ARLEInformation Security Policy Statement

Legal

Information Security Policy Statement

Last updated: July 2026

This page is a courtesy translation. Only the Dutch original is legally binding.

The management of ARLE recognises that information is a critical business asset and essential to the trust of our clients, suppliers, government agencies and employees.

Management statement and commitment

As a specialised supplier of advanced solutions for defence, law enforcement and private security, we process, among other things:

  • Operationally sensitive information
  • Contract and tender documentation
  • Technical specifications
  • Export-controlled information
  • Commercially confidential data
  • Personal data

Management commits to protecting the confidentiality, integrity and availability of this information on a structural basis, through a formally established Information Security Management System in accordance with ISO 27001.

Information security is an integral part of how ARLE operates.

Information Security Management System

ARLE has established an Information Security Management System that:

  • Identifies and assesses risks systematically
  • Implements appropriate controls
  • Safeguards compliance with laws and regulations
  • Measures and monitors performance
  • Is directed at continual improvement

The ISMS provides the framework for setting, implementing and evaluating information security objectives.

This policy applies to all employees, members of management, contracted personnel and relevant external parties.

ARLE complies with all relevant national and international laws and regulations, including:

  • GDPR
  • Relevant Dutch and Belgian regulations on defence and export control
  • Contractual security obligations towards government agencies
  • Applicable requirements arising from ISO 27001
  • ABRO legislation

Where contractual or statutory requirements go beyond internal standards, those external obligations prevail.

Risk management

ARLE applies a risk-based approach to information security. This means that:

  • Risk assessments are carried out periodically
  • Threats, vulnerabilities and impact are assessed
  • Appropriate technical and organisational measures are determined
  • Residual risks are explicitly accepted or mitigated

Information security is proportionate to the nature of the information processed and to the defence-related context in which ARLE operates.

Roles and responsibilities

Management holds ultimate responsibility for the Information Security Management System.

Operational responsibility for drafting, maintaining and reviewing the information security policy rests with the Data Protection Officer, in close cooperation with those responsible for ICT, HR and operational processes.

Duties, responsibilities and authorities relating to information security are formally documented and clearly communicated.

Every employee is responsible for information security within their own sphere of influence and is expected to be familiar with the applicable policies and procedures.

Incident management

Security incidents and suspected breaches are reported in accordance with the internal incident reporting procedure. Incidents are:

  • Recorded
  • Analysed
  • Assessed for impact
  • Followed up with corrective and preventive measures

The purpose of incident management is not only recovery, but also structural improvement of the level of security.

Awareness and training

ARLE provides appropriate awareness and training in the field of information security. Employees are informed about:

  • Applicable security measures
  • Safe handling of sensitive information
  • Reporting procedures
  • Relevant statutory obligations

Continual improvement

Through internal audits, management reviews and periodic assessment, ARLE monitors:

  • The effectiveness of the ISMS
  • Compliance with policy measures
  • Achievement of security objectives

On the basis of these evaluations, improvement measures are determined and implemented.

Information security is a continual process, not a one-off effort.

Closing statement

With this policy statement, the management of ARLE confirms its structural commitment to protecting information and to safeguarding reliable, secure and professional service within a regulated and security-critical environment.

Signed on behalf of management and the DPO.

We use functional cookies to run this site and remember your language. With your consent, we also use analytics cookies to understand how visitors use the site. Cookie Policy