1. Objective

The objective of this Information Security Policy is to establish a reference framework for the protection of information at Nukke, LLC., and its subsidiaries, guaranteeing its confidentiality, integrity, and availability. This policy seeks to mitigate risks associated with information management, prevent security incidents, and ensure compliance with applicable standards and regulations, including the protection of customer information.

2. Scope

This policy applies to all employees, contractors, suppliers, and third parties who access, process, store, or manage information of Nukke, LLC. It extends to all information systems, databases, storage devices, and any other technological resource used in the company’s operation.

3. Definitions

Information Security: A set of measures and controls designed to protect information against unauthorizedaccess, alteration, or destruction.

Confidentiality: Guarantee that information is accessible only by authorized persons.

Integrity: Ensuring that information remains accurate, complete, and free from unauthorized modifications.

Availability: Guarantee that information is available when required by authorized users.

Security Incident: An event that puts the security of information at risk.

Information Security Risk: The possibility that a threat exploits a vulnerability, causing an impact on the organization.

Supplier: An external company or entity that supplies goods, services, or technologies to Nukke, LLC., and must comply with the information security requirements established in this policy.

Client: A person or entity receiving services from Nukke, LLC. Whose information must be protected in accordance with this policy.

4. Responsibilities

Senior Management: Senior Management is responsible for approving the general cybersecurity policy and ensuring it is alignedwith the organization’s strategic objectives.

CISO: In charge of designing, implementing, maintaining, and reviewing the general cybersecurity policy. Additionally, leads the management of information-related risks, coordinates the implementation of controls, supervisescompliance with policies, and reports periodically to Senior Management.

Collaborators: All users and collaborators of the organization have the responsibility to comply with the guidelines established in the cybersecurity policy.

5. General Description

Nukke, LLC., recognizes the importance of information security in its operation and in its relationship with employees, clients, and suppliers. Information is a fundamental asset that must be protected against internal and external threats to ensure business continuity and the fulfillment of strategic objectives.

5.1 Security Principles
  • The principle of least privilege will be applied, limiting access to information only to those who require it for their functions.Access control measures will be implemented, ensuring adequate authentication and authorization.
  • Periodic backups will be performed to ensure information availability.
  • Cryptographic controls will be applied for the protection of sensitive data.
  • An incident response plan will be established to mitigate possible security breaches.
  • Periodic risk analyses will be conducted, identifying potential threats and applying appropriate mitigationmeasures.
  • Suppliers will be required to comply with security standards and notify of relevant incidents.
  • The protection of client information will be guaranteed through appropriate processes and controls.
5.2 Risk Management
  • Information security risk assessments will be conducted periodically.
  • Potential threats such as cyberattacks, human errors, technological failures, and natural disasters will be identified.
  • The impact and probability of risks will be evaluated, defining strategies to reduce their impact on the organization.
  • Security controls will be implemented based on a risk management approach.
  • Policies and procedures will be reviewed regularly to adapt to new emerging risks.
5.3 Security Incident Management
  • A formal incident management process will be established, including detection, notification, analysis, containment, eradication, and recovery from security incidents.
  • A team responsible for incident response will be designated with clearly defined roles and responsibilities.
  • All incidents must be reported immediately to the Information Security Officer.
  • A post-incident analysis will be conducted to identify root causes and prevent recurrence.
  • Detailed records of security incidents will be maintained for future audits and policy improvements.
  • Suppliers will be required to report any security incident that may affect Nukke, LLC., and its clients.
5.4 Information Backups
  • Backups of information, software, and system images will be performed according to data criticality and business recovery requirements.
  • Backups will have adequate physical and logical protection measures (such as encryption) and, where feasible, will be stored in a geographic location distinct from the main one to prevent data loss in the event of physical disasters.
  • Periodic restoration tests will be performed to verify that backup media are reliable and that information can be effectively recovered within the required time.
5.5 Training and Awareness
  • Training programs on information security will be carried out for all employees.
  • A security culture based on good practices and regulatory compliance will be fostered.
  • Specific training on risk management will be included for all key employees and collaborators.
  • Training will be provided to suppliers regarding Nukke, LLC., security expectations and requirements.
  • Employees will be trained on the secure handling of client information.
5.6 Audit, Compliance, and Continuous Improvement
  • Periodic internal and external audits will be conducted to evaluate policy compliance, verifying the correct implementation of security measures and compliance with standards by suppliers.
  • Findings will be documented, improvement plans will be executed, and senior management will be informed about results and progress in security.
6. Periodicity

This policy must be reviewed periodically whenever required (at least once a year). If necessary, the policy will be adjusted based on presenting conditions.

Likewise, it will be reviewed in the event of changes to national regulations

7. Sanctions

Non-compliance with this policy by employees, contractors, suppliers, or any linked third party may result in disciplinary sanctions in accordance with Nukke, LLC., internal regulations, including warnings, suspension, or termination of the labor or commercial contract. In serious cases, legal actions may be taken according to current legislation. These measures also apply to negligence in protecting client information or failure to report security incidents

8. References

This policy is developed in conformity with the ISO/IEC 27001:2022 standard, ensuring its alignment with international best practices in information security management.

9. Validity

This policy enters into force upon its approval and is mandatory for all members of Nukke, LLC.