Security Policy

At CITI, we recognize the importance of maintaining proper control over Information Security—both our own and that of third parties entrusted to us. For this reason, and aligned with our objectives, we have established processes that promote a culture of security in managing our most valuable asset: information.

Through risk identification and mitigation, CITI implements controls that ensure the proper use and careful protection of all information handled by CITI users, whether internal or external. These controls help prevent the destruction, disclosure, modification, or unauthorized use of any information under CITI’s custody. We are committed to developing, implementing, and continuously improving our Information Security Management System (ISMS) and Service Management System (SMS).

Accordingly, CITI’s management is fully committed to continuously improving its services and meeting the service levels agreed upon with our clients, at all times adhering to the requirements of international standards ISO/IEC 27001:2013 and ISO/IEC 20000-1:2018, as well as to all applicable legal and regulatory requirements.