With reference to ISO 9001:2015, ISO 14001:2015, ISO 27001:2013 and ISO 50001:2011*
Extract from the Quality, Environment, Energy and Information Security Policy
Continuing to assess risks and opportunities thoroughly is a key part of Aruba's corporate culture. Every day, we take on responsibility for protecting and making the most of all our resources:
- our customers and the trust that they place in us;
- our information assets, with data centers certified at the highest levels;
- our professionals, who boast technical and cross-disciplinary knowledge;
- our environmental and energy resources, assets that belong to all the countries in which we work.
We are committed to developing an Information Security culture as one of our shared values to inspire our day-to-day activities. We do this in accordance with measures designed to guarantee the confidentiality, integrity and availability of the information we store and transmit, depending on how critical and sensitive they are, and on their value.
This means that day after day, we can increase the trust of customers, suppliers and the community in general, along with our ability to manage processes in a controlled way.
We are dedicated to fulfilling our obligations in terms of compliance, by optimizing and mitigating the use of non-renewable environmental resources, and by favouring renewable energy sources and solutions that are more energy efficient.
Read the objectives of our policies
The purposes of this document are:
- to make sure that the Management System always complies with international standards in relation to the objectives the company has set for itself;
- to guarantee the consistency, precision and timeliness of the service offered;
- to put together external information on a regular basis, in order to make sure the service provided can always be improved;
- to improve the efficiency, repeatability over time and reliability of the performance of all processes, in particular by using written, therefore certain, procedures;
- whenever practically possible, to choose the best technological solutions in terms of their energy and environmental impact;
- to secure and maintain a competitive advantage over competitors in terms of the saleability of the service and market penetration - thanks among other things to excellent value for money - with the resulting increase in corporate profitability;
- to prevent and correct instances of non-compliance efficiently;
- to make sure at all times that the client's/market's demands and expectations are met; these must be identified as clearly and quickly as possible, whether in writing, verbally or implicitly;
- to strive to improve by offering services that meet demand in terms of suitability for use, performance, security, reliability and maintainability;
- to fulfil the obligations stipulated by the Authorities and/or Government Agencies as well as by the client;
- to organize the appropriate records, statistics and reports and appropriate analysis methods to assess the efficiency of its own corporate processes in terms of predefined objectives;
- to promote and share the principle of continuous improvement of services in terms of Quality, the Environment, Energy and Information Security;
- to involve all staff in the sharing of the company's objectives and values;
- to measure the success and efficiency of the Management System for Quality, the Environment, Energy and Information Security by carrying out periodic reviews;
- to guarantee the availability of information and services, which includes having specific business continuity plans;
- to ensure the confidentiality of information when restricted access is required;
- to prevent changes to and the loss of information assets;
- to raise awareness among, and educate, staff, partners and third parties about the company's environment policy, the need for security and data and information protection, as well as about everyone's roles and responsibilities;
- to establish incident identification and management procedures (incident handling, data breaches) to respond to emergencies or incidents that might arise during activities quickly, efficiently and meticulously;
- to provide the customer and/or any other person concerned with the information needed to exercise their rights relating to personal data as stipulated by the regulation in force;
- to implement appropriate technical and organizational measures to make sure that, by default, only personal data needed for each individual purpose for processing is actually processed;
- to secure a profit for the Aruba Group.
*Certification process underway