This policy provides the basis for defining and delineating the objectives and responsibilities for the various technical and organizational measures required to ensure compliance with information security requirements, in accordance with the applicable legal framework, directives, specific policies, and defined procedures.


These measures are selected and implemented based on a risk analysis and the balance between acceptable risk and the cost of the measures.
SIRT has defined the security requirements, identifying and prioritizing the importance of the various elements of the activity, so that the most important and/or sensitive processes receive greater protection.


Management and all SIRT employees are committed to promoting and supporting the implementation of the technical and organizational measures necessary to minimize the potential risks to which information is exposed, in pursuit of the business’s strategic objectives.

The purpose of this Policy is to achieve an appropriate level of compliance, commitment, and protection. Specifically regarding the Company’s information security and respect for user privacy, this policy is designed to uphold the following security principles:

These basic principles must be preserved and ensured regardless of the form the information takes—whether electronic, printed, visual, or spoken—and regardless of whether it is handled on or off Company premises.
Furthermore, these principles must be taken into account in the following areas of security:

The Information Security Policy has been developed to ensure the confidentiality, integrity, traceability, authenticity, and availability of the Company’s technology and information assets, and it aligns with international standards for information security. Furthermore, this Policy refers to the General Information Security Regulations, and the controls of the National Security Framework at the high-security level apply.
With regard to data protection and privacy, this Policy has been developed in accordance with the guidelines and directives of the supervisory authority (Spanish Data Protection Agency) and the recommendations of the European Data Protection Board, including the guidelines of the Article 29 Working Party.

The Company's Executive Management expresses its formal commitment to supporting the safety plans resulting from the implementation of this integrated policy.

This support will take the following forms:

We are publishing this policy for the record and to ensure it takes effect as intended.