INFORMATION SECURITY POLICY

1.General Information

1.1. Objective

The objective of this document is to establish the Information Security Policies that will govern Cima Software Corporation S.A.C.

1.2. Scope

This Information Security Policy must be approved by the Board of Directors and communicated to all individuals working at Cima Software Corporation, including both internal and external personnel.

1.3. Sanctions

The Company reserves the right to initiate legal or disciplinary actions, as applicable, against individuals or entities whose actions do not adhere to this policy.

1.4. Adherence to the Policy

Information security requires the participation and support of all individuals working at Cima Software Corporation, both internal and external. In this regard, all collaborators (employees, consultants, contractors, and temporary personnel) must appropriately use and protect information assets, complying with the Information Security Standards, Procedures, Guidelines, and Policies issued as part of this Policy and required for this purpose.

2.INFORMATION SECURITY PROVISIONS


INFORMATION SECURITY MANAGEMENT SYSTEM POLICY

Cima Software Corporation S.A.C. is an information technology company providing business solutions based on information technologies, implementation and development of solutions, electronic invoicing services, and document digitization services.

To ensure the confidentiality, integrity, reputation, corporate image, continuity of our services, protection of assets, and availability of information, we have decided to implement an Information Security Management System based on ISO/IEC 27001:2022, with the following scope:

“Information Security Management System for the electronic invoicing service as a PSE (Electronic Service Provider), document digitization service, and Development, Implementation, and Support of Solutions based on the DocuClass system,  according to the current Statement of Applicability.”

Senior Management recognizes that information is a highly valuable asset for the Organization and therefore requires adequate protection. Senior Management also establishes the following as foundational objectives, guiding principles, and support elements for information security:

  • Protection of personal data and individual privacy
  • Safeguarding organizational records
  • Documentation of the information security policy
  • Assignment of security responsibilities
  • Training and education on information security
  • Recording of security incidents and threat intelligence
  • Management of business continuity
  • Management of changes related to security within the organization

Accordingly, through the development and implementation of this Information Security Management System, the following commitments are adopted:

  • Develop products and services in compliance with applicable information security requirements, including legal, contractual, and organizational guidelines in the countries where we operate.
  • Promote continuous training in information security within the organization under a strict professional ethics framework, and take appropriate measures when any information security guideline is violated.
  • Develop business continuity management, including continuity plans that enable us to maintain operations.
  • Promote continuous improvement to increase the effectiveness of the system.
  • Communicate this policy throughout the organization and make it available to any interested party upon request.

General Management