Security Policy
Version updated on 12 February 2024.
APPROVAL AND ENTRY INTO FORCE
Text approved on 12 February 2024 by the Management of GRUPO ACRECENTA.
This Information Security Policy is effective as of that date and until it is replaced by a new Policy.
INTRODUCTION
GRUPO ACRECENTA, aware that the information it handles is a highly valuable resource, has established a Management System for all the companies of the group in accordance with the requirements set out in Royal Decree 311/2022, of 3 May, regulating the National Security Framework (Esquema Nacional de Seguridad) and the ISO 27001:2022_Information Security Management System standard, in order to guarantee the continuity of the information systems, minimise the risk of damage and ensure that the established objectives are met.
The scope is as follows:
"The Information Systems that support the processes of design, development, implementation, support, training and maintenance of the IT consulting and software development services provided by Acrecenta Development"
The purpose of having an Information Security System is to guarantee the quality of the information and the continuity of the services provided, acting preventively, supervising daily activity and reacting promptly to incidents.
The objective of the Information Security Policy is to establish the framework of action required to protect information resources against internal or external, deliberate or accidental threats that may affect the information systems needed to provide the services, the information of our clients managed by GRUPO ACRECENTA, or our own information considered confidential.
To this end, those risks that may affect the elements making up the systems supporting the activity of GRUPO ACRECENTA and that may affect the confidentiality, integrity, availability, authenticity and traceability of the aforementioned systems or information must be identified. For each identified risk, the probability of the threat materialising, the organisation's level of vulnerability to it, and the impact of its materialisation must be determined.
In addition, the Security Committee undertakes to establish measures aimed at reducing the risk level of those system elements that are rated above LOW.
The effectiveness and application of the Management System is the direct responsibility of the Management Committee, which is responsible for the approval, dissemination and compliance with this Security Policy. On its behalf and in its representation, a Management System Officer has been appointed, holding sufficient authority to play an active role in the Management System, supervising its implementation, development and maintenance.
Compliance with this policy is mandatory for all personnel involved in the provision of the services offered by the entity and for anyone who may access the information resources related to them.
Any person whose activity may, directly or indirectly, be affected by the requirements of the Management System is obliged to strictly comply with the Security Policy.
REGULATORY FRAMEWORK
The Information Security Management System implemented at GRUPO ACRECENTA must respond to the requirements established in this respect by the legislation in force applicable to the entity's activity, whose main references are:
- REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 ("Cybersecurity Act").
- Royal Decree 43/2021, of 26 January, implementing Royal Decree-Law 12/2018, of 7 September, on the security of network and information systems.
- Royal Decree 311/2022, of 3 May, regulating the National Security Framework.
Likewise, GRUPO ACRECENTA will comply with the security requirements that the clients of its services may pass on to it.
The list of external documents of the Management System includes a detailed record of the legislation, regulations and other requirements in this area to which GRUPO ACRECENTA must respond. This list is updated regularly, analysing the requirements arising from the applicable regulations and the commitments entered into, and periodically assessing compliance with them.
The security regulations will be available to all members of the organisation who need to know them, in particular to those who use, operate or administer the information and communications systems, in a cloud folder.
SECURITY ORGANIZATION
The implementation of the Security Policy at GRUPO ACRECENTA requires all members of the organisation to understand their obligations and responsibilities according to the position they hold. Each specific role, assigned to particular users, must understand the implications of their actions and the responsibilities attributed to them, which are identified in this section and grouped as follows:
- The Security Committee
- Information Owner
- Service Owner
- Security Officer
- Information System Manager
The following sections specify the functions attributed to each of these roles:
The Security Committee
It coordinates information security. This Committee is made up of each of the roles mentioned above.
Its functions are as follows:
- Reviewing and approving the Security Policy and the main responsibilities.
- Defining and driving the security strategy and planning, proposing the allocation of the necessary budget and resources.
- Supervising and controlling significant changes in the exposure of information assets to the main threats, as well as the development and implementation of the controls and measures intended to guarantee the security of those assets.
- Approving the main initiatives to improve security.
- Supervising and monitoring aspects such as:
- Main Information Security incidents.
- Preparation and updating of continuity plans.
- Compliance with and dissemination of the Security Policies.
The Secretary of the Security Committee
This role will be held by the Security Officer, whose functions are:
- Convening the meetings of the Information Security Committee.
- Preparing the matters to be discussed at the Committee meetings, providing timely information for decision-making.
- Drawing up the minutes of the meetings.
