Founded in September 2005, agap2IT is a European organisation in the field of Information Systems, Science, and Technology. Committed to innovation, agap2IT is focused on creating real value for Clients, Employees, and other stakeholders.
The ability to operate globally, combined with the high level of experience and technical, functional, and business know-how of the team, ensures excellence in responding to the most demanding and complex challenges.
As Information is one of agap2IT's strategic assets, its protection provides added advantages for the Organisation among clients, employees, and other stakeholders. The Information Security Policy contributes to the proper management and use of information under the Organisation’s responsibility.
agap2IT's Information Security Policy defines the Information Security Principles that must be followed by all Clients, Employees, and other stakeholders, as well as outlining the levels and domains of security and their respective control objectives.
agap2IT recognises that all information managed by the Organisation must ensure and guarantee credibility with its clients, partners, and employees, and to achieve this, it is necessary to adhere to the following principles and objectives:
- Ensure and strengthen compliance with current legal regulations and requirements related to Information Security;
- Ensure the company's commitment to the Information Security Management System (ISMS);
- Ensure the confidentiality, integrity, and availability of information;
- Implement, maintain, and continuously improve appropriate procedures to minimise the occurrence of security incidents and implement accountability processes for breaches of internal policies and procedures within the ISMS;
- Promote awareness and training of all employees in the field of Information Security.
This Policy is based on the adaptation of recommended international standards, such as the ISO 27001 standard.
Information Security must be a continuous and uninterrupted effort, framed by technical and organisational measures, awareness, and training of all involved (employees, as well as third parties who, in some way, may interact with the information of the Organisation and its Clients). These parties are required to comply with and enforce all of the Organisation's information security standards and must promptly report to the CISO (Chief Information Security Officer) any event that could cause or has caused an Information Security breach. To report an incident, please send an email to security@moongy.pt.
Employees, as well as third parties, may be held disciplinarily or legally accountable in the event of non-compliance with the Information Security policies and standards established by the company.
Lisbon, November 4, 2024