CORPORATE INFORMATION SECURITY POLICY

A.P. SUPPLIES & MEDIA conducts each of its activities in such a way, to serve the needs and expectations of its customers in the most efficient and secure manner and considers the applicable standards, legislation, regulations, as well as their application guidelines in all its activities and undertakes to comply with them.

The activities of A.P. SUPPLIES & MEDIA are:
Wholesale of computer equipment and software.
This policy is aligned with the Business Strategy and the relevant requirements of the Company.
Information Security is defined as the protection of Confidentiality, Integrity and Availability of Information

The physical security of facilities, personnel, documents, software and vulnerable equipment is ensured by the company in accordance with the relevant policies and procedures.

The heads of the Departments are responsible for the appropriate training of the staff so that they are able to use in the safest and most efficient way the company assets available to them to carry out their work.

Risk assessment is an iterative effort and considers each component’s contribution to the company’s mission,
vulnerabilities, risks, impact of a potential breach, single points of failure, method of quantifying and assessing risks, and ways to mitigate impacts through implementation protection measures.

The specifications for the supply of new or for the expansion of existing systems also include security
requirements depending on the mission they perform or are about to perform.

Access to the corporate network, as well as to the devices interconnected to it, is controlled. Access to the
company’s support systems is given to authorized personnel working for this purpose.

A centrally controlled system protects the corporate network from known or unknown malicious software.

The files containing the anti-malware features are updated frequently and automatically. The system protects, among other things, servers, workstations, and remote computers. A centrally controlled system protects the internal network from the Internet. The company has a Business Continuity Plan and maintains its applicability.

Finally, the company is committed to the continuous improvement of the Information Security Management System according to ISO 27001:2022 with which it complies and the achievement of the Information Security objectives it sets, through the framework of this policy, as well as the individual policies and procedures applied for this purpose.

This policy is reviewed annually or whenever there are significant changes and is available to all interested parties.