Skip to main content

Security Policy

1. Introduction

Xeridia, S.L. relies on information systems to achieve its business objectives: custom software development, application maintenance and the provision of technical support services to its clients. These systems must be managed diligently, adopting measures appropriate to the risk in order to protect them against accidental or deliberate damage that may affect the confidentiality, integrity, availability, authenticity or traceability of the information processed and the availability of the services provided.

The ultimate goal of information security is to ensure that Xeridia can fulfil its mission and deliver its services continuously and with quality, acting preventively, monitoring day-to-day activity and reacting swiftly to incidents.

Security is conceived as an integral part of the entire software life cycle (ISO/IEC 12207), from conception to withdrawal from service, including development, procurement and operation decisions. Security requirements and funding needs are identified and incorporated into project planning, proposals and tender specifications.

This Policy is the highest-level document within Xeridia's body of security regulations and addresses measure org.1 Security policy of Annex II of Royal Decree 311/2022, taking Guide CCN-STIC-805 as a reference. It has been drafted in accordance with the principles of technological neutrality, adaptability to technical progress and accessibility required by the ENS (Spanish National Security Framework).

2. Scope and purpose

The purpose of this Policy is to establish the general guidelines governing the management and protection of Xeridia's information and services, as well as to define the organisation, the responsibilities and the reference framework upon which the rest of the body of security regulations is built.

Its scope of application covers:

  • All Xeridia information systems included within the declared scope of the ENS: those supporting the services subject to ENS compliance (by contractual requirement of clients and by voluntary adoption) and the corporate services that support them.
  • All persons who form part of the organisation (own staff, interns and collaborators), regardless of their position or contractual relationship.
  • Xeridia's service providers and ICT solution suppliers, under the terms of section 11.

Xeridia, as a private-sector entity, adopts the National Security Framework (ENS, Royal Decree 311/2022) for two reasons: (i) to meet the contractual requirement of clients who demand ENS compliance and (ii) the decision of Management to take it as a reference framework to strengthen the security of its systems and services. The detailed scope (systems, services and sites) is maintained in the ENS Statement of Applicability, consistent with the scope of the ISO/IEC 27001 certification.

3. Mission and security objectives

Xeridia's mission: to provide software engineering solutions and services (development, maintenance and technical support) that add value to its clients, guaranteeing the quality and security of the information processed.

The security objectives that Xeridia intends to guarantee through this Policy are:

  • To guarantee the confidentiality, integrity, availability, authenticity and traceability of information and the continuity of service delivery.
  • To implement risk-based security measures that are proportionate and justified.
  • To train and raise the awareness of all Xeridia personnel, reinforcing the duty of confidentiality regarding information learned in the performance of their duties, and to apply the principle of least privilege while guaranteeing the traceability of access.
  • To deploy and control the physical security of assets in secure areas, according to the risks involved.
  • To establish security in the management of communications, protecting information in transit.
  • To control the acquisition, development and maintenance of systems across all life-cycle phases, guaranteeing security by default and by design.
  • To manage security incidents so that they are correctly detected, contained, mitigated and resolved, adopting measures to prevent their recurrence.
  • To protect personal information in accordance with data protection legislation, having regard to the risks of the processing.
  • To continuously monitor the security management system, improving and correcting any inefficiencies detected.

4. Guiding principles of the Policy

In accordance with the basic principles of the ENS (articles 5 to 12 of Royal Decree 311/2022), Xeridia assumes the following principles:

  • Strategic scope (art. 5): security has the commitment and support of all levels of the entity and is coordinated and integrated coherently with the rest of the strategic initiatives and with the Integrated Management System.
  • Comprehensive security (art. 6): security is a process that integrates technical, human, material and organisational elements, present from the initial design of the systems and in day-to-day operations.
  • Risk-based management (art. 7): measures are established and maintained according to the risks, minimising them to acceptable levels, also considering the risks of personal data processing.
  • Prevention, detection, response and preservation (art. 8): preventive actions, reduction of vulnerabilities, agile response to restore information or services, and secure preservation of information.
  • Existence of lines of defence (art. 9): the security strategy is designed and implemented in layers.
  • Continuous monitoring and periodic reassessment (art. 10): detection of and response to anomalous behaviour, continuous evaluation of the security posture and a continuous improvement process.
  • Segregation of responsibilities (art. 11): the roles of the Security Officer and the System Officer are kept separate.
  • Security by default and by design (art. 12): providing the minimum functionality necessary to deliver the service for which the systems were designed.

5. Regulatory framework

The main regulations affecting this Policy are listed below. Their detail and updating are managed as a living record of the Integrated Management System (IMS):

  • Royal Decree 311/2022, of 3 May, regulating the National Security Framework (ENS), and its Technical Security Instructions (compliance, audit, incident notification and security status report).
  • Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
  • Cybersecurity legislation applicable given Xeridia's status (Directive (EU) 2022/2555 NIS2 and its transposing legislation), where applicable.
  • Regulation (EU) 2024/1689 on Artificial Intelligence, where AI systems are acquired, developed or deployed.
  • The framework of Xeridia's Integrated Management System: ISO 9001, ISO 14001, ISO/IEC 20000-1, ISO/IEC 27001 and ISO/IEC 12207-33000, with which this Policy is consistent.

