.
To reinforce the achievement of these objectives, Senior Management demonstrates its commitment by appointing responsible individuals at the different levels of the Firm and allocating the necessary human, technical, and financial resources.
Responsibilities of collaborators
- Understand, apply, and strictly comply with this Policy and with the framework of policies, procedures, and controls defined by INNOVATION DRIVES CHANGE, S.L. regarding information security.
- Protect the organization's own information assets, systems, and infrastructure.
- Act responsibly, professionally, and conscientiously at all times, ensuring that their actions do not affect the security of their own information or that of third parties.
- Report any identified security incidents, suspicious events, and misuse of information assets.
Compliance
In the event of non-compliance with this Policy, the Company reserves the right to apply the disciplinary measures and penalties defined by employment law, its internal work regulations, or the terms and conditions of contracts established with Company personnel.
All executives and employees are responsible for ensuring compliance with the Information Security Policy.
Effective date
This Policy is effective as of September 18, 2026.