- Being responsible for the direct or delegated execution of the Committee's decisions.
Information Owner
Has the authority to establish the security requirements of the information managed. If this information includes personal data, the requirements arising from the corresponding data protection legislation must also be taken into account.
- Determining the security levels of the information.
Service Owner
Has the authority to establish the security requirements of the services provided.
- Determining the security levels of the information.
Security Officer
Responsible for defining, coordinating and verifying compliance with the information security requirements defined in accordance with the strategic objectives.
The functions are as follows:
- Chairing the meetings of the Security Committee, reporting on, proposing and coordinating its activities and decisions.
- Coordinating and controlling information security and data protection measures.
- Supervising the implementation of, maintaining, controlling and verifying compliance with:
- The information security strategy defined by the Security Committee.
- The rules and procedures contained in the Information Security Policy.
- Supervising the security incidents that occur.
- Disseminating the rules and procedures contained in the Information Security Policy, as well as the functions and obligations regarding information security.
- Supervising and collaborating in the internal / external audits required to verify the degree of compliance with the Security Policy, implementing regulations and applicable laws on personal data protection and information security.
- Advising the different operational areas on information security matters.
Information System Manager
Responsible for ensuring the execution of measures to secure the assets and services of the information systems supporting the activity, in accordance with the organisation's objectives.
The functions are as follows:
- Developing, operating and maintaining the Information System throughout its life cycle, including its specifications, installation and verification of its correct operation.
- Defining the topology and management system of the Information System, establishing the criteria for use and the services available in it.
- Ensuring that specific security measures are properly integrated within the general security framework.
- Selecting and establishing the functions and obligations of the IT Technical Managers responsible for tailoring the security management of the assets, in accordance with the defined security strategy.
- Guaranteeing that the implementation of new systems and of changes to existing ones complies with the established security requirements.
- Establishing the processes and controls for monitoring the state of security that make it possible to detect incidents and to coordinate their investigation and resolution.
The System Manager may decide to suspend the handling of certain information or the provision of a certain service if informed of serious security deficiencies that could affect the satisfaction of the established requirements. This decision must be agreed with the owners of the affected information and the affected service and with the Security Officer before being carried out.
APPOINTMENT PROCEDURE
The following responsibilities are assigned:
- Information and Service Owner: A member of Senior Management, normally one of the partners.
- Security Officer: A member of Senior Management, normally one of the partners, who understands what each department does and how the departments coordinate with each other to achieve the objectives set by Management.
- System Manager: A senior programmer from the software development department responsible for the operation and maintenance of the Information System.
Appointments will be reviewed every 2 years or whenever any of the positions becomes vacant.
The Security Officer and the System Manager will be appointed by the General Manager at the proposal of the Security Committee.
The structure of the committee is detailed in the deed of constitution of the information security committee and the designation of the information security roles.
REVIEW OF THE INFORMATION SECURITY POLICY
It will be the Security Committee's task to review this Information Security Policy annually and to propose its revision or continuation. The Policy will be approved by management and disseminated so that all affected parties are aware of it.
PERSONAL DATA
In application of the principle of proactive accountability established in the General Data Protection Regulation, personal data processing activities will be integrated into the system categorisation of the National Security Framework, taking into account the threats and risks associated with this type of processing.
Any other legislation in force on the protection of personal data will also apply.
DOCUMENT CLASSIFICATION
Classification guidelines
Information classifications, and other associated protection controls, must take into account that entities need to share or restrict access to certain information. In general, the classification given to information is a shorthand way of determining how it must be handled and protected.
Information and systems handling sensitive data must be catalogued according to their value and importance for the entity. At GRUPO ACRECENTA, the following classification is established for the information considered within the scope of the Information Security Management System.
- Public: The information is allowed to be accessible to the entity's personnel and to external parties without any restrictions.
- Private: This information may be accessed by GRUPO ACRECENTA personnel without any restriction, and by authorised external personnel.
- Confidential: The information may only be accessed by the Management of GRUPO ACRECENTA and by internal or external personnel holding the corresponding authorisation.
The classification applied to the information will be reflected in the lists of internal documents and in the record control section of each System document, which will also indicate, for confidential information, who is authorised to access it.
At least annually, the Information Security Officer must review the established criteria, as well as the classification given to each information resource, in order to assess whether they remain valid for the organisation or whether changes must be introduced.
Information labelling
The System's information assets must be appropriately labelled so that personnel know what use may be made of them and apply the corresponding security measures.
