The Entity considers the integrity, availability and confidentiality of the information it manages, its own as well as the rest of the group’s companies, collaborators, suppliers and, in particular, that of our customers, is essential for proper operational functioning and protection of customers’ interests and, therefore, must be protected against any risk that may affect it.
The Management of the Entity has determined, accordingly, that the information as well as the platforms and systems that enable its processing, storage and communication are assets of particular relevance for the Entity and as such are protected.
In this respect, within the strategic objectives the Entity has defined, information security contributes significantly to ensure a quality service, that having information systems security as one of its key pillars, enables us to improve our production processes, as well as build our customers’ trust in the services offered by the Entity.
The Entity establishes as information security and cybersecurity objectives:
- Demonstrate the Management’s commitment to information security providing the necessary means.
- Define, develop and put into operation the methodological, technical, organisational and management controls, needed to effectively ensure the preservation of the appropriate levels of confidentiality, availability and integrity of the information, following a risk-based approach, and based on the “secure by design” and “secure by default” principles.
- Comply at all times with existing legislation that is applicable to the Entity’s activity from the point of view of security and cybersecurity.
- Protect information assets against internal and external cyberthreats.
- Comply with existing regulations and directives in security matters issued by supervisory bodies, as well as with those security requirements the Entity contractually acquires.
- Continually create and promote a “security culture” internally, to all the staff, as well as externally to customers and suppliers, in order to ensure the efficiency and effectiveness of the controls implemented and build customers’ trust in our Entity.
- Promote capacities for prevention, detection, reaction, analysis, recovery, investigation and coordination against security incidents and cybercrime activities.
- Address information security integrated in a model of continuous improvement that achieves increasingly more optimised security controls.
- Preserve the confidentiality, integrity and availability of the information based on its level of relevance.
- Ensure the resilience and continuity of the business.
- Enable the auditability of all the relevant security events.