Menu

Last modification: 21/07/2026
 
SECURITY POLICY
INTRODUCTION

This document sets out the Information Security Policy of INTELEQUIA TECHNOLOGIES S.L. (hereinafter INTELEQUIA), as the set of basic principles and lines of action to which the organization is committed, within the framework of the ISO 27001 Standard.

Information is a critical, essential asset of great value for the development of INTELEQUIA's activity. This asset must be adequately protected, by means of the necessary security measures, against threats that may affect it, regardless of the formats, media, means of transmission, systems, or persons involved in its knowledge, processing or processing.

Information Security is the protection of this asset, in order to ensure the quality of information and business continuity, minimize risk and maximize the return on investments and business opportunities.

Information security is a process that requires technical and human resources and adequate management and definition of procedures and in which the maximum collaboration and involvement of all INTELEQUIA staff is essential.

Different departments must ensure that ICT security is an integral part of every stage of the system's lifecycle, from conception to decommissioning, development or acquisition decisions and operational activities. Security requirements and funding needs should be identified and included in planning, in the request for proposals, and in tender documents for ICT projects.

Departments must be prepared to prevent, detect, react and ensure conservation in the event of incidents, in accordance with Article 8 of the ENS.

This policy will be developed by applying the following minimum requirements:

  • Organization and implementation of the security process.

  • Risk analysis and management.

  • Personnel management.

  • Professionalism.

  • Authorisation and access control.

  • Protection of the facilities.

  • Acquisition of security products and contracting of security services.

  • Least privilege

  • System integrity and updating.

  • Protection of information in storage and in transit.

  • Prevention of other interconnected information systems.

  • Activity logging and detection of harmful code.

  • Security incidents.

  • Continuity of activity.

  • Continuous improvement of the security process.

The management of INTELEQUIA, aware of the value of information, is deeply committed to the policy described in this document.

PREVENTION

Departments should avoid, or at least prevent as much as possible, information or services from being harmed by security incidents. To do this, departments must implement the minimum security measures determined by the ENS, as well as any additional controls identified through a threat and risk assessment.

These controls, and the safety roles and responsibilities of all personnel, must be clearly defined and documented.

To ensure compliance with the policy, departments should:

  • Authorize systems before they go into operation.

  • Regularly assess security, including assessments of configuration changes made on a routine basis.

  • Request periodic review by third parties for the purpose of obtaining an independent evaluation.

DETECTION

Since services can be rapidly degraded due to incidents, ranging from a simple slowdown to a stoppage, services must monitor the operation on an ongoing basis to detect anomalies in service delivery levels and act accordingly as set out in Article 8 of the ENS.

Monitoring is especially relevant when lines of defence are established in accordance with Article 9 of the ENS. Detection, analysis and reporting mechanisms will be established that reach those responsible regularly and when there is a significant deviation from the parameters that have been pre-established as normal.

RESPONSE

Departments must:

  • Establish mechanisms to respond effectively to security incidents.

  • Designate a point of contact for communications regarding incidents detected in other departments or in other agencies.

  • Establish protocols for the exchange of information related to the incident. This includes two-way communications with Emergency Response Teams (CERTs).

PRESERVATION

Without detracting from the other basic principles and minimum requirements established in the ENS, the information system will guarantee the conservation of data and information in electronic format.

DEFINITIONS
  • Information System: An organized set of resources for information to be collected, stored, processed, maintained, used, shared, distributed, made available, presented, or transmitted.

  • Risk: estimate of the degree of exposure to a threat materializing on one or more assets causing damage or harm to the organization.

  • Risk management: coordinated activities to direct and control an organization with respect to risks.

  • Information Security Management System (ISMS): management system that, based on the study of risks, is established to create, implement, operate, supervise, review, maintain and improve information security. The management system includes the organizational structure, policies, planning activities, responsibilities, practices, procedures, processes, and resources.

  • Availability: It is necessary to ensure that system resources are available when they are needed, especially critical information.

  • Integrity: The information in the system must be available as stored by an authorized agent.

  • Confidentiality: The information should only be available to authorized agents, especially its owner.

  • ENS: These are the acronyms for the National Security Scheme, regulated by Royal Decree 311/2022, of 3 May, which regulates the National Security Scheme, being its application in the field of electronic administration in the public sector. Its purpose is to establish the security policy and create the necessary conditions for confidence in the use of electronic means, through measures to guarantee the security of electronic systems, data, communications and services, which allows the exercise of rights and the fulfillment of duties through these means.

