Information Security Policy


ARIFA's INFORMATION SECURITY POLICY

Overview: ARIFA commits to protecting all information, in any form, against
unauthorized modification, destruction, or disclosure, through adequate security levels.
The firm reserves the right to monitor and audit information and systems to ensure
compliance with this policy.

Purpose: To establish a framework for maintaining the confidentiality, integrity, and
availability of ARIFA's data and resources using effective procedures.

Scope of Application: Applies to all employees and external providers with access to
systems within ARIFA's environment or managed in the cloud.

Key Definitions:

  • Availability: Data or information accessible to authorized individuals.
  • Confidentiality: Protection of data against unauthorized disclosure.
  • Encryption: Converting data into a code to secure its readability.
  • Information: All forms of data, including printed, electronic, and verbal.
  • Information Security: Preservation of the confidentiality, integrity, and availability of data.

Vision and Objectives: To protect customer information from all threats and ensure
security is an integral part of ARIFA’s planning, complying with laws and protecting
confidential information in a professional and ethical manner.

Roles and Responsibilities:
Security Team/Leaders: Develop and implement the policy.
Security Manager: Manages security efforts under direct supervision.
Information Owner: Responsible for creating or primarily using the information.
Custodian: Manages information processing and storage.
User: Authorized to interact with information, adhering to security policies.

Policy Organization: Structured in three levels: central policy, support policies,
and support procedures, targeted at different audiences and security needs.

Protection and Use of Information: Information of ARIFA and its clients must be
consistently protected and used only for authorized purposes, applying regardless of the
medium, location, system technology, or handlers involved.

Legal Conflict Reporting Policy: Any conflict between the security policy and existing
laws/regulations should be reported to the Security Team.

Compliance and Violation: Management must comply with policies; any incidents
should be reported to the Security Team.

Supplier Management: Suppliers must adhere to the same security standards and
follow the Supplier Management Policy before accessing information.

Client Contractual Agreements: Security standards related to handling client
information must be reviewed by the Security Team.

Policy Exceptions: Must be submitted and approved by the security team.