Integrated Management System Policy

ARUMEL’s general policy is based on providing services that fully satisfy our clients. We are firmly committed to maintaining the confidentiality, integrity, authenticity, traceability and availability of information, always in strict compliance with all applicable legal and regulatory requirements, as well as contractually applicable codes, standards and specifications.

ARUMEL’s Management:

  • Promotes the maintenance and continual improvement of an Integrated Management System (IMS), which includes Quality, based on the UNE-EN ISO 9001 standard, and Information Security, based on the National Security Scheme and the UNE-EN/ISO-IEC 27001 standard. This system promotes maintenance and continual improvement throughout the organisation, deploying all resources deemed necessary to strengthen these foundations and to achieve our objectives.
  • Maintains its commitment to meeting client requirements, feasible from both technological and human perspectives, with the commitment to preserving the confidentiality, integrity and availability of information. Strict compliance with applicable legal and regulatory requirements, as well as the codes, standards and specifications established by contract, constitutes the fundamental basis of our business activity.
  • Commits to carrying out our work within an environment that ensures continual improvement, through the establishment and periodic review of our quality and security objectives.
  • Fosters a culture of innovation aligned with its continual improvement and focused on enhancing innovation in its products and services, in its processes and in its organisational management.
  • Commits to conducting its activity while reducing risks in its services, both internal and external and both technical and human, thereby increasing the availability of our resources.
  • Aims to provide the best technical, human and user service, measuring the commitments established with users. Seeks to integrate suppliers, providers, collaborators and partners to a greater extent, aligning them with the services they provide.
  • Promotes ongoing training and awareness among personnel, with the aim of improving their contribution to the company while enhancing their creativity, teamwork and innovative spirit.
  • Seeks to reduce or eliminate risks or impacts on ARUMEL’s activity that may arise from potential information security failures, taking into account the consequences of any loss of confidentiality, integrity or availability of existing assets.
  • ARUMEL defines, as its general policy, the provision of services with a commitment to maintaining the confidentiality, integrity, availability, traceability and authenticity of information, always in strict compliance with current legal and regulatory requirements.
  • Promotes the maintenance and continual improvement of a Security Management System, based on the National Security Scheme and the UNE-EN/ISO-IEC 27001 standard, deploying all necessary resources and ensuring compliance with its security measures to strengthen these foundations and achieve its objectives.
  • Encourages the reduction or elimination of risks or impacts on ARUMEL’s activity that may arise from potential security failures, taking into account the consequences of any loss of confidentiality, integrity, availability, authenticity or traceability of existing assets.
  • Each year, it formulates information security objectives and monitors them, verifying compliance and establishing the necessary measures should such compliance be at risk.

ARUMEL’s Management, as well as all the organisation’s personnel, understand the importance of this policy and integrate it into their working practices. To this end, Management takes the necessary measures to ensure that it is disseminated at all levels and sets annual objectives to improve quality and information security, maintaining a continual improvement process.

This policy is disseminated to all personnel and ensures that the Integrated Management System Policy and internal regulations are understood by all personnel in the organisation and other interested parties.

Certificación de conformidad con el ENS
ISO 27001
ISO 9001