back to top

Management System Policy

Version Date Author Approved By
v1 09/04/2026 Alex Donatelli Nicolò Spiezia

Purpose

KnowCE S.p.A. (hereinafter “the organization”) adopts this policy to express the will and commitment of Top Management towards the Integrated Management System (IMS), compliant with the ISO 9001 and ISO/IEC 27001 standards. The document promotes a balance between the needs of economic development and value creation, typical of business activity, and the needs of service quality, social responsibility, and information and data security.

The organization recognizes that the design, development, and management in SaaS mode of the CEA platform, dedicated to the digitalization, repeated inspection, and risk analysis of civil and infrastructural works, require a solid framework, appropriate to the operating context and consistent with the company’s strategic direction. This policy constitutes such a framework: it guides the definition of quality and information security objectives and supports the organization’s mission and vision.

KnowCE S.p.A. is also committed to complying with applicable current legislation and to encouraging, at all levels, the spread of a culture founded on respect for legal principles and continuous improvement.

Scope of application

This policy applies to all activities, processes, and information assets of KnowCE S.p.A. connected to the design, development, and management in SaaS mode of the CEA platform for the digitalization, repeated inspection, and risk analysis of civil and infrastructural works. It involves all personnel, including employees, collaborators, and external consultants, as well as third parties who access the organization’s information or systems. Since the organization operates entirely in full-remote mode from its registered office at Foro Buonaparte 55, Milan, the policy extends to every location from which personnel carry out their work and to all devices used to access company systems.

Regulatory references

  • ISO 9001
  • ISO/IEC 27001
  • Regulation (EU) 2016/679

Terms and definitions

  • Management system: set of interrelated or interacting elements of an organization used to establish policies, objectives, and processes to achieve those objectives.
  • Top management: person or group of people who, at the highest level, direct and control an organization.
  • Policy: intentions and direction of an organization, as formally expressed by its top management.
  • Objective: result to be achieved.
  • Risk: effect of uncertainty on objectives.
  • Continual improvement: recurring activity to enhance performance.
  • Interested party: person or organization that can affect, be affected by, or perceive itself to be affected by a decision or activity.
  • Documented information: information required to be controlled and maintained by an organization, and the medium on which it is contained.
  • Information security: preservation of the confidentiality, integrity, and availability of information.
  • Confidentiality: property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
  • Integrity: property of accuracy and completeness of information.
  • Availability: property of being accessible and usable on demand by an authorized entity.

Roles and responsibilities

  • Top Management: establishes, approves, and keeps this policy up to date, ensures the resources necessary for its implementation, and promotes a culture of quality and information security at all levels of the organization.
  • Management System Manager: reviews, at least annually, the consistency of the policy with the organization’s strategic direction and operating context, proposes any necessary revisions to Top Management, and oversees its communication and dissemination to personnel and interested parties.

Management system commitment and objectives

Commitment to service quality

KnowCE S.p.A. pursues excellence in the design, development, and delivery in SaaS mode of the CEA platform, with the aim of fully satisfying the needs and expectations of its customers: infrastructure managers, engineering firms, engineers in charge, operations and maintenance functions, as well as parties active in risk management such as insurance companies, banking institutions, and regulatory authorities. The organization is committed to ensuring the accuracy and reliability of the analyses generated by the platform, to complying with contractual requirements, and to pursuing conformity with applicable requirements.

Customer satisfaction represents a key indicator of the effectiveness of the IMS. The organization promotes ongoing dialogue with its customers and the systematic collection of feedback, so that the results guide the improvement of services and internal processes.

Commitment to information security

The organization adopts a systematic approach to risk management in order to identify, assess, and treat threats that could compromise the confidentiality, integrity, or availability of information.
Security decisions are proportionate to the actual level of risk, so as to focus resources on the areas of greatest criticality and ensure that controls reflect real operating conditions. Risk management is governed by the PRO Risk Management Procedure.

