ARLEInformation Security Policy Statement
Information Security Policy Statement
Last updated: July 2026
This page is a courtesy translation. Only the Dutch original is legally binding.
The management of ARLE recognises that information is a critical business asset and essential to the trust of our clients, suppliers, government agencies and employees.
Management statement and commitment
As a specialised supplier of advanced solutions for defence, law enforcement and private security, we process, among other things:
- Operationally sensitive information
- Contract and tender documentation
- Technical specifications
- Export-controlled information
- Commercially confidential data
- Personal data
Management commits to protecting the confidentiality, integrity and availability of this information on a structural basis, through a formally established Information Security Management System in accordance with ISO 27001.
Information security is an integral part of how ARLE operates.
Information Security Management System
ARLE has established an Information Security Management System that:
- Identifies and assesses risks systematically
- Implements appropriate controls
- Safeguards compliance with laws and regulations
- Measures and monitors performance
- Is directed at continual improvement
The ISMS provides the framework for setting, implementing and evaluating information security objectives.
This policy applies to all employees, members of management, contracted personnel and relevant external parties.
Legal and regulatory compliance
ARLE complies with all relevant national and international laws and regulations, including:
- GDPR
- Relevant Dutch and Belgian regulations on defence and export control
- Contractual security obligations towards government agencies
- Applicable requirements arising from ISO 27001
- ABRO legislation
Where contractual or statutory requirements go beyond internal standards, those external obligations prevail.
Risk management
ARLE applies a risk-based approach to information security. This means that:
- Risk assessments are carried out periodically
- Threats, vulnerabilities and impact are assessed
- Appropriate technical and organisational measures are determined
- Residual risks are explicitly accepted or mitigated
Information security is proportionate to the nature of the information processed and to the defence-related context in which ARLE operates.
Roles and responsibilities
Management holds ultimate responsibility for the Information Security Management System.
Operational responsibility for drafting, maintaining and reviewing the information security policy rests with the Data Protection Officer, in close cooperation with those responsible for ICT, HR and operational processes.
Duties, responsibilities and authorities relating to information security are formally documented and clearly communicated.
Every employee is responsible for information security within their own sphere of influence and is expected to be familiar with the applicable policies and procedures.
Incident management
Security incidents and suspected breaches are reported in accordance with the internal incident reporting procedure. Incidents are:
- Recorded
- Analysed
- Assessed for impact
- Followed up with corrective and preventive measures
The purpose of incident management is not only recovery, but also structural improvement of the level of security.
Awareness and training
ARLE provides appropriate awareness and training in the field of information security. Employees are informed about:
- Applicable security measures
- Safe handling of sensitive information
- Reporting procedures
- Relevant statutory obligations
Continual improvement
Through internal audits, management reviews and periodic assessment, ARLE monitors:
- The effectiveness of the ISMS
- Compliance with policy measures
- Achievement of security objectives
On the basis of these evaluations, improvement measures are determined and implemented.
Information security is a continual process, not a one-off effort.
Closing statement
With this policy statement, the management of ARLE confirms its structural commitment to protecting information and to safeguarding reliable, secure and professional service within a regulated and security-critical environment.
Signed on behalf of management and the DPO.