Legal information

ISMS Policy

1.

Introduction

Open HealthCare S.L. is aware of the importance of information security, particularly regarding employees, clients and business processes, and has implemented an information management system based on the ISO 27001 standard.

In order to develop the organisation’s express commitment to continuous improvement of the management system, Management sets out the following information security management principles.

2.

Information security management principles

  • Knowledge and application, by all employees and collaborators, according to their role within the company, of security policies and procedures, both general and those that may apply to specific groups, including:
    • Access control, opening and closing of premises.
    • Information and handling of visits to the premises.
    • Security training, awareness and motivation.
    • Awareness of roles and responsibilities.
    • Business continuity management.
    • Consequences of failing to comply with security policies.
    • Support in the management of information security.
    • Compliance with legislation.
    • User best practices manual.
  • Diligence on the part of all employees and collaborators in reporting possible security incidents.
  • Ensuring that the procedures determining the confidentiality, integrity, availability, traceability and authenticity of information are complied with.
  • Support for the security organisational structure established to meet the information security control objectives and ongoing risk management.
  • Guaranteeing the correct use of facilities and equipment so that they correspond to the organisation’s activity and objectives.
  • Commitment to protecting the safety and health of its workers, as well as to establishing an appropriate working environment.
  • Structuring our management system so that it is easy to understand.
3.

Policy management and communication

The management of our system is entrusted to the Management Officer, and the system will be available on our information system in a repository, which can be accessed according to the access profiles granted under our current access management procedure.

This policy is complemented by the other policies, procedures and documents currently in force to develop our management system.

These principles are adopted by Management, who has the necessary resources for their implementation, and are communicated for compliance to all employees and collaborators of the company through this Information Security Policy.