KnowCE S.p.A. classifies its information according to three levels of confidentiality (public, restricted use, confidential) and applies the principle of least privilege when granting access, ensuring that each person holds only the authorizations necessary to carry out their duties.

The protection of information extends to relationships with suppliers and partners who access the organization’s data or systems: KnowCE S.p.A. assesses such parties and contractually binds them to adopt measures consistent with its own policies. The POL Information Security Policy formalizes in detail the specific principles and commitments on this matter, completing the framework set out by this policy.

Shared responsibility and awareness

Service quality and information security involve every person who works on behalf of the organization. KnowCE S.p.A. promotes staff awareness and competence through periodic training and awareness-raising initiatives, so that every collaborator understands their role in preserving the quality of the services delivered and in protecting the company’s information assets.

The organization provides personnel with dedicated channels for the timely reporting of information security events, vulnerabilities, or suspected incidents. The Code of Conduct sets out the ethical and behavioral principles that every member of the organization is required to observe, directly linking individual conduct to the protection of information assets and to adherence to the IMS’s policies and procedures.

Compliance with applicable requirements

The organization is committed to meeting the legal, regulatory, and contractual requirements applicable to its activities, with particular attention to the protection of personal data, cybersecurity regulations, and the technical requirements of the infrastructure sector. The regulatory context and the needs of relevant interested parties are analyzed in the Context Analysis and periodically reviewed to ensure the IMS remains aligned with developments in the reference framework.

Management system objectives

This policy constitutes the framework of reference for defining quality and information security objectives. These objectives are set by Top Management in line with the organization’s strategic direction, taking into account the internal and external context, the identified risks and opportunities, and the expectations of relevant interested parties. In particular, the organization pursues:

  • the confidentiality of customer data and of technical information relating to the CEA platform;
  • the integrity of the digital models, inspections, and analyses generated by the platform;
  • the continuous availability of the services provided in SaaS mode to organizations that manage civil infrastructure;
  • the strengthening of the capacity to detect and respond to information security events;
  • the promotion of staff awareness and competence in matters of quality and security;
  • compliance with applicable regulatory and contractual requirements.

Each objective is accompanied by an implementation program specifying timelines, resources, performance indicators, responsibilities, and methods for verifying effectiveness, as governed by the Objectives and Planning procedure for their Achievement. The Management System Manager, together with Top Management, reviews the objectives at least annually as part of the management review.

Continual improvement

KnowCE S.p.A. pursues the continual improvement of the IMS through performance monitoring, the analysis of incidents and nonconformities, the results of internal and external audits, and the management review. Each review cycle, governed by the PRO Management Review Procedure, is an opportunity to confirm or update this policy, redefine strategic objectives, and identify further improvement opportunities, ensuring that the IMS remains adequate, suitable, and effective over time.

Communication of the policy

The organization is committed to making this policy accessible, understandable, and applied at all levels. The Management System Manager oversees its internal dissemination through approved company channels and collects evidence of communication at each publication or update. The policy is also made available to external interested parties through the company website and the organization’s institutional channels, in accordance with the Communication Management Procedure.

Filing and update

This policy is retained as documented information of the IMS on the organization’s document management platform, in a durable and accessible format, in compliance with the principle of least privilege. The Management System Manager oversees its review at least annually, in conjunction with the management review, or earlier should significant changes occur in the organizational, regulatory, or strategic context. Each update follows the approval process defined in the Documented Information Management Procedure and is recorded in the revision history; superseded versions are archived with an appropriate notation to prevent unintended use.

Reference documents

  • Information Security Policy
  • Risk Management Procedure
  • Objectives and Planning for their Achievement
  • Management Review Procedure
  • Communication Management Procedure
  • Documented Information Management Procedure
  • Code of Conduct
  • Context Analysis

Join our team

Become active partner

Book a demo

Want to become an active partner?
Click here
Want to join our team?
Click here
COPYRIGHT © 2024 KNOWCE. ALL RIGHTS RESERVED
SUBSCRIBE TO OUR NEWSLETTER