Baufest

Information Security Policy

Effective date: July 11, 2025

PURPOSE and OBJECTIVES

The Information Security Policy of BAUFEST establishes a set of measures aimed at preserving the confidentiality, integrity, and availability of information — the three fundamental pillars of information security. Its purpose is to define the necessary requirements to protect information, equipment, and technology services that support the organization’s business processes, in compliance with best industry practices and applicable regulations, including ISO Standard 27001:2022.

Baufest's Information Security objectives are defined to:

These objectives help strengthen Baufest’s security posture and ensure compliance with the regulatory framework adopted by the organization.

BAUFEST INFORMATION SECURITY POLICY

The BAUFEST Management acknowledges that information is a key asset to the organization and therefore must be adequately protected. It promotes and commits to continuous improvement of the Information Security Management System and to meeting its requirements by establishing and maintaining an appropriate policy that provides a framework for setting information security objectives and controls aligned with the organization's business goals.

This document is approved by BAUFEST Management, which commits to publishing, communicating, and enforcing it with all employees, as well as with third parties who interact regularly or occasionally and may have access to sensitive information.

The Baufest Information Security Policy is based on the following strategic pillars: