QUALITY AND INDORMATION SECURITY POLICY
1 – INTRODUCTION AND OBJECTIVES
CISNERIA ENGINEERING, a company specialized in the design, development, and implementation of digital solutions, optimization systems, and engineering services for the transport sector and other industrial fields, establishes the following priorities:
- Customer satisfaction through the quality of products and services.
- Protection of information by ensuring its confidentiality, integrity, and availability.
Objectives of the Integrated Management System (IMS):
- Increase customer satisfaction through safe, reliable, and high-quality deliveries.
- Reduce information-related risks through periodic assessments and preventive measures.
- Ensure business continuity in the face of security incidents.
- Strengthen team capabilities through technical training and ISO best practices.
- Optimize internal processes through automation, digitalization, and data analysis.
2 – GUIDING PRINCIPLES OF THE IMS
At CISNERIA, we understand that service quality and information security are inseparable components in achieving excellence, operational continuity, and customer trust. Therefore, the guiding principles of our IMS are structured as follows:
The organization’s quality principles are:
Customer focus
We strive to understand, anticipate, and meet customer needs and expectations, offering solutions that deliver value, reliability, and confidence.
Leadership
Management promotes a culture of quality and excellence by aligning strategic objectives with the needs of the environment and motivating the entire team towards continuous improvement.
Employee Engagement
We foster the active involvement of all personnel through continuous training, effective communication, and recognition of well-done work as a driver of growth and improvement.
Process approach
We structure our activities based on a process approach that allows us to control and optimize each stage of the solution development lifecycle, ensuring consistent results.
Continual improvement
We consider continual improvement as a key principle to evolve, adapt to our environment, and respond effectively to market and customer challenges.
Relationship with Interested Parties
We establish sustainable, mutually beneficial relationships with clients, suppliers, and strategic partners, strengthening our value chain.
Our information security principles are:
Confidentiality
We protect information so that it is only accessible to authorized individuals, ensuring its legitimate and controlled use at all times.
Integrity
We maintain information completeness, accuracy, and protection against unauthorized modifications throughout its lifecycle, supporting the reliability of our services.
Availability
We ensure that information is available and accessible to authorized users when needed, including mechanisms that guarantee its persistence in case of contingencies.
The integration of these principles allows quality and information security to reinforce each other. A well-managed system in terms of processes, leadership, and customer orientation becomes a resilient system against technological and information risks. This integrated approach enhances:
- Customer trust in our products and services
- Operational efficiency
- Prevention of failures and vulnerabilities
- Long-term business sustainability
3 – COMMITMENT
At CISNERIA, we are fully aware that the quality of our products and services, as well as the protection of the information we manage, are essential pillars for ensuring customer trust, business continuity, and operational sustainability. We recognize that the information system supporting the design, development, and implementation of digital solutions, optimization systems, and engineering services requires adequate protection and management. To that end, we commit to the following:
Awareness and dissemination
We actively promote an organizational culture based on quality and information security. We implement continuous training and awareness programs that encourage staff participation, ensuring that individual skills contribute both to process improvement and information protection.
Regulatory and contractual compliance
We ensure strict compliance with applicable laws and regulations, as well as with contractual commitments made to our clients, especially regarding information security, personal data protection, and applicable quality standards.
Continuous improvement and performance measurement
We commit to maintaining a continuous improvement approach by regularly evaluating our processes and services through objective indicators and control mechanisms that help identify improvement opportunities in both service quality and operational security.
Proactive risk management
We conduct periodic risk assessments using recognized methodologies that allow us to evaluate exposure levels and establish preventive and corrective measures through specific policies, appropriate technical solutions, and agreements with specialized third parties. This management encompasses both quality and information security (confidentiality, integrity, and availability).
Staff commitment to system objectives
All CISNERIA personnel are actively involved in achieving the objectives set by the Integrated Management System, acting at all times with responsibility, professional ethics, and alignment with client requirements and applicable regulations.
Selection of reliable suppliers and partners
We apply strict evaluation criteria for the selection of employees, suppliers, and subcontractors to ensure they share our values in terms of quality and information security.
Incident management and transparent communication
We have established procedures for recording, analyzing, and managing incidents related to quality or information security. In the event of any weakness that compromises or could compromise our services, we act diligently, applying the necessary corrective or preventive actions and informing stakeholders within the stipulated timeframes.
Transparency and accessibility
Our integrated policy is communicated at all levels of the organization and is available to interested parties, reflecting our commitment to transparency, operational excellence, and customer satisfaction.
* This document of Quality and Information Security Policy in this website has been reviewed and approved by Management on date 24-10-2025.