Overview Economy Community People Environment Governance & Risk Disclosure GRI & ADX 87GRI 102-16, 102-17, 102-18, 102-19, 102-28, 103-2 Data security Our advanced data and IT security policies and procedures protect us, and our stakeholders, against the risk that personal or company data may be stolen, corrupted or otherwise compromised. A comprehensive management framework, supported by standard operating procedures, ensures that data security is fully embedded throughout the company, including a rigorous ongoing testing regime to ensure that our controls are resilient to potential cyber-attacks. All policies and the company’s IT Risk Management Framework are aligned with CObIT, ISO27001 and NIST management standards and frameworks. Aldar’s IT services have been awarded ISO/IEC 27001:2013 certification in recognition of our best-in-class approach, and an annual ISO 27001 surveillance audit is conducted by Aldar’s Lead Auditors. We have implemented a robust security architecture, coupled with the deployment of up-to-date security technologies to prevent cyber threats and detect security incidents. These include a system-vulnerability management programme, security enhancements as part of our standard assessments, need-to-know and need-to-have principles for data access, Domain Name System security controls, an Advanced Threat Protection layer deployed on user endpoints and perimeters, a Disaster Recovery Strategy, and an organisation-wide end-user security awareness training programme. Our investments in this area mean that Aldar was strongly positioned to adapt to the COVID-19 pandemic, with our systems ready to support a rapid transition to home working. We took immediate steps to create a safe firewall, as well as implementing phishing controls, end-user authentication frameworks, protecting userbase multi factor identification, and ETP protection of Aldar laptops. Governance