  • Asset: In relation to information security, it refers to any information or element related to its processing (systems, supports, buildings, people...) that has value for the organization.

  • Threat: The potential cause of an unwanted incident, which can lead to damage to a system or organization.

  • Risk Analysis: The process of understanding the nature of the risk and determining the level of risk.

  • Risk treatment: The process of modifying risk by implementing controls.

  • Authenticity: Ownership that a person and or company that has accessed and used the information is what it claims to be.

PURPOSE

The purpose of this Information Security Policy is to protect INTELEQUIA's information assets, ensuring the availability, integrity and confidentiality of the information and the facilities, systems and resources that process, manage, transmit and store it, always in accordance with the requirements of the business and current legislation.

SCOPE

The scope of the Information Security Management System encompasses the information systems that support the development, infrastructure, support and training services that are carried out working under CMS, SaaS, PaaS and IaaS solutions in public clouds, and the SOC (Security Operation Center) services for our customers. The execution of these works is carried out at the headquarters located in Santa Cruz de Tenerife, Avenida Manuel Hermoso Rojas 4, Torre I, Office 8. Property of INTELEQUIA.

This Information Security Policy is applicable to all persons, systems and means that access, process, store, transmit or use the information known, managed or owned by INTELEQUIA for the processes described.

Personnel subject to this policy include all persons with access to the information described, regardless of the automated or non-automated support in which it is located and whether or not the individual is an employee of INTELEQUIA. Therefore, it also applies to contractors, clients or any other third party that has access to INTELEQUIA's information or systems.

To ensure that the security process in place will be continuously updated and improved, an Information Security Management System will be implemented and documented. In this way, the content of the Information Security Policy will be developed into complementary security standards and procedures.

OBJECTIVES AND RATIONALE OF THIS POLICY

Information must be protected throughout its life cycle, from its creation or reception, during its processing, communication, transport, storage, dissemination and until its eventual deletion or destruction. Therefore, the following minimum principles are established:

  • Principle of confidentiality: information systems must be accessible only to those users, bodies and entities or processes expressly authorised to do so, with respect for the obligations of secrecy and professional secrecy.

  • Principle of integrity and quality: the integrity and quality of the information must be maintained, as well as the processes for processing it, and mechanisms must be established to ensure that the processes of creation, processing, storage and distribution of the information contribute to preserving its accuracy and correctness.

  • Principle of availability and continuity: a level of availability in the information systems will be guaranteed and the necessary plans and measures will be provided to ensure the continuity of services and recovery in the event of possible serious contingencies.

  • Risk management principle: a continuous process of risk analysis and treatment must be articulated as a basic mechanism on which the management of the security of information systems must rest.

  • Principle of proportionality in cost: the implementation of measures that mitigate the security risks of information systems must be carried out under an approach of proportionality in economic and operational costs, without prejudice to ensuring that the necessary resources for the information security management system are available.

  • Principle of awareness and training: initiatives will be articulated that allow users to know their duties and obligations regarding the secure treatment of information. Similarly, specific training in ICT security will be promoted for all those who manage and administer information and telecommunications systems.

  • Principle of prevention: specific plans and lines of work will be developed aimed at preventing fraud, non-compliance or incidents related to ICT security.

  • Principle of detection and response: services must continuously monitor the operation to detect anomalies in the levels of service provision and act accordingly by responding effectively, through the mechanisms established for this purpose, to security incidents.

  • Principle of continuous improvement: the degree of compliance with the security improvement objectives planned annually and the degree of effectiveness of the ICT security controls implemented will be reviewed, in order to adapt them to the constant evolution of risks and the technological environment of the Public Administration.

  • ICT security principle in the life cycle of information systems: security specifications shall be included in all phases of the life cycle of services and systems, accompanied by the corresponding control procedures.

  • Principle of differentiated function: the responsibility for the security of information systems will be differentiated from the responsibility for the provision of services.

  • Establish the guidelines and principles that will govern the way in which the entity, INTELEQUIA, will manage and protect its information and services, through the implementation, maintenance and improvement of Royal Decree 311/2022, of 3 May, which regulates the National Security Scheme.

  • Guide the actions on Information Security Management that INTELEQUIA adopts and commits to, so that they are aligned with the business objectives.

