SUSTAINABILITY POLICY
To be a model company in compliance and corporate sustainability, from the development of methodologies and technologies to support our clients, as well as in internal management as a global company of the 21st century, contributing in a deep and broad way to the global transformation process towards sustainable human development.
Purpose
It establishes the framework for the management of sustainable development for GISMA and our stakeholders, based on regulatory compliance and global corporate sustainability standards, seeking the implementation of a business model that generates high value for all stakeholders of our company.
Scope
It provides guidelines for the sustainable development of GISMA and SIGEA Software; it is a core part of our business strategy and its metrics are communicated through the Sustainability Report.
Dimensions of the policy
Consideration of stakeholders
• Environment
• Integrated Management
• Human Rights
1. CONSIDERATION OF STAKEHOLDERS
GISMA will establish and maintain relationships of trust and mutual benefit with the defined interest groups; will consider their interests and expectations, and will seek opportunities for the creation of social, environmental and economic value.
A. Collaborators/Workers
GISMA will promote the development of people and maintain fair labor practices, in a safe and healthy work environment.
GISMA considers health and safety within its Pillars of the Business Strategy, strengthening working conditions for all its collaborators and self-care.
GISMA will promote the necessary skills to improve knowledge, skills and abilities in order to be able to carry out its organizational development plan, and strengthen the management of collaborators.
B. Community
GISMA will maintain a harmonious coexistence with the communities neighboring its physical facilities and will develop collaboration plans with social development, contributing from the company's knowledge area, such as sustainability, environment and digital transformation, contributing to improve the quality of life of neighbors and promote local development.
C. Suppliers, contractors and business partners
GISMA is committed to ensuring fair operational practices with suppliers, contractor companies and business partners, complying with high quality standards and transparency in access to relevant information for them. Likewise, alignment will be promoted, by suppliers, with safety, health and environmental standards and criteria, including strict adherence to labor regulations, risk control and prevention of socio-environmental impacts.
D. Clients
For GISMA, ensuring the expectations and requirements agreed with customers in terms of quality, quantity and opportunity is part of its Business Strategy Pillars. GISMA will increase the capacity to offer high quality products and services and impact to its clients and users, implementing operational improvements and generating increasingly competitive offers, based on efficiency and innovation.
E. Authorities
GISMA is committed to the authorities to comply with legal and ethical standards that apply to business operations, based on regulatory compliance management and the implementation of good practices. This stakeholder is highly relevant to the business strategy as it is the one that defines the applicable regulatory framework, the pillar of our value offer. It will tend to facilitate the relationship between our clients and the authority seeking the symmetry of information for all parties and generate digital flows of information for reportability and for the reception of regulatory changes.
F. Shareholders
GISMA is committed to managing management processes that guarantee a fiduciary performance that fully represents the interests of the shareholders, harmoniously guaranteed with the generation of value for all interested parties.
1. CONSIDERATION OF STAKEHOLDERS
GISMA will establish and maintain relationships of trust and mutual benefit with the defined interest groups; will consider their interests and expectations, and will seek opportunities for the creation of social, environmental and economic value.
A. Collaborators/Workers
GISMA will promote the development of people and maintain fair labor practices, in a safe and healthy work environment.
GISMA considers health and safety within its Pillars of the Business Strategy, strengthening working conditions for all its collaborators and self-care.
GISMA will promote the necessary skills to improve knowledge, skills and abilities in order to be able to carry out its organizational development plan, and strengthen the management of collaborators.
B. Community
GISMA will maintain a harmonious coexistence with the communities neighboring its physical facilities and will develop collaboration plans with social development, contributing from the company's knowledge area, such as sustainability, environment and digital transformation, contributing to improve the quality of life of neighbors and promote local development.
C. Suppliers, contractors and business partners
GISMA is committed to ensuring fair operational practices with suppliers, contractor companies and business partners, complying with high quality standards and transparency in access to relevant information for them. Likewise, alignment will be promoted, by suppliers, with safety, health and environmental standards and criteria, including strict adherence to labor regulations, risk control and prevention of socio-environmental impacts.
