This policy provides the basis for defining and delineating the objectives and responsibilities for the various technical and organizational measures required to ensure compliance with information security requirements, in accordance with the applicable legal framework, directives, specific policies, and defined procedures.
These measures are selected and implemented based on a risk analysis and the balance between acceptable risk and the cost of the measures.
SIRT has defined the security requirements, identifying and prioritizing the importance of the various elements of the activity, so that the most important and/or sensitive processes receive greater protection.
Management and all SIRT employees are committed to promoting and supporting the implementation of the technical and organizational measures necessary to minimize the potential risks to which information is exposed, in pursuit of the business’s strategic objectives.
The purpose of this Policy is to achieve an appropriate level of compliance, commitment, and protection. Specifically regarding the Company’s information security and respect for user privacy, this policy is designed to uphold the following security principles:
- Confidentiality
- Information Integrity
- Availability
- Authenticity
- Traceability
These basic principles must be preserved and ensured regardless of the form the information takes—whether electronic, printed, visual, or spoken—and regardless of whether it is handled on or off Company premises.
Furthermore, these principles must be taken into account in the following areas of security:
- Physical Security: Understanding the security of facilities, installations, hardware systems, media, and any physical assets that handle or may handle
information. - Logic: Including aspects of application protection, networks, and prototypes for electronic communication and computer systems.
- Political-Corporate: Consisting of security aspects related to the Company itself, internal policies, regulations, and applicable legal requirements
The Information Security Policy has been developed to ensure the confidentiality, integrity, traceability, authenticity, and availability of the Company’s technology and information assets, and it aligns with international standards for information security. Furthermore, this Policy refers to the General Information Security Regulations, and the controls of the National Security Framework at the high-security level apply.
With regard to data protection and privacy, this Policy has been developed in accordance with the guidelines and directives of the supervisory authority (Spanish Data Protection Agency) and the recommendations of the European Data Protection Board, including the guidelines of the Article 29 Working Party.
The Company's Executive Management expresses its formal commitment to supporting the safety plans resulting from the implementation of this integrated policy.
This support will take the following forms:
- provide the necessary human and financial resources, within budgetary constraints;
- assign roles and responsibilities to the individuals involved in the safety plans;
- support the training of personnel involved in the integrated management system so that they acquire the necessary level of awareness and skills;
- ensure the proper functioning of the management system.
- facilitate communication with other organizations regarding information security, as well as direct contact with the relevant authorities.
- Promote the development of this policy
We are publishing this policy for the record and to ensure it takes effect as intended.