Specifically, for proper compliance with the ENS, the information security objectives will be established in the relevant functions and levels, focused on improvement and using as a frame of reference:

  • Changes in stakeholder needs leading to improved system scope.

  • Applicable information security requirements and the results of the assessment and treatment of risks to ensure the confidentiality, integrity, availability, traceability and authenticity of the information.

  • Internal factors such as the application of organizational techniques that improve the monitoring of the processing and resolution of security incidents.

  • External factors such as technological advances, the application of which improves the effectiveness of risk treatment.

  • Improving the effectiveness of the training and awareness of the personnel working at INTELEQUIA and affecting their performance in information security.

Likewise, the planning for the achievement of the established information security objectives will be carried out taking into account the following elements:

  • What is going to be done.

  • The necessary resources.

  • The person responsible.

  • Time limit for completion.

  • Indicators to evaluate the result/compliance

The Information Security Policy is approved by the Management of INTELEQUIA and its content and that of the rules and procedures that develop it are mandatory.

  • All users with access to the information processed, managed or owned by INTELEQUIA have the obligation and duty to safeguard and protect it.

  • The Information Security Policy and Standards will be adapted to the evolution of systems and technology and organisational changes and will be aligned with current legislation and with the standards and best practices of ISO/IEC 27001:2022.

  • The security measures and the applicable physical, administrative and technical controls will be detailed in the Applicability Document and INTELEQUIA must establish a plan for their implementation and management.

  • The security measures and controls established shall be proportional to the criticality of the information to be protected and its classification.

  • Users who fail to comply with the Information Security Policy or the complementary rules and procedures may be sanctioned in accordance with the provisions of the contracts that protect their relationship with INTELEQUIA and with current and applicable legislation.

LEADERSHIP AND MANAGEMENT COMMITMENT

INTELEQUIA's Management undertakes to facilitate and provide the necessary resources for the establishment, implementation, maintenance and improvement of the entity's ENS, as well as to demonstrate leadership and commitment to it, through the constitution of the Information Security Committee that will be responsible for:

  • Ensure the establishment of this policy and the objectives of information security, and that these are compatible with INTELEQUIA's strategy.

  • Ensure integration and compliance with applicable ENS requirements in the organization's processes.

  • Ensure that the necessary resources for the ENS are available.

  • Communicate the importance of effective and ENS-compliant safety management.

  • Ensure that the ENS achieves the intended results.

  • Lead and support people to contribute to the effectiveness of the ENS.

  • Promote continuous improvement.

  • Support other relevant roles of the Management, leading their areas of responsibility in information security.

LEGAL REQUIREMENTS
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR).

  • Organic Law 3/2018, of 5 December, on Data Protection and Guarantee of Digital Rights (LOPDGDD).

  • Royal Legislative Decree 1/1996, of 12 April, Intellectual Property Law.

  • Law 34/2002 of 11 July 2002 on information society services and electronic commerce.

  • Law 2/2019, of 1 March, amending the revised text of the Intellectual Property Law, approved by Royal Legislative Decree 1/1996, of 12 April, and incorporating Directive 2014/26/EU of the European Parliament and of the Council, of 26 February 2014, into Spanish law, and Directive (EU) 2017/1564 of the European Parliament and of the Council, of 13 September 2017.

  • Royal Decree 311/2022, of 3 May, regulating the National Security Scheme.

INFORMATION CLASSIFICATION

The information will be classified according to the sensitivity required in its processing and the levels of security and protection required.

ROLES, RESPONSIBILITIES AND DUTIES

Management assigns and communicates responsibilities, authorities, and roles in relation to information security. It will also ensure that users are aware of, assume and exercise the responsibilities, authorities and roles assigned.

The ICT Security Committee will be made up of:

This committee may be assisted sporadically by external consultants.

The ICT Security Committee will have the following functions:

  • Annual review of the security policy.

  • Development of the procedure for the designation of roles.

  • Designation of roles and responsibilities.

  • Supervision and approval of ENS follow-up tasks:

  • Adequacy tasks.

  • Risk analysis.

  • Biennial audit.

  • Ensure compliance with safety regulations.

  • Definition and monitoring of initiatives and strategic objectives in ICT security

  • Setting the conditions to meet information security requirements.

  • Approve safety procedures.

  • Ensure the availability of the necessary resources to develop the necessary strategic security initiatives and objectives.

  • Promote the development of guidelines on information security.

  • Promote training and awareness in information security.

  • Ensure proper compliance with the security policy.

