The Entity considers that the confidentiality, integrity, availability and authenticity of the information it manages, both its own and that of the rest of the group companies, collaborators, suppliers and, particularly, our customers, is essential for the proper operational functioning and protection of the interests of customers, and therefore needs to be protected from any risk that may affect it.
The Entity’s management has determined, accordingly, that both the information and the platforms and systems that allow its processing, storage and communication are assets of particular relevance to the Entity and as such are protected.
In this sense, within the strategic objectives that the Entity has set out, information security contributes significantly to ensure a quality service, which having the security of information systems as one of its fundamental pillars, allows us to improve our production processes and increase our customers’ trust in the services offered by the Entity.
The Entity sets as information security and cybersecurity objectives:
- Demonstrate the commitment of the Management to information security by providing the necessary means.
- Define, develop and implement the methodological, technical, organisational and management controls necessary to effectively ensure the preservation of adequate levels of confidentiality, integrity, availability and authenticity of information, following a risk-based approach, and on the basis of the principles of "safety by design" and "safety by default".
- Comply at all times with the current legislation applicable to the activity of the Entity from the point of view of security and cybersecurity.
- Protect information assets against internal and external cyberthreats.
- Comply with the regulations and directives in force in terms of safety issued by the supervisory bodies, as well as with those security requirements that the Entity contractually acquires.
- Create and continuously promote a "safety culture" both internally, to all staff, and externally to customers and suppliers, which ensures the efficiency and effectiveness of the controls implemented and increases customer's trust in our Entity.
- Promote capabilities for prevention, detection, response, analysis, recovery, response, investigation and coordination against security incidents and cybercrime activities.
- Treat information security integrated in a model of continuous improvement that achieves increasingly optimized security controls.
- Preserve the confidentiality, integrity, availability and authenticity of information based on the level of its relevance.
- Ensure business continuity and resilience.
- Enable the auditability of all safety relevant facts.