Products · Services · Technology · The Company · Contact
Information security policy.
INTRODUCTION
Capmar, hereinafter referred to as the Organization, relies on ICT (Information and Communication Technologies) systems to achieve its business objectives. These systems must be managed with due diligence by implementing appropriate measures to protect them against accidental or deliberate damage that may affect the availability, integrity, or confidentiality of the information processed or the services provided.
The objective of information security is to ensure the quality of information and the continuous delivery of services by acting proactively, monitoring daily operations, and responding promptly to security incidents.
ICT systems must be protected against rapidly evolving threats that may affect the confidentiality, integrity, availability, intended use, and value of information and services. To defend against these threats, a strategy that adapts to changes in the operating environment is required in order to ensure continuous service delivery.
This means that all departments must implement the minimum security measures required by the Spanish National Security Framework (ENS), continuously monitor service performance levels, track and analyze reported vulnerabilities, and prepare effective responses to security incidents to ensure service continuity.
All departments shall ensure that ICT security is an integral part of every stage of the system lifecycle—from design through decommissioning—including development or acquisition decisions and operational activities. Security requirements and funding needs must be identified and incorporated into planning, procurement requests, and tender specifications for ICT projects.
Departments shall be prepared to prevent, detect, respond to, and recover from incidents, in accordance with Article 7 of the ENS.
PREVENTION
Departments shall avoid—or, wherever possible, prevent—information or services from being adversely affected by security incidents.
To achieve this, departments shall implement the minimum security measures established by the ENS, together with any additional controls identified through threat and risk assessments.
These controls, together with the security roles and responsibilities assigned to all personnel, shall be clearly defined and documented.
To ensure compliance with this policy, departments shall:
Authorize systems before they enter into operation.
Regularly assess security, including evaluations of routine configuration changes.
DETECTION
Because services may deteriorate rapidly as a result of incidents—from minor performance degradation to complete service interruption—they shall be continuously monitored to detect anomalies in service performance levels and appropriate action shall be taken in accordance with Article 9 of the ENS.
Monitoring is particularly important when defense layers are implemented in accordance with Article 8 of the ENS.
Detection, analysis, and reporting mechanisms shall be established to provide regular information to responsible personnel and whenever a significant deviation from predefined normal operating parameters occurs.
RESPONSE
Departments shall:
Establish mechanisms to respond effectively to information security incidents.
Designate a point of contact for communications regarding incidents detected by other departments or organizations.
Establish protocols for exchanging information related to security incidents, including two-way communications with Computer Emergency Response Teams (CERTs).
SCOPE
This policy applies to all ICT systems of the Organization and to all Capmar personnel, without exception.
MISSION
In response to a new technological environment where the convergence of information technology and communications is creating a new productivity paradigm for businesses, the Organization is strongly committed to promoting research, technological development, and innovation projects within a quality-driven environment where the implementation of Information Security best practices is essential to achieving the objectives of confidentiality, integrity, availability, and legal compliance for all managed information.
Accordingly, the Organization establishes the following principles within the framework of its Information Security Management System (ISMS).
Senior Management recognizes its responsibility to guarantee information security as an essential element for the proper delivery of the Organization's services and therefore supports the following objectives and principles:
I. Promote the value of Information Security throughout the Organization.
II. Ensure that every member of the Organization contributes to protecting Information Security.
III. Preserve the confidentiality, integrity, availability, and resilience of information in order to ensure compliance with legal, regulatory, and customer requirements relating to information security, and specifically with regard to personal data:
a. Personal data shall be processed lawfully, fairly, and transparently in relation to the data subject (Lawfulness, Fairness and Transparency).
b. Personal data shall be collected for specified, explicit, and legitimate purposes and shall not be further processed in a manner incompatible with those purposes (Purpose Limitation).
c. Personal data shall be adequate, relevant, and limited to what is necessary for the purposes for which it is processed (Data Minimization).
d. Personal data shall be accurate and, where necessary, kept up to date. Every reasonable step shall be taken to ensure that inaccurate personal data is erased or rectified without delay (Accuracy).
e. Personal data shall be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which it is processed, except where longer retention is required solely for archiving in the public interest, scientific or historical research, or statistical purposes (Storage Limitation).
f. Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage through appropriate technical and organizational measures (Integrity and Confidentiality).
g. Personal data shall be processed in a manner that guarantees an appropriate level of security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through the implementation of appropriate technical and organizational measures (Integrity and Confidentiality).
IV. Protect the Organization's information assets against internal and external threats, whether deliberate or accidental, in order to ensure the continuity of services provided to customers and the security of information.
V. Establish an Information Security Plan that integrates activities aimed at preventing and minimizing the risk of security incidents, based on the Organization's established risk management criteria.
