- Home
- Information Security Policy
Information Security Policy
Information Security Management System Manual Annex B. Information Security Policy – 15 January 2026
The BIVALTASA GLOVAL ADVISORY S.L. group (hereinafter, “Gloval”), aware of the importance of information security for our clients’ trust in the services we offer and of the threats that currently exist, has implemented an Information Security Management System in accordance with the ISO/IEC 27001:2022 standard (hereinafter, “ISMS”) in the business processes commercially managed by all the companies that are part of the Gloval group.
The objective of this Management System is to establish an operational and control framework, based on internationally recognized best business practices, to protect all information under Gloval’s control, as well as the various assets necessary for its processing.
This ISMS Policy, as well as all implementing regulations created within its scope, is mandatory for all personnel. Failure to comply with the provisions of these documents will have various consequences for all parties involved, including the implementation of disciplinary proceedings for internal staff or the termination of agreements between Gloval and its collaborating third parties. Gloval has established specific procedures to ensure that all personnel are aware of, understand, and comply with the ISMS Policy and all its implementing regulations.
Additionally, mechanisms have been established and are available to all stakeholders to communicate any concerns, notifications, or complaints regarding the various compliance obligations that affect Gloval or to which it has committed. The use of these means will not, under any circumstances, result in retaliation or any other detriment to those who submit notifications in good faith. In the event of risks or situations related to the commission of crimes or bribery, all Gloval personnel, as well as any third parties with whom it has a relationship, will be obligated to report these situations as soon as possible.
As a demonstration of its commitment to security, Gloval’s Management publicly makes the following commitments:
• To consider security as a comprehensive, risk-based process, continuously evaluating and managing the internal and external factors that affect the organization.
• To actively support the Management System, as well as the personnel in charge of it, providing them with the necessary resources for its performance.
• To establish a framework for defining, reviewing, and achieving the organization’s objectives, values, and strategy with respect to the service’s Management System.
• To define and assign clear and specific responsibilities, creating the corresponding organizational structure. Among other measures, Gloval has appointed an ISMS Manager and established an Information Security Committee.
• Create and promote a culture of compliance throughout the organization through annual awareness and training programs.
• Integrate risk identification and management into the entire GLOVAL service process, prioritizing actions based on their impact and probability.
• Provide the different areas of the organization with the necessary resources for the proper functioning of the ISMS.
• Proactively seek to safeguard information security in its dimensions of Confidentiality, Integrity, and Availability.
• Comply with the requirements of the ISO/IEC 27001:2022 standard.
• Comply with all applicable legal, regulatory, and contractual requirements regarding information security.
• Achieve continuous improvement of all processes related to the ISMS and to information security management.
• Ensure segregation of duties: Measures will be implemented to ensure that critical responsibilities within the ISMS are properly segregated to avoid conflicts of interest. This includes separating the functions of approval, implementation, and monitoring of security controls, promoting effective and independent oversight.
Specifically, in daily security management, the following requirements will always be considered:
• Prevention, detection, response, and retention in the event of security incidents.
• Continuous monitoring and periodic reassessment of the organizational context and associated risks.
• Clear differentiation of responsibilities throughout the organizational structure.
• Organization and implementation of the security process, ensuring compliance with the controls established in Annex A of the ISO/IEC 27001:2022 standard.
• Risk analysis and management, documenting the impact and actions.
Preventive or corrective measures.
• Authorization and control of access, implementing measures such as multi-factor authentication and regular audits.
• Protection of physical and technological facilities.
• Acquisition of certified security products and services aligned with ISMS requirements.
• Application of the principle of least privilege in access management.
• Integrity and continuous updating of the information system.
• Protection of information both at rest and in transit through encryption and access controls.
• Prevention of vulnerabilities in interconnected systems.
• Activity logging and detection of malicious code.
• Business Continuity Plan to ensure operational continuity in the event of interruptions.
• Continuous improvement of the security process through periodic reviews and lessons learned from incidents.
All documentation, records, and guidelines The documented aspects of the ISMS are managed in accordance with the documented procedures that Gloval has developed, taking into account the applicable national and international standards in each case.
The Management of Gloval