This labelling applies to information assets held on paper, in electronic files, as well as on digital storage media such as CDs, DVDs, etc.
Information handling
Access to information will be subject to the assigned classification criteria. The restrictions intended to prevent access by unauthorised personnel are described in FP-04 Access control.
In addition, as a general rule, the filing of information classified as confidential on paper or on removable media (USB memory sticks, CDs, DVDs, etc.) will be avoided, with the sole exception of those cases in which this is strictly necessary for carrying out the activity.
Media handling
Management of removable media
In any case, for removable media that may hold confidential information, the premises defined in the following must be applied:
- FP-04 Access Control
- The Protection of portable devices section of FP-07 Protection of equipment.
- The Custody and transport section of FP08 Protection of information media.
- Procedure for the entry and exit of equipment and media.
No media containing information classified as confidential may be provided to persons outside the organisation without the due authorisation of the Management of GRUPO ACRECENTA.
Disposal of media
Media containing sensitive information must be stored and/or disposed of securely, in order to prevent unauthorised personnel from accessing it.
No media that may contain information classified as confidential or private will leave the organisation for disposal without the express authorisation of the Management of GRUPO ACRECENTA.
The disposal of paper documents, as well as of any data recording media (DVD or CD) containing information classified as confidential or private, will be carried out by physical destruction, either by mechanical or manual means.
In the case of other IT media, the System Manager will be in charge of managing them, having to prevent access to them while they are in their custody and being responsible for their secure disposal in accordance with the provisions of the Erasure and Destruction of media section of FP-08 Protection of information media.
Physical media in transit
As a general rule, physical media containing information considered confidential or private may not be taken outside the premises of GRUPO ACRECENTA without the express authorisation of the Management of GRUPO ACRECENTA.
In any case, in order to prevent unauthorised access:
- Whenever possible, the information will be encrypted.
- In the case of information on paper, it must be sent in a closed and sealed envelope.
Likewise, as already indicated in the previous sections, the measures described in the following must be applied:
- Access Control
- The Protection of portable devices section of Protection of equipment.
- The Custody and transport section of Protection of information media.
RISK MANAGEMENT
All systems subject to this Policy must carry out a risk analysis, assessing the threats and risks to which they are exposed. This analysis will be repeated:
- regularly, at least once a year,
- when the information handled changes,
- when the services provided change,
- when a serious security incident occurs, and/or
- when serious vulnerabilities are reported.
In order to harmonise risk analyses, the ICT Security Committee will establish a reference assessment for the different types of information handled and the different services provided. The ICT Security Committee will promote the availability of resources to meet the security needs of the different systems, encouraging horizontal investments.
Risk management will be documented in the Risk analysis and management report.
STAFF OBLIGATIONS
Each and every user of the information systems is responsible for the security of the information assets through their correct use, always in accordance with their professional and academic remit.
All members of GRUPO ACRECENTA are obliged to know and comply with this Information Security Policy and the Security Regulations, and it is the responsibility of the Security Committee to provide the means necessary for the information to reach those affected.
In addition, they will attend an information security awareness session at least once a year. A continuous awareness programme will be established to reach all members of GRUPO ACRECENTA, in particular new joiners.
Persons with responsibility for the use, operation or administration of ICT systems will receive training on the secure handling of the systems to the extent that they need it to carry out their work. Training will be mandatory before assuming a responsibility, whether it is their first assignment or a change of position or of responsibilities within the same position.
Failure to comply with this Information Security Policy may lead to the initiation of the appropriate disciplinary measures, without prejudice to the corresponding legal liabilities.
THIRD PARTIES
When GRUPO ACRECENTA provides services to other organisations or handles information belonging to other organisations, they will be informed of this Information Security Policy, channels will be established for reporting and for coordination between the respective Security Committees, and procedures will be established for reacting to security incidents.
When GRUPO ACRECENTA uses third-party services or transfers information to third parties, they will be informed of this Security Policy and of the Security Regulations affecting those services or that information. Such third parties will be subject to the obligations established in those regulations, and may develop their own operating procedures to comply with them.
Specific procedures will be established for reporting and resolving incidents. It will be ensured that third-party personnel are adequately aware of security matters, at least to the same level as that established in this Policy.
When any aspect of the Policy cannot be satisfied by a third party as required in the preceding paragraphs, a report from the Security Officer will be required specifying the risks incurred and how to address them. Approval of this report by the Information Owner and the Owners of the affected services will be required before proceeding.