VI. Provide the necessary resources to implement appropriate actions for managing identified risks.
VII. Promote awareness and training in Information Security as a means of ensuring compliance with this Policy.
VIII. Extend the Organization's commitment to Information Security to all employees and suppliers.
IX. Continually improve Information Security through the establishment, monitoring, and periodic review of Information Security objectives.
This Policy shall be maintained, updated, and kept appropriate to the Organization's purpose while remaining aligned with its risk management framework. It shall be reviewed at planned intervals or whenever significant changes occur to ensure its continued suitability, adequacy, and effectiveness.
Likewise, the Organization has established a formally defined Risk Assessment Procedure to manage the risks it faces. All policies and procedures that form part of the Information Security Management System (ISMS) shall be reviewed, approved, and promoted by the Organization's Management.
REGULATORY FRAMEWORK
The Organization's Management ensures that externally generated documentation relevant to the operation of the company is made available to the employees who require it and is maintained up to date and accessible at all times.
To achieve this, the Organization uses the methods defined in this document together with the procedures that implement it.
Reference Documents
Spanish National Security Framework (ENS).
CCN Guides, Abstracts, CoCENS documentation, and all regulations applicable to the Organization.
INFORMATION SECURITY ORGANIZATION
COMMITTEES, ROLES AND RESPONSIBILITIES
An Information Security Committee has been established consisting of:
General Management.
Information Security Manager.
Systems Manager.
Data Protection Officer.
Information Owner.
Service Owner.
The Information Security Committee has the following responsibilities:
Address Management's and IT's security concerns.
Obtain an overall view of the Organization's Information Security status.
Promote the continual improvement of the Information Security Management System (ISMS).
Define the Information Security strategy and roadmap.
Review this Policy, related regulations, and procedures at least annually.
Approve Information Security training requirements.
Prioritize Information Security initiatives.
Promote ISMS and technical security audits.
Ensure that Information Security is incorporated into every organizational project.
ROLES: FUNCTIONS AND RESPONSIBILITIES
Executive Management
Participates in establishing Information Security objectives and performance indicators.
Approves Information Security policies.
Approves ISMS Management Reviews.
Validates the conclusions of Information Systems audits.
Executive Management defines the Organization's organizational structure, which includes additional functions and responsibilities beyond those described in this Policy. This document details only those roles directly related to Information Security.
Information Security Manager
Promote the security of information processed and electronic services provided by the Organization's information systems, with the authority and responsibility to ensure that the Information Security Management System complies with the requirements of the Spanish National Security Framework (ENS).
Monitor compliance with this Information Security Policy, its associated standards and procedures, and the security configuration of all information systems.
Define appropriate and effective security measures to meet the security requirements established by the Service Owners and Information Owners, always in accordance with Annex II of the ENS, documenting the applicability of those measures.
Promote awareness and Information Security training within their area of responsibility.
Coordinate and monitor the implementation of ENS compliance projects in collaboration with the Systems Manager.
Perform the required risk assessments together with the Systems Manager, select appropriate safeguards, review the risk management process, and jointly accept the residual risks identified during the risk assessment.
Promote periodic audits to verify compliance with Information Security requirements, analyze audit reports, and prepare conclusions for the Systems Manager so that appropriate corrective actions can be implemented.
Coordinate the Information Security Management process in collaboration with the Systems Manager.
Determine the security category of each information system in accordance with Annex I of the ENS and define the security measures required under Annex II.
Verify that implemented security measures provide adequate protection for both information and services.
Systems Manager
Develop, operate, and maintain the Information System throughout its entire lifecycle, including its specifications, installation, and verification of correct operation.
Ensure that specific security measures are properly integrated into the Organization's overall Information Security framework.
Carry out security exercises and testing of operational security procedures and existing Business Continuity Plans.
Implement the measures necessary to guarantee the security of the Information System throughout its lifecycle, in coordination with the Information Security Manager.
Conduct the required risk assessments together with the Information Security Manager, select the appropriate safeguards to be implemented, review the risk management process, and jointly accept the residual risks identified during the risk assessment.
Prepare, together with the Information Security Manager, third-level security documentation, including STIC Operational Procedures and STIC Technical Instructions.
Ensure the implementation and application of operational security procedures.
Verify that established security controls are strictly enforced and that approved procedures for operating the Information System are consistently followed.
Supervise hardware and software installations, as well as any modifications and upgrades, to ensure that security is not compromised and that all changes comply with the appropriate authorizations.
Monitor the security status of the Information System using implemented security event management tools and technical auditing mechanisms.
Report any security anomaly, compromise, or vulnerability to the appropriate responsible parties.
Collaborate in the investigation and resolution of security incidents from their detection through to their final resolution.
Data Protection Officer
Inform and advise the Information Owner and employees regarding their obligations under the General Data Protection Regulation (GDPR) and other applicable data protection legislation.
