top of page

Management System & Information Security 
Policy

Management System Policy

dated 20/01/2026

 

Management System Commitment and Objectives

Management Commitment BAMI recognizes the Integrated Management System as a strategic lever for its development in the AEC and Energy markets and is committed to ensuring adequate resources for its implementation, maintenance, and continual improvement. The Chief Executive Officer, as the highest expression of corporate leadership, assumes responsibility for integrating the management system requirements into business processes, promoting risk-based thinking and a process approach, and communicating to all staff the importance of effective quality and information security management.

The organization is committed to:

  • meeting applicable requirements — explicit and implicit customer requirements, legal, regulatory, and contractual requirements, and those arising from information security risk assessment;

  • preserving the confidentiality, integrity, and availability of information managed on behalf of customers in the AEC and Energy sectors, as well as the organization's own information assets;

  • ensuring the operational continuity of critical services through backup, recovery, and resilience strategies;

  • promoting staff awareness and competence so that every employee recognizes their role in protecting information assets and achieving quality objectives;

  • supporting managerial functions in exercising their leadership on quality and information security matters.

 

Management System Objectives

This policy provides the framework for defining measurable objectives, periodically reviewed during Management Review, consistent with the commitments stated above. These objectives include, but are not limited to:

  • the quality of services provided and customer satisfaction;

  • the effectiveness of information security controls and the reduction of incidents;

  • the development of staff competencies in technical, digital, and regulatory areas;

  • technological innovation and the consolidation of data-driven and Digital Twin solutions;

  • the continual improvement of the suitability, adequacy, and effectiveness of the management system.

Each objective is supported by a program specifying timelines, resources, monitoring indicators, responsibilities, and methods for verifying effectiveness, as described in the  Objectives and Planning Procedure for their achievement.

Fundamental Principles

The organization bases its actions on the following principles:

  • Risk-based approach: strategic and operational decisions are based on the systematic assessment of risks and opportunities related to the internal and external context.

  • Shared responsibility: information security and quality are not the prerogative of a single function, but a common objective for all staff, at every organizational level.

  • Customer focus: understanding and exceeding the expectations of customers — organizations and companies in the AEC and Energy sectors — guides every design and service choice.

  • Innovation and continual improvement: investment in research and development, collaboration with universities and research centers, and the adoption of emerging technologies (BIM, Artificial Intelligence, IoT, Cloud Computing, Digital Twin) represent the pillars of BAMI's competitive development.

  • Acceptable use of resources: access to information and resources associated with the management system is limited to legitimate business purposes, following the principle of least privilege.

  • Timely reporting of events: all staff are required to promptly report security events through dedicated channels, in an environment free of negative consequences for the person reporting.

Information Security Policy

dated 20/01/2026

Information Security Objectives

BAMI pursues measurable information security objectives, consistent with its business strategy and derived from risk analysis, the needs of interested parties, and the outcomes of management review.

The organization is committed to:

  • Preserving the confidentiality, integrity, and availability of information managed on behalf of customers in the AEC and Energy sectors, safeguarding information assets throughout the entire lifecycle of digital assets.

  • Ensuring compliance with applicable legal, regulatory, and contractual requirements for information processing, with particular attention to the protection of personal data.

  • Reducing the organization's exposure to information security risks through the systematic identification, assessment, and treatment of threats, keeping residual risk within acceptable levels approved by Top Management.

  • Ensuring the operational continuity of critical services through backup, recovery, and resilience strategies proportionate to the impact of disruptions on service delivery capacity.

  • Promoting staff awareness and competence in information security, so that every employee recognizes their role in protecting information assets.

  • Continually improving the effectiveness of the ISMS through the analysis of performance indicators, audit outcomes, the management of nonconformities, and decisions made during management review.

Fundamental Principles of Information Security

Risk-Based Approach

The organization adopts a systematic approach to risk management as the foundation of every decision related to information security. The identification, analysis, and assessment of risks guide the selection and prioritization of controls, ensuring that resources are allocated proportionally to the likelihood and impact of identified threats. Top Management formally approves acceptable risk levels and treatment strategies, and the Management System Manager coordinates the periodic review of the risk profile in line with changes in the internal and external context.

 

Acceptable Use of Information and Associated Resources

BAMI is committed to ensuring that information and its associated resources are used exclusively for legitimate business purposes, in compliance with the protection requirements defined by the assigned classification. Every assignment of company assets is formalized through the MOD Asset Assignment Form, which binds the assignee to handle the resources received with diligence and in accordance with company rules. The Register of Users Authorized to Use Information documents current authorizations, specifying for each user the systems, repositories, and information categories accessible. The organization promotes the responsible use of resources and prohibits any unauthorized, abusive use, or use contrary to the purposes for which the assets were assigned.

 

Screen and Workstation Protection

The organization adopts clear screen and clear desk rules to prevent unauthorized access to information in both digital and paper format. All company devices are configured with automatic screen locking after a maximum period of inactivity of five minutes when connected to mains power and three minutes on battery mode, and are protected by a PIN code or authentication credential. Staff are required to manually lock their workstation session whenever they step away, and to store confidential documents in a manner that prevents access by unauthorized persons.

 

Reporting of Information Security Events

BAMI promotes a culture in which every person involved in business activities is called upon to promptly report any observed or suspected information security event. The organization provides dedicated reporting channels and ensures that no negative consequences result from reporting a potential vulnerability or anomaly in good faith. Each report is evaluated, classified, and managed according to the Information Security Incident Management Procedure, and recorded in the Information Security Incident Register.

 

Security of Off-Site Assets

Given the established practice of remote work and the nature of activities carried out at customer sites, BAMI is committed to protecting its assets even outside company premises. Devices used while mobile or in smart working mode must meet the same security requirements applicable in the offices, including the encryption of storage media, connection via secure networks, and prudent behavior in the physical custody of equipment. The organization provides staff with specific guidance on the precautions to adopt while working in external environments, so that information protection remains guaranteed regardless of where the activity takes place.

 

Shared Responsibility and Continual Improvement

Information security is a responsibility that permeates the entire organization: from Top Management, which sets its strategic direction and ensures resources, down to each employee, who contributes through their daily conduct to maintaining controls. BAMI is committed to continually improving the adequacy and effectiveness of the ISMS, assessing performance through measurable indicators, incorporating the findings of internal audits and security events, and translating lessons learned into concrete actions that strengthen the organization's security posture over time.

bottom of page