Information Security Policy

LAST UPDATED: 2026-06-22

1 Scope

This policy applies to all information handled by SDC (regardless of format) and to employees, contractors, and relevant external parties who access SDC information or information systems.

2 Policy statement and principles

SDC iscommitted to protecting the confidentiality, integrity, and availability of information.

Through this policy, SDC commits to information security that:

·       Supports the organization’s strategy,business objectives and business requirements.

·       Is managed using a structured and risk-based approach.

·       Provides a framework for establishing, reviewing, and following up information security objectives aligned with SDC’s strategic priorities, risk exposure, compliance obligations, and business requirements.

·       Protects information against unauthorized access, disclosure, modification, loss, or unavailability.

·       Fulfils applicable legal,regulatory, contractual requirements and other relevant information security requirements.

·       Is considered in organizational changes, new initiatives, and significant business decisions.

·       Promotes awareness, accountability, and secure handling of information in daily work.

·       Supports continuous improvement of the Information Security Management System.

3 Roles and responsibilities

Management is responsible for implementing and supporting this policy and for ensuring that information security is appropriately governed within the organization.

Employees, contractors, and relevant external parties shall comply with this policy and applicable information security requirements, use information and systems responsibly, and report suspected or actual information security incidents or weaknesses without delay.

Detailed roles and responsibilities are defined in the ISMS Manual and supporting documents.

4 Review and approval

This policyis approved by management and reviewed annually, or when significant changesoccur, to ensure its continued suitability, adequacy, and effectiveness.