ROLES: ROLES AND RESPONSIBILITIES

The person responsible for the information will have the following functions and responsibilities:

  • Establishment of security requirements that guarantee the processing of information.

  • Work in collaboration with the Security Manager and the System Manager in the assessment of the information in the different security dimensions and the maintenance of the systems catalogued according to Annex I ENS.

  • Ensure the correct inclusion of security clauses in contracts with third parties and their compliance.

  • Assess the consequences of a negative impact on information security, taking into account its impact on the organisation's ability to achieve its objectives, the protection of its assets, the fulfilment of its service obligations, respect for the law and the rights of citizens.

The person responsible for the service will have the following functions and responsibilities:

  • Establishment of the requirements for services provided through electronic means in terms of security.

  • Work in collaboration with the Security Manager and the System Manager in the assessment of the services in the different security dimensions and the maintenance of the systems catalogued according to Annex I of the ENS.

  • Assess the consequences of a negative impact on information security in terms of its impact on the organisation's ability to achieve its objectives, protect its assets, fulfil its service obligations, respect for the law and the rights of citizens

  • Include safety specifications in the life cycle of services and systems, accompanied by control procedures.

The person responsible for security will have the following functions and responsibilities:

  • Maintain the security of the information correctly handled and the services provided, following the guidelines set by the Information Security Committee and in accordance with the provisions of the Security Policy.

  • Promote security training and awareness following the guidelines set by the Information Security Committee.

  • Prepare proposals for modification and updating of the security policy

  • Promote periodic audits for approval and follow-up in the Security Committee to verify compliance with safety obligations.

  • Develop the safety policy by drawing up safety regulations.

  • Analyze, complete, and approve all documentation related to system security.

  • Monitor the security status of the system provided by the security event management tools and auditing mechanisms implemented in the system.

  • Support and oversee the investigation of security incidents from notification to resolution.

  • To propose for approval and follow-up in the Security Committee the lines of action in the field of information security,

  • Determine the relevant security decisions to meet the requirements established by those responsible for information and services. Being a natural person, hierarchically independent of the System Manager.

  • Prepare the Declaration of Applicability document.

  • To act as a trainer of good practices in the security of networks and information systems, both in physical and logical aspects.

  • To constitute the specialised point of contact for coordination with the CSIRT of reference.

  • Notify the competent authority, through the CSIRT of reference and without undue delay, of incidents that have disruptive effects on the provision of services.

  • Receive, interpret and apply the instructions and guides issued by the Competent Authority, both for the usual operation and for the correction of the deficiencies observed.

  • Collect, prepare and supply information or documentation to the competent authority or the CSIRT of reference, at its request or on its own initiative.

The person responsible for the system will have the following functions and responsibilities:

  • Develop, operate and maintain the information system throughout its life cycle, including its specifications, installation and verification of its correct operation.

  • Define the topology and management of the information system, establishing the criteria for use and the services available in it.

  • Ensure that security measures are properly integrated into the overall security framework.

  • The System Manager may propose the suspension of the processing of certain information or the provision of a certain service if it notices serious security deficiencies that could affect the satisfaction of the established requirements. The final decision, which will be taken by the management of the entity, must be agreed with those responsible for the information and services affected and the Security Officer.

APPOINTMENT PROCEDURES

The Information Security Officer will be appointed at the proposal of the ICT Security Committee. The appointment will be reviewed every 2 years or when the position becomes vacant.

The Department responsible for a service that is provided electronically in accordance with Law 39/2015 will designate the person responsible for the System, specifying their functions and responsibilities within the framework established by this Policy

CONFLICT RESOLUTION

The resolution of conflicts between the different responsible parties will be governed by the decision of the Management, which must be communicated to the Information Security Committee.

SECURITY RISK ASSESSMENT

Knowing the risks and developing a strategy to manage them properly is essential for INTELEQUIA, since only if the state of security is known can the appropriate decisions be made to mitigate the risks it faces.

The Magerit methodology will be used to analyse the risks. Therefore, a detailed analysis of the risks affecting the assets included in an asset inventory will be carried out, which will be documented in a Risk Analysis document.

The entity must determine the levels of risk from which it will take treatment actions on them. A Risk is considered acceptable when implementing more security controls is estimated to consume more resources than the potential associated impact.

Once the risk assessment process has been carried out, INTELEQUIA's management will be responsible for approving the residual risks and risk treatment plans.

