NEOVANTAS CONSULTING, S.L., an international consultancy that accelerates business growth through the use of advanced analytics and the application of Behavioral Economics, has implemented an Integrated Management System (IMS) based on the requirements of the standards ISO 9001:2015 (Quality Management), ISO 14001:2015 (Environmental Management), and ISO 27001:2022 (Information Security Management), with the objective of ensuring the satisfaction of its clients and other interested parties, the protection of the environment, and the confidentiality, integrity, and availability of information assets and resources, ensuring the continuity of business lines, minimizing damage, and maximizing return on investment and business opportunities, all within a framework of continuous improvement.
The Management of NEOVANTAS CONSULTING, S.L., through the maintenance of its Integrated Management System (IMS), makes the following commitments:
Regarding Information Security (ISO 27001:2022):
Develop solutions and services compliant with legislative requirements, identifying for this purpose the applicable legislation to the business lines developed by the organization and included in the scope of the ISMS:
- Establish and fulfill contractual requirements with interested parties.
- Build and maintain the trust of clients, employees, and regulators.
- Provide information security training and awareness programs for all employees and other interested parties.
- Prevent and detect any viruses and other malicious software, through the development of specific policies and the establishment of contractual agreements with specialized organizations.
- Perform information security risk assessments to identify and implement controls to mitigate the impact of identified risks.
- Develop and maintain business continuity and disaster recovery plans.
- Establish the consequences of security policy violations, which will be reflected in the contracts signed with interested parties, suppliers, and subcontractors.
- Promote a culture of continuous improvement in information security management and implement improvements based on the analysis of incidents, audits, and periodic reviews.
- Act at all times in accordance with the strictest professional ethics.
- Ensure that access and use of information systems is carried out securely and in compliance with established policies.
- Maintain the brand’s reputation regarding data security.
- Adequately manage the information lifecycle, so that misuse can be prevented at any stage.
- The organization’s personnel will participate in the management of incidents related to services and information security management, with the aim of restoring normal service operating levels as quickly as possible and minimizing the adverse impacts of such incidents on the organization.
- Ensure the protection of intellectual property rights.
- Periodically establish a set of objectives and indicators, allowing management to carry out adequate monitoring of the offered service levels and management activities.
- Management commits to providing the necessary resources to maintain and improve the Information Security Management System (ISMS), integrated within the organization’s Integrated Management System (IMS).
Regarding Quality (ISO 9001:2015):
- Understand and satisfy client requirements and expectations, delivering rigorous, reliable, and high-value-added consulting services that increase their trust and satisfaction.
- Comply with legal, regulatory, contractual, and other requirements applicable to the services provided, periodically evaluating their degree of compliance.
- Manage the organization through a process-based approach and risk-based thinking, planning and implementing actions to address identified risks and opportunities.
- Ensure the competence and continuous training of people, fostering a culture of quality and continuous improvement at all levels of the organization.
- Transfer quality criteria to the supply chain, establishing qualification and evaluation requirements for suppliers and subcontractors who may affect service conformity.
- Establish, review, and periodically monitor measurable quality objectives consistent with this policy, as part of Management review.
- Continuously improve the suitability, adequacy, and effectiveness of the Integrated Management System and its quality performance.
Regarding Environment (ISO 14001:2015):
- Protect the environment, including the prevention of pollution, through the identification and control of significant environmental aspects associated with the organization’s activities, services, and operations.
- Comply with applicable legal, regulatory, and other environmental requirements, periodically evaluating their level of compliance.
- Promote the efficient use of energy, water, and materials, minimizing waste generation and ensuring its correct management and traceability, including Waste Electrical and Electronic Equipment (WEEE).
- Contribute to climate change mitigation by reducing the carbon footprint of the activity, especially that derived from travel and energy consumption, and promoting efficient and sustainable work.
- Identify potential environmental emergency scenarios and maintain preparedness and response plans that allow preventing or mitigating the impacts.
- Foster awareness and participation of all personnel in environmental protection and compliance with established good environmental practices.
- Establish, review, and periodically monitor measurable environmental objectives, and continuously improve the organization’s environmental performance.
The Management of NEOVANTAS CONSULTING, S.L. commits to providing the necessary resources to maintain, periodically review, and continuously improve the Integrated Management System (IMS). This policy is maintained as documented information, communicated, understood, and applied within the organization, and is available to interested parties upon request.
Signed: President
JOSÉ LUIS CORTINA MUGURUZA