Change History
| Version | Release Date | Edited By | Status | Modifications/ Comments |
| 01.00 | 14/02/2024 | Marsh Advisory | Published | Initial Version |
| 02.00 | 23/01/2025 | Juan Ibero | Published | 2025 Review |
Approval
| Author | Reviewed By | Approved By |
| Information Systems and Information Security Manager | Director of Technology Strategy | Enhol General Management |
| Date | Date | Date |
| 10/03/2025 | 11/03/2025 |
Distribution List
| Name | Position / Company / Unit |
| All interested parties | Grupo Enhol |
Document Description
The Information Security Policy detailing the corporate principles upon which all information security activities and initiatives within the organization shall be based.
1.1 Information Security Policy
ENHOL Group recognizes the importance of information security in the processing and management of information across the Group, its suppliers, customers and, in general, any organization or institution with which it maintains a relationship.
It is essential to establish the appropriate treatment of information throughout its entire lifecycle in order to guarantee its confidentiality, integrity and availability.
The purpose of this Information Security Policy is to provide a framework for establishing and evaluating information security objectives, which will serve as the basis for all actions undertaking in this area through the following principles:
- Establish an appropriate level of security and resilience aligned with the organization’s purpose and the needs of its stakeholders.
- Ensure compliance with all applicable legal, regulatory and contractual requirements.
- Provide the organization with procedures and tools for analysis, prevention, detection, response and recovery, enabling it to adapt quickly to changes in the technological environment.
- Raise awareness among all employees and collaborators, according to their responsibilities, regarding security risks and ensure they receive the necessary training and skills to protect the organization’s information systems.
- Ensure a continuous review and improvement process of the security management model to adapt it at all times to potential threats that may affect the organization.
- Promote prompt reporting by employees and collaborators of any information security incident.