Information Security Policy

Share

Objetive

Establish Alsea’s commitment to the comprehensive protection of its information and that of its stakeholders, ensuring the confidentiality, integrity and availability of information assets across all business activities

Scope

This Global Information Security and Cybersecurity Policy (also referred to as the “Information Security Policy” or the “Security Statement”) applies to all Alsea business processes, as well as to any person who, directly or indirectly, accesses or handles Alsea information or the information of its clients, or provides services to Alsea. This includes employees, collaborators, suppliers and related third parties, regardless of the nature of their contractual relationship. All of them must be familiar with and comply with this Policy and related policies, as well as with all complementary information security documentation

Authorized areas to consult this document

It applies to the entire organization and to the general public

Definitions

Information security: The preservation of the confidentiality, integrity and availability of information. Other properties may also be involved, such as authenticity, accountability, non-repudiation and reliability (source: ISO/IEC 27000)

Stakeholder: An individual, group or organization that has a right, claim, interest or concern in a system or in a set of characteristics that satisfy their needs and expectations (source: ISO/IEC/IEEE 15288)

For more definitions, see the ISMS Terminology Manual.
Note: this manual is an Alsea-internal document and is not publicly accessible. The definitions included in this policy are those relevant for external disclosure

Information Security Statement

Alsea establishes as its purpose to safeguard information security in each and every one of its activities. This allows us to differentiate ourselves competitively, ensuring the availability and proper functioning of systems and services, and compliance with any legal, regulatory or contractual requirement related to information security and cybersecurity, including applicable regulations on data protection and privacy

It is particularly relevant to ensure effective Information Security management for our services, given the sensitivity and the volume of personal information processed. Effective management is a key control to protect people, systems and information assets, ensuring a secure and trustworthy environment. This management is led by Alsea’s Executive Management through the Global CISO Office

In conclusion, the integrity, confidentiality and availability of information and systems are critical to the security and continuity of our business, as well as to that of our clients

This Information Security Policy applies to all Alsea business processes and to all persons who have access to Alsea information or to the information of its clients, and/or who provide services to Alsea, even if their relationship is not of an employment nature. Employees, suppliers and related third parties must be familiar with and comply with this Policy and with related policies regarding the processing of information

Therefore, we commit to protecting the information of customers, employees, partners and stakeholders, reasonably considering and addressing their information security needs and expectations. This policy sets out the following key principles to guarantee the confidentiality, integrity and availability of information