Quality and Security Policy
1.1. Quality and Information Security Policy
TRIDIOM’s mission is to offer clients a comprehensive range of top-quality language services, including translation and interpreting, to help them thrive and grow their business, whilst ensuring a service that consistently exceeds their expectations.
The purpose of this high-level policy is to set out the objective, direction, principles and basic rules for the management of quality and information security.
This Policy applies to the entire Quality and Information Security Management System, as defined in the scope.
TRIDIOM’s management wishes to convey to all users of this document (employees, clients, partners, suppliers and other stakeholders) its firm belief that quality and security of information are a key factor in the organisation’s development.
TRIDIOM considers that both quality management and information security, together with the provision of the training and resources necessary for the organisation to carry out its activities, and the implementation or the use of ICT (Information and Communications Technology) systems to achieve its objectives and to support these services, are the main pillars on which its daily work and efforts are based.
The company relies on ICT systems to achieve its objectives. These systems must be managed with due care, taking appropriate measures to protect them against accidental or deliberate damage that could affect availability (the characteristic of information whereby it may only be accessed by authorised persons when necessary), integrity (the characteristic of information whereby it is modified only by authorised persons or systems and in a permitted manner) and the confidentiality of the information processed or the services provided (the characteristic of information whereby it is available only to authorised persons or systems).
The overall objective of information security is to ensure client satisfaction by guaranteeing the quality of information and the continuous provision of services, taking preventative action, monitoring day-to-day operations and responding promptly to incidents in order to minimise potential damage. The targets are in line with TRIDIOM’s business objectives, strategy and business plans.
TRIDIOM’s Quality and Information Security Management System bases its activities on planning, establishing, implementing, operating, monitoring, reviewing, maintaining and improving, in order to safeguard the quality of services and protect the availability, integrity and confidentiality of the information that underpins the company’s processes.
To this end, the Quality and Information Security Management System has the following objectives:
- Quality management of the services provided, in accordance with the international standard UNE-EN ISO 9001:2015, and information security management, in accordance with the international standard UNE-EN ISO/IEC 27001:2022, through the responsibility and involvement of all members of the company.
- Effective allocation of roles and responsibilities.
- Effective management and control of the production process by qualified staff specialising in translation and interpreting, with a view to the continuous improvement of processes, procedures, delivered products and services provided to the client, thereby achieving greater maturity in management and execution over time.
- Staff training must be provided in line with the technical changes and technological innovations affecting the company’s operations, to ensure that work is carried out to the required standards of quality and information security, and to promote staff training in any areas identified as needing improvement.
- To provide services of a quality and level of information security that meet and exceed our clients’ needs.
- Preventing potential defects and information security incidents before they occur, by focusing on improvement and communication.
- Continuous improvement of the system, with a view to meeting our clients’ requirements, through regular reviews of the system, whilst complying with the legal and regulatory requirements relevant to the organisation in the field of information security, as well as with contractual obligations
- Establishment of quality and security indicators that enable us to assess the level of effectiveness and security of our production processes
- Implementation of new business management models, methods and systems, and the search for and development of new documents that clearly describe the organisation’s activities, followed by their implementation.
- Implementation of ongoing methodologies designed to gauge the level of satisfaction and ensure that our clients’ needs and expectations are met.
- To maintain ongoing communication with our clients, both internal and external, viewing their suggestions and complaints as a means of improvement, and assessing their satisfaction as an area for continuous improvement.
- Establish the security level based on a risk analysis.
- Carrying out regular security audits to assess the level of compliance with the security policy.
- To manage our resources effectively – both human (specialised staff) and material (economic and financial) – in order to optimise results by identifying the costs of poor quality.
- Raising staff awareness and motivation regarding the importance of implementing and developing a Quality and Information Security Management System.
- Define and implement processes and procedures to address information security risks associated with the supply chain for Information and Communications Technology (ICT) products and services – Control 5.21: Information security management in the ICT supply chain in line with NIS2 (Directive on measures for a high common level of cybersecurity).
- Climate change: Tridiom is committed to assessing the impact of climate change and engaging with stakeholders. The aim is to mitigate the effects of climate change on the quality of products and services.
This Policy will serve as a framework for establishing objectives and the corresponding individual security controls or groups of security controls, which will be proposed by the Integrated Management System Manager and approved by Senior Management. The process for selecting controls is set out in the risk assessment and treatment methodology. The selected controls and their implementation status are set out in the Statement of Applicability.
The responsibilities relating to TRIDIOM’s Quality and Information Security Management System are as follows:
The Integrated Management System Manager:
- To ensure that the System is implemented and maintained in accordance with this Policy and that all necessary resources are made available.
- Operational coordination of the system, as well as reporting on its performance.
- Implement training and awareness programmes for all those who play a role in the management of quality and information security.
- Define what information relating to quality and information security is to be communicated to which stakeholders (both internal and external), by whom, and when.
- To ensure that this Policy is communicated to all the company’s employees, as well as to the relevant external stakeholders.
- Define the method for measuring the achievement of objectives, as well as for analysing, evaluating and reporting the results for review by management, recording details of the measurement, frequency and results obtained.
- To receive information on all security incidents or vulnerabilities for processing and reporting to management.
Management must review the Quality and Information Security Management System at least once a year or whenever a significant change occurs, in order to determine whether it is adequate, suitable and effective.
All objectives must be reviewed at least once a year by the Integrated Management System Manager and approved by Senior Management. The protection of the integrity, availability and confidentiality of assets is the responsibility of the owner of each asset.
Senior Management establishes and promotes the principles underpinning this Policy, which must be embraced and implemented with the support of all staff, working together as a single team.
This Policy will be available on the premises, on the corporate server and on the website, and will be made known to all stakeholders (clients, employees, external partners, etc.).