Monitor compliance with the GDPR, other applicable European Union or Member State data protection regulations, and the Organization's policies regarding the protection of personal data, including the assignment of responsibilities, staff awareness and training, and related audits.
Provide advice when requested regarding Data Protection Impact Assessments (DPIAs) and monitor their implementation in accordance with Article 35 of the GDPR.
Cooperate with the Supervisory Authority.
Act as the primary point of contact for the Supervisory Authority on matters relating to personal data processing, including prior consultations under Article 36 of the GDPR and any other related matters.
The Service Owner
Define security requirements for the services under their responsibility, including interoperability, accessibility, and availability requirements.
Determine the required security levels for the services in collaboration with the Information Security Manager and the Systems Manager.
Ensure the security of the information processed and the services provided by the Information Systems within their area of responsibility.
Information Owner
Ensure the proper use and protection of information assets.
Define security requirements applicable to the information under their responsibility.
Determine the security classification and protection level of the information processed by evaluating the consequences of any potential adverse impact.
Users and employees
Comply with this Information Security Policy and with all related standards, procedures, and supporting instructions.
Protect and safeguard the Organization's information by preventing unauthorized disclosure, external transmission, modification, deletion, accidental destruction, or misuse, regardless of the medium or format through which the information is accessed or stored.
Understand and comply with the Information Security Policy, the Information Systems Acceptable Use Policy, and all other applicable Information Security policies, standards, procedures, and controls.
APPOINTMENT PROCEDURES
The Organization's Management is responsible for formally appointing personnel to Information Security roles and responsibilities, as well as establishing the committees required to ensure compliance with this Policy.
These appointments and internal organizational structures shall be documented and maintained within the Organization's internal records.
INFORMATION SECURITY POLICY
The Information Security Committee shall be responsible for conducting an annual review of this Information Security Policy and for proposing any necessary revisions or confirming its continued suitability.
This Policy shall be formally approved by the Information Security Committee and communicated to all affected parties to ensure that they are aware of its contents and responsibilities.
RISK MANAGEMENT
All information systems covered by this Policy shall undergo a formal risk assessment to evaluate the threats and risks to which they are exposed.
Risk assessments shall be repeated:
At least once every year.
Whenever the information being processed changes.
Whenever the services provided change.
Following any major security incident.
Whenever significant vulnerabilities are identified.
To ensure consistency in risk assessments, the ICT Security Committee shall establish baseline classifications for the various types of information processed and the services provided.
The ICT Security Committee shall also promote the availability of the resources required to address the security needs of the different information systems, encouraging investments that strengthen security across the Organization.
DEVELOPMENT OF THE INFORMATION SECURITY POLICY
This Policy shall be supported by additional Information Security standards and procedures that address specific operational aspects relating to the use, administration, and management of the Organization's Information Technology systems.
These Information Security standards shall be made available to all members of the Organization who require access to them, particularly personnel responsible for using, operating, or administering Information and Communication Systems.
The Information Security Policy shall also be available on the Organization's website:
PERSONNEL RESPONSIBILITIES
All members of the Organization are required to understand and comply with this Information Security Policy and all associated Information Security standards.
The Information Security Committee is responsible for ensuring that the necessary means are available to communicate this information effectively to all affected personnel.
Every member of the Organization shall attend an Information Security awareness session at least once each year.
An ongoing security awareness program shall be maintained to ensure that all personnel—and especially newly hired employees—receive appropriate Information Security training.
Personnel responsible for the use, operation, or administration of Information Systems shall receive the security training necessary to perform their duties safely and effectively.
This training shall be mandatory before assuming any new responsibilities, whether as part of an initial appointment or following a change in role or responsibilities.
THIRD PARTIES
Whenever the Organization provides services to other organizations or processes information on their behalf, those organizations shall be informed of this Information Security Policy.
Appropriate communication channels shall be established to facilitate coordination between the respective Information Security Committees, together with procedures for reporting and responding to Information Security incidents.
Whenever the Organization uses third-party services or shares information with third parties, those parties shall be informed of this Information Security Policy and of any Information Security standards applicable to the services provided or the information shared.
Third parties shall be bound by the obligations established in those standards and may develop their own operational procedures provided that they satisfy the required security controls.
Specific procedures shall be established for reporting and resolving Information Security incidents involving third parties.
The Organization shall ensure that third-party personnel receive Information Security awareness at least equivalent to that required for its own personnel.
Where a third party cannot fully comply with any requirement of this Policy, the Information Security Manager shall prepare a formal report describing:
The associated risks.
The proposed risk treatment measures.
This report shall be approved by the relevant Information Owner(s) and Service Owner(s) before any exception is accepted or the related activity proceeds.
APPROVAL AND ENTRY INTO FORCE
This Information Security Policy was approved by the Organization's Information Security Committee on 27 April 2026.
This Policy shall enter into force on that date and shall remain effective until it is replaced by a new version.