D. Clients
For GISMA, ensuring the expectations and requirements agreed with customers in terms of quality, quantity and opportunity is part of its Business Strategy Pillars. GISMA will increase the capacity to offer high quality products and services and impact to its clients and users, implementing operational improvements and generating increasingly competitive offers, based on efficiency and innovation.
E. Authorities
GISMA is committed to the authorities to comply with legal and ethical standards that apply to business operations, based on regulatory compliance management and the implementation of good practices. This stakeholder is highly relevant to the business strategy as it is the one that defines the applicable regulatory framework, the pillar of our value offer. It will tend to facilitate the relationship between our clients and the authority seeking the symmetry of information for all parties and generate digital flows of information for reportability and for the reception of regulatory changes.
F. Shareholders
GISMA is committed to managing management processes that guarantee a fiduciary performance that fully represents the interests of the shareholders, harmoniously guaranteed with the generation of value for all interested parties.
2. ENVIRONMENT
GISMA will promote environmental, social and governance responsibility in all its business areas, complying with the applicable regulatory frameworks, as well as the principles and agreements voluntarily signed.
The company will act under a Social Responsibility framework, consistent with corporate values, such as the GISMA Corporate Environmental Management Standard, United Nations Global Compact Principles, international standards and industry best practices.
GISMA is constantly in search of innovations that allow the possible environmental impacts generated by the company and its clients to be reduced, generating spaces for the dissemination of useful methods and concepts for clients, suppliers and society as a whole.
GISMA will promote a continuous improvement of energy efficiency in all the activities of the Company.
GISMA participates in multisectoral alliances to contribute to society, through knowledge management initiatives, innovation, social inclusion, environmental education and biodiversity conservation.
3. INTEGRATED MANAGEMENT
GISMA will promote and support the continuous improvement of the sustainability of the company through integrated management systems, establishing indicators that allow evaluating, verifying and reporting the fulfillment of objectives and goals, involving all interested parties (considering third-party workers, contractors and workers own, among others) and thus improve the results in operational, commercial and administrative excellence, including safety in facilities and for people, as a priority labor element.
GISMA will promote the incorporation of sustainability criteria at a transversal level, in the different processes and lines of business.
4. HUMAN RIGHTS HR
GISMA undertakes to identify, prevent and mitigate any negative impact of operations in Chile and abroad, respecting and adapting the particularities of each place where its operations are located.
GISMA is based on the fundamental principles of Human Rights, regarding its culture and associated risks, in accordance with the UN Guiding Principles on Business and Human Rights, as well as the principles of the International Covenant on Civil and Political Rights and the Covenant International Economic, Social and Cultural Rights.
GISMA promotes respect for human rights, particularly of minorities and the most vulnerable groups, and rejects any form of discrimination. The company is against any situation that violates its corporate values and behaviors such as discrimination and exclusion based on ethnic, multicultural, gender, religious option or other aspects that could affect the dignity of people.
In short, GISMA promotes a culture of integrity, probity and transparency.
5. INTEGRATED MANAGEMENT SYSTEM POLICY
To establish the guidelines of the Integrated Management System based on the International Standards ISO 9001:2015 and ISO 27001:2022, to implement, maintain and improve an Integrated Management System in GISMA, which allows compliance with the objectives of quality and information security, through compliance with the satisfaction of our clients and the applicable requirements related to information security, guaranteeing the confidentiality, availability and integrity of the information.
2. SCOPE
This Integrated Management System policy applies to GISMA and to:
- Its collaborators, regardless of the contractual relationship with the Organization, external service providers, consultants, auditors, contractors who access the company's facilities, either physically or remotely to perform work and/or use GISMA's information technology resources.
- All facilities, equipment (including laptops and mobile accessories) for processing or storing GISMA information.
- All software for data processing or communications transport, regardless of the storage media or processing method that GISMA has available for its purposes.
- The use of third-party hardware, software and resources that GISMA owns or controls or licenses or has the right to use.
