
Security Principles
COM3
Security Principles
Security Principles
COM3 Systems will protect information throughout all phases of its life cycle —creation/reception, use and processing, communication and transport, storage and authorised dissemination, and deletion or destruction— ensuring its confidentiality, integrity, availability, authenticity, and traceability. This protection shall apply to physical and logical media, both owned and third-party (including cloud), through organisational, technical, and physical controls proportionate to its classification (e.g., access control, encryption, logging and monitoring, and certified destruction where applicable).
Accordingly, the following minimum principles are established:
a) Security as an integral process (art. 6)
Security is conceived as an integral and continuous process encompassing the human, material, technical, legal, and organisational elements of the information system. All information processing shall be governed by this principle, avoiding isolated or ad hoc actions.
Management and those responsible (CISO, IO, DO, SO) shall ensure effective coordination, the definition of responsibilities, and the allocation of necessary resources. Awareness and training shall be promoted for all persons involved, so that lack of knowledge, organisation, coordination, or instructions does not become a source of risk.
Security shall be implemented under a continuous improvement approach (PDCA), with preventive, detective, and corrective controls that are documented and measurable.
b) Risk-based security management (art. 7)
Risk analysis and management is an essential, continuous, and up-to-date process that underpins security. Its objective is to maintain a controlled environment, reducing risks to acceptable levels defined by Management (risk appetite).
Risk reduction shall be achieved through the proportionate and balanced application of security measures (organisational, operational, and technical) in accordance with the classification of information, the services provided, and exposure to threats.
Identified risks shall be recorded and addressed in accordance with a risk analysis methodology, applying treatment options to mitigate, transfer, avoid, or accept, with defined responsible parties, deadlines, and evidence.
c) Prevention, detection, response, and preservation (art. 8)
System security shall be implemented as a continuous cycle of prevention, detection, and response, in order to minimise vulnerabilities, deter and reduce the attack surface, and ensure that threats do not materialise or, if they do, limit their impact on information and services.
Prevention measures shall eliminate or reduce the likelihood of materialisation (hardening, patching, access control, segmentation, encryption, principles of least privilege and Zero Trust).
Detection measures shall enable the discovery and qualification of cyber incidents in a timely manner (event logging and correlation, defined alerts and thresholds).
Response measures shall restore affected information and services in accordance with the maximum time to restore service and the maximum acceptable data loss, including containment, eradication, recovery, and lessons learned.
Without prejudice to the ENS principles, the system shall guarantee the preservation and authenticity of electronic data and the availability of services throughout the entire information life cycle.
d) Existence of defence layers (art. 9)
The system shall have a multi-layer protection strategy. If one layer is compromised, the remaining layers shall allow for an adequate reaction and containment of the incident, reducing the probability of total compromise and minimising the impact on information and services.
These defence layers shall include coordinated organisational, physical, and logical/technological measures.
e) Continuous monitoring and periodic reassessment (art. 10)
Continuous system monitoring shall enable the detection of anomalous activities or behaviours and a timely response to contain them.
Ongoing security assessment of assets shall measure their evolution, identifying vulnerabilities and configuration deviations.
Security measures shall be periodically reviewed and updated, adjusting their effectiveness to the evolution of risks, threats, and protection technologies, and the security approach may be reconsidered when necessary.
f) Segregation of responsibilities (art. 11)
A clear segregation of responsibilities shall be maintained within the information system:
Information Owner (IO): Defines the classification and security requirements of the information processed.
Service Owner (SO): Establishes the security requirements of the service and ensures they are met in operations.
System Owner (DO): Responsible for the implementation and technical operation that supports the services (infrastructure, applications, networks).
Chief Information Security Officer (CISO): Guides and decides on security matters to meet defined requirements, coordinates risk management and incident response.
Where personal data processing occurs, the roles of Data Controller and, where applicable, Data Processor shall also be identified, in accordance with GDPR/LOPDGDD, ensuring consistency between these functions and the aforementioned responsibilities.
Regulatory Framework
COM3 Systems is subject to the following regulations in the provision of services to its clients:
Royal Decree 311/2022, of 3 May, regulating the National Security Framework (ENS).
Resolution of 7 October 2016, of the Secretary of State for Public Administrations, approving the Technical Security Instruction on Security Status Reporting.
Resolution of 13 October 2016, of the Secretary of State for Public Administrations, approving the Technical Security Instruction in accordance with the National Security Framework.
Resolution of 27 March 2018, of the Secretary of State for Public Function, approving the Technical Security Instruction on Information System Security Auditing.
Resolution of 13 April 2018, of the Secretary of State for Public Function, approving the Technical Security Instruction on Security Incident Notification.
Organic Law 3/2018, of 5 December, on Personal Data Protection and Guarantee of Digital Rights.
REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
CCN-STIC Security Guides.
Occupational Risk Prevention Law 31/1995 of 8 November and Royal Decree 39/1997.
Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).
Royal Decree-Law 13/2012 of 30 March, Cookie Law.
Royal Legislative Decree 1/1996, of 12 April, approving the revised text of the Intellectual Property Law.
Security Roles and Functions
The different roles determined, together with their respective functions and responsibilities, are:
CISO — Chief Information Security Officer
Design, implement, and maintain the ISMS in accordance with the ENS.
Maintain risk analysis and treatment, training/awareness plan.
Establish standards/procedures (access, changes, incidents, backups, logs, continuity).
Coordinate security incidents.
Measure and report indicators.
SO — Service Owner
Be the functional owner of the service.
Define, integrate, and maintain security requirements in contracts with suppliers.
Align operations with business needs and with the ENS.
DO — System Owner
Be the technical owner of the platform/system: architecture, hardening, patching, backups, logs.
Manage configuration and inventory, vulnerabilities, monitoring, and capacity.
Execute day-to-day operations.
IO — Information Owner
Establish access criteria and authorise access to their data.
Define information retention and destruction.
Participate in impact assessments and incident management.
Awareness and Training
All COM3 Systems employees are obliged to know and comply with this Information Security Policy. All shall attend an ICT security awareness session at least once a year.
System Security Documentation
COM3 Systems has a document management system through which documents are edited, reviewed, and approved.
Risk Management
All systems subject to this Policy shall be included in a risk analysis that evaluates threats, vulnerabilities, and impacts. This analysis shall be repeated:
Periodically, at least annually.
When the information processed changes.
When the services provided or their criticality changes.
Following a serious security incident.
In the event of serious vulnerabilities or new relevant threats.
Organisational, Operational, and Protection Controls (ENS)
Principles and requirements aligned with the ENS are established, applicable to all services, assets, and persons involved, including: organisation, risk analysis, personnel management, access control, facility protection, system integrity and updating, information protection, activity logging, incident management, business continuity, and continuous improvement.
Personal Data
COM3 Systems processes personal data and shall guarantee its protection in accordance with the GDPR/LOPDGDD and the ENS.
Third Parties (Suppliers and Clients)
When services are provided or information from other organisations is processed, such parties shall know and accept this Security Policy and the applicable associated regulations.
Prevention, Detection, Response, and Recovery
COM3 Systems shall be prepared to prevent, detect, respond to, and recover from security incidents, with defined responsibilities and coordination by the Security Committee.
Information Security Policy Review
The Information
on Security Committee shall draft the Information Security Policy (ISP) in accordance with art. 12 of the ENS and control ORG.1 of Annex II. It shall carry out its review at least annually.
The ISP shall be approved by Management (CEO of COM3 Systems) and communicated to all affected parties.
.png)