DALO's Information Security Principles

At DALO, we define information security requirements for our suppliers based on the principle that security measures should be proportionate to the threats we face and the potential consequences of a security incident.

 

Our objective is to establish a coherent supplier engagement throughout the entire contract lifecycle, where trust between the parties forms the foundation for effective information security. This approach is reflected in our security meetings, assurance statements, and audits, all of which are based on verification, transparency, and constructive dialogue.

 

We want our suppliers to implement and maintain the agreed level of security because it creates value and resilience for both parties. Should an information security incident occur, timely reporting and close cooperation between the supplier and DALO remain the most effective way to minimise the impact, restore operations, and continuously improve our security processes.

 

Contractual Requirements

Every procurement is unique. Consequently, information security requirements are tailored to the specific contract, particularly for high-risk projects where suppliers may be required to comply with more detailed and comprehensive requirements, including standards such as ISO/IEC 27001 and DALO's internal security policies.

 

To establish a consistent minimum level of protection, DALO has introduced a Baseline Information Security Annex based on internationally recognised best practices. The annex contains 21 security requirements organised into four key categories, providing a common foundation for information security across all relevant contracts.

 

Further Guidance

DALO applies the same information security principles as the wider Danish public sector by aligning its requirements with ISO/IEC 27001 and by following the guidance issued by the Danish national cyber security authority, the Danish Defence Intelligence Service (DDIS).

 

Current strategic cyber threat assessments for the Danish defence sector are available from the Danish Defence Intelligence Service. Additional tools, guidance, and publications on information security can be found on the websites of the Danish Agency for Digital Government and SAMSIK.

 

The Cyber Threat Landscape

The cyber threat level facing the Danish Armed Forces and our suppliers is currently Very High, and its complexity continues to increase each year due to rapid technological development in an increasingly digital and interconnected world.

 

A Very High threat level means that malicious actors have both the intent and the capability to conduct cyber activities targeting us and our suppliers. Such activities may include the sale of information about vulnerabilities in the supply chain to the highest bidder, the compromise of information relating to procurement activities and contractual terms, or cyberattacks designed to cause serious and prolonged disruptions to critical operations.

 

Information security extends beyond protecting the equipment and systems used directly in the production of defence materiel. It encompasses all forms of information, whether exchanged through mobile phone conversations, meetings, emails, or physical documents. It is equally important that the information we rely on remains accurate, trustworthy, and available when needed.

Last updated August 17, 2026 - 13:22