All systems subject to this Policy shall conduct a risk analysis, assessing the threats and risks to which they are exposed. This analysis will be repeated:

  • regularly, at least once a year

  • when the information handled changes

  • when the services provided change

  • When a Serious Security Incident Occurs

  • when serious vulnerabilities are reported

For the harmonisation of risk analyses, the ICT Security Committee will establish a reference assessment for the different types of information handled and the different services provided. The ICT Security Committee will boost the availability of resources to meet the security needs of the different systems, promoting horizontal investments.

RISKS ARISING FROM THE PROCESSING OF PERSONAL DATA

INTELEQUIA carries out a risk analysis of personal data and applies the following criteria:

  • Transparency, lawfulness and fairness in data processing

  • Limitation of the purpose of the processing

  • Principleofminimization,Pick upaloneTheDatastrictly necessary

  • Accuracy, data must be truthful and up-to-date

  • Retention period limited to the time necessary for the fulfilment of the purpose

  • Data confidentiality and integrity

PROJECTS

All projects related to or affecting information systems must include, in their analysis process, an assessment of the security requirements and define a security model agreed with the information security officer.

In the design, development, installation and management of information systems and projects, the concepts of security will be taken into account and applied from the design, secure coding and the controls and security measures that are appropriate according to the applicability document approved by INTELEQUIA.

CONTRACTING AND PROCUREMENT

All contracts and acquisitions that involve or require access to or processing of information classified as non-public must be carried out under a contract that includes clauses aimed at guaranteeing the safeguarding of the confidentiality, integrity and availability of information.

In those cases in which the contracted services involve access to or processing by the provider of personal data, the clauses required for compliance with the Organic Law on the Protection of Personal Data and its developments, as well as the future development of the European Data Protection Regulation, must be included in the contract.

Companies and persons who, on the occasion of contracting services or acquisitions of any kind, have access to confidential information or information for internal use, must be aware of the Information Security Policy and the complementary rules and procedures that are applicable for the purpose of the contract.

Companies and external persons who access INTELEQUIA's information must consider such information, by default, as confidential. The only information that may be considered as non-confidential is that which has been obtained through the public media.

AWARENESS, DISSEMINATION AND TRAINING

This Information Security Policy must be known by all internal and external users and by the companies that access, manage or process INTELEQUIA data.

The set of Policies, standards and procedures complementary to this Information Security Policy must also be adequately communicated and made known to the persons, companies and institutions affected or involved in each case.

Communication, awareness and training programmes will be defined periodically and a copy of the corresponding regulations will be given to users.

SECURITY INCIDENT RESPONSE

Any compromise of the confidentiality, integrity or availability of INTELEQUIA's information is considered a security incident. This includes, but is not limited to, unauthorized access, deletion, destruction, modification, or discontinuance of availability. Security incidents are also considered mere attempts to compromise the above conditions, those to avoid, alter or modify security measures or violations or breaches of the Information Security Policy or complementary rules and procedures.

Users are responsible for immediately reporting any security incident, through the channels and procedures defined in the organization for the communication of incidents.

THIRD PARTIES

When INTELEQUIA provides services to other organizations or handles information from other organizations, they will be made participants in this Security Policy, channels will be established for reporting and coordination of the respective ICT Security Committees and action procedures will be established for the reaction to security incidents.

When INTELEQUIA uses third-party services or transfers information to third parties, they will be made participants in this Security Policy and the Security Regulations that concern such services or information. This third party will be subject to the obligations established in said regulations, and may develop its own operating procedures to satisfy it. Specific procedures will be established for reporting and resolving incidents, for which the signatory of the contract will be considered as the interlocutor in the resolution of incidents, unless expressly mentioned or designated in the contract. It will be ensured that third-party personnel are adequately aware of security, at least at the same level as that established in this Policy. Where any aspect of the Policy cannot be satisfied by a third party as required in the preceding paragraphs, a report from the Security Officer shall be required specifying the risks incurred and how to deal with them. Approval of this report by those responsible for the information and services concerned will be required before proceeding.

REVIEW AND AUDITS

The Security Officer will review this policy annually or when there are significant changes that make it advisable, and will submit it again for management approval.

The reviews will check the effectiveness of the policy, assessing the effects of technological and business changes.

Management will be responsible for approving the necessary modifications to the text when there is a change that affects the risk situations set out in this document.

The safety management system will be audited every year, according to an audit plan developed by the safety officer.