Cybersecurity Policy

Introduction

The organization’s Security Policy reflects the concepts, principles, responsibilities and objectives in security matters, the results of which allow the company to guarantee the necessary freedom of action.
The objective of the organization’s Integral Security is to protect the people who work in the company, the confidentiality of its communications and the integrity and availability of its information. It also safeguards the other assets that make up the company’s assets, such as its facilities and contents of all kinds.
Integral Security comprises the traditional concepts of physical security and logical (technological) security in order to maintain business continuity in the face of any adverse circumstance.
An increase in the «security culture» among company personnel will provide clear benefits by increasing the security of systems and procedures, and will minimize the risk of potential malicious actions.
It is essential that all information concerning security issues flows through the appropriate channels to the company’s decision-making bodies.

Principles

Integration. Global Security is an integrated process aligned with the business, in which the entire company participates.

Profitability. Security is guided by business criteria, taking into account the relationship between expenditure and investment. Its criteria are set centrally, taking advantage of any existing synergies. This management allows for an overall reduction in expenditure and a better return on the effort applied to security.

Continuity. Security must be present throughout its work cycle: protection, prevention, detection, response and recovery.

Adequacy. The means employed must be adapted to the business environment. Among other factors, competition with other companies, social, political and economic upheavals, amateur or professional hacking, etc. stand out for their impact on the business and on the organization’s security levels.

Responsibilities

The ultimate responsibility for security lies with the management team, which is directly responsible for managing its development and implementation.
The management team will analyze the security risks and vulnerabilities that may affect the smooth running of the business and will propose the appropriate rules, means and measures to minimize them.
All the organization’s personnel must assume responsibility for maintaining the security of the assets in their charge, observing the security standards implemented by the management team.

Objectives

Achieve and maintain the level of security required to adequately guarantee business continuity, even in adverse situations.
To increase the integration and mutual support of the physical and logical aspects of security.
Collaborate in the management of other security disciplines, including labor and environmental aspects, taking into account the criteria that promote Corporate Social Responsibility.
Establish the corporate security structure defined by the organization’s decision-making bodies and create the appropriate communication channels between all those involved.
Comply with official safety regulations and other requirements.
Establish and implement Safety Training and Dissemination Plans to improve personnel training.
Express commitment to continuous improvement.
Integrate the different departments of the company in a safety management system that, under common criteria, takes advantage of synergies and achieves consistency in resources and actions.
All personnel of the organization will know and apply the regulations that develop this Safety Policy.