- The environments and premises of GISMA in which information and communications are processed.
3. REFERENCES
- ISO 9001:2015 standard (requirement 5.2)
- ISO 27001:2022 Standard (requirement 5.2 and Control A.5.1. Policies for information security)
4. DEFINITIONS
- Confidentiality: La información debe ser conocida únicamente por aquellas personas que estén autorizadas para acceder información específica del negocio. Esto es necesario para proteger los asuntos reservados como planes estratégicos, información legal, de recursos humanos, información de los empleados y cualquier dato sensitivo.
- Integrity: The information that supports the business must be accurate and complete so that the decisions made produce the expected results.
- Availability: Information must be available when needed in the format required for processing, to ensure that business processes and decisions are timely.
- Owner of the Information: He is the owner of the process that uses or generates that information.
- Information User: This refers to any person, internal or external collaborator, who, with proper authorization, enters, deletes, changes, or reads company information. Users should only have access to the information they are authorized to view or process, and the authorizations granted must limit their capabilities so that they cannot perform activities other than those for which permission was granted.
- Customer satisfaction: Customer perception of the degree to which their requirements have been met.
- Continuous improvement: Recurring activity to increase the capacity to meet requirements.
- Information Assets: These are all the relevant elements in the production, transmission, storage, communication, display, and retrieval of information of value to the organization. They consist of:
- Information itself, in its multiple formats (paper, digital, text, image, audio, video, verbal transmission, among others).
- The equipment, systems, and infrastructure that support this information.
- The people who use the information and who have knowledge of the processes.
5. RESPONSIBILITIES
- General Management: Approve the Integrated Management System Policy.
- Information Security Committee: Ensure that the Integrated Management System Policy and Objectives are established, that they are compatible with the organization's context and strategic direction, and that the integrated management system requirements are integrated into the organization's business processes. Ensure that the matters addressed in this policy are implemented and met, identify how non-compliance is handled, promote the dissemination and awareness of the matters addressed in this document, and periodically review this policy, identifying and proposing improvements.
- Quality Compliance Officer / ISMS Coordinator: Support the Information Security Committee in overseeing the implementation of this policy. Receive and respond to non-conformities and information security incidents.
- Collaborators: To comply with this Integrated Management System Policy, and to report any detected security events, weaknesses, or incidents.
6. POLICY DESCRIPTION
At GISMA we provide consulting services and supply environmental management software (SIGEA)...
- Achieving customer satisfaction, securing their business and exceeding their service expectations.
- To provide the client with innovation in methodologies and information technologies.
- To guarantee the confidentiality, integrity and availability of information for our clients, users, suppliers and other interested parties.
- Meet applicable information security requirements, agreed commitments, and applicable legal and regulatory requirements.
- Continuously improve the effectiveness of the Integrated Management System.
- Strengthen the management of knowledge and skills of human capital that add value to the quality of our services.
6.1 RELATIONSHIP WITH SUPPLIERS (A.5.19, A.5.20, A.5.21)
Every critical external supplier of the company must have a formal document that supports the relationship with the Company (service agreement or contract)...
- Physical access control.
- Access control to information.
- Asset control.
- Confidentiality of information.
- Safety in operations.
In the absence of a formal document, the critical supplier must explicitly accept this clause and commit to its compliance. Furthermore, they must guarantee the confidentiality and exclusive use of the information for contractual purposes…
7. POLICY UPDATE
As part of the continuous improvement of information security policies, this policy must be reviewed at least once a year from the date of entry into force, following the procedure P.SGI.01 Control of Documents and Records.
8. DISSEMINATION OF THE POLICY
All policies must be communicated to management so they can disseminate them according to the level of access permitted to each employee. The formal communication channel is the company's institutional email.
9. CHANGE CONTROL
| Version | Type | Description | Cargo | Date |
|---|---|---|---|---|
| 01 | Creation/Approval | N/A | Oficial de Cumplimiento de Calidad / Coordinador de SGSI | 09/Mayo/2014 |