This Policy is consistent with the framework of Xeridia's Integrated Management System: ISO 9001, ISO 14001, ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC/IEEE 12207 and ISO/IEC 33000.

6. Security organisation

6.1. Information Security Committee: functions and responsibilities

The Information Security Committee shall have the following functions:

  • To approve and promote the dissemination of the Security Regulations that develop this Policy.
  • To establish the baseline valuation of the types of information and services, and to harmonise risk analyses.
  • To coordinate resources and promote horizontal investments in security.
  • To resolve conflicts between officers (section 6.4).
  • To oversee ENS compliance, audit results and the IMS security indicator dashboard.
  • To propose the annual review of this Policy to Senior Management.

6.2 Roles: functions and responsibilities

In accordance with art. 11 of the ENS and with CCN-STIC-801, the Security and System functions are kept separate.

Role Main mission
Information Owner Determines the security requirements of the information processed and its level across the security dimensions.
Service Owner Determines the security requirements of the services provided and their level.
Security Officer Determines the measures needed to meet the requirements, oversees their implementation and incident management, and maintains ENS compliance. A function kept separate from the System Officer. Acts as Point of Contact (POC).
System Officer Manages the operation of the information system and applies the security measures; may agree to suspend the handling of information in the event of serious deficiencies.
ENS Maintenance and Monitoring Officer Ensures continuous ENS compliance: monitoring of the adaptation and improvement plan and its degree of implementation, maintenance of the compliance calendar (biennial re-certification at MEDIUM category), preparation of the security status report and follow-up of findings and corrective actions through to closure. At Xeridia this falls to the Integrated Management System Officer, as delegate of the Security Officer for compliance management (section 6.3); by virtue of that delegation it includes the Point of Contact (POC) function. Signing the Statement of Applicability corresponds in all cases to the Security Officer.

6.3 Appointment procedures

  • The members of the Information Security Committee shall be appointed by Management.
  • The Information Owner and the Service Owner shall be appointed by Management, at the proposal of the Committee.
  • The Security Officer shall be appointed by Management, at the proposal of the Committee.
  • The System Officer shall be appointed by Management, at the proposal of the Committee.

6.4 Conflict resolution

In the event of a conflict between officers, the Information Security Committee shall settle the discrepancies. Decisions affecting principles or designated responsibilities shall be escalated to Senior Management.

7. Processing of personal data within the entity

Xeridia processes personal data in accordance with its Record of Processing Activities. The associated risks shall be assessed, and an action plan proposed to correct those exceeding the authorised threshold. The risk analysis shall be periodically reassessed with the advice and supervision of the Data Protection Officer, and a Data Protection Impact Assessment (DPIA) shall be carried out whenever high-risk processing is identified. The data protection risk treatment plan is coordinated with that of the ENS, as are incident and breach response and the control of service providers. Xeridia's DPO is external: Construyendo Futuro Informático, S.L.

8. Risk management

All systems subject to this Policy shall undergo a risk analysis assessing the threats and risks to which they are exposed. This analysis shall be reviewed and approved annually and shall also be repeated:

  • when there are changes in the information handled;
  • when there are changes in the services provided;
  • when a serious security incident occurs;
  • when serious vulnerabilities are reported;
  • when there are modifications to the risk analysis or to the data protection impact assessments.

The Security Committee shall establish a baseline valuation for the types of information and services and shall mobilise resources to meet security needs, promoting horizontal investments. Data protection risks shall be taken into account, with the opinion of the DPO, coordinating the risk treatment plans. Risks above the acceptable threshold shall be managed, with acceptance of the residual risk being the responsibility of Management.

9. Development of the Policy and documentation structure

This Policy is integrated with and consistent with the other policies and with Xeridia's Integrated Management System (quality, environment, IT services, information security and software life cycle). It is developed through security regulations addressing specific aspects, made available to all members who need to know them, in particular those who use, operate or administer the systems.

Security documentation is structured in levels (measure [org.1.5]):

  • Information Security Policy (this document): general framework approved by Senior Management.
  • Security regulations: mandatory rules that standardise the use of specific aspects of the system and users' responsibilities.
  • Security operating procedures: step-by-step instructions for specific tasks.
  • Guides and instructions: training and support material.
  • Records and evidence: risk analyses, statement of applicability, audit reports, incident logs, etc.

All this documentation is maintained in the Integrated Management System with version and access control according to the need-to-know principle.

10. Personnel obligations: awareness and training

All Xeridia personnel are obliged to know and comply with this Policy and the Regulations that develop it.

  • All personnel shall receive at least one awareness session per year; a continuous awareness programme shall be maintained, with specific attention to new joiners.
  • The security competence of persons with responsibility for the use, operation or administration of systems is ensured through the training and experience requirements defined for each position.
  • All members accept this Policy in the aspects that affect them and take part in periodic awareness activities.
  • All personnel have a duty to immediately report to the Security Officer, through the established channels, any security event, weakness or incident of which they become aware.

11. Third parties, service providers and solution suppliers

  • Where Xeridia provides services to or handles information belonging to other entities, they shall be made party to this Policy and to the applicable Regulations, establishing reporting and coordination channels between the respective Security Committees.
  • Where Xeridia uses third-party services or transfers information (including cloud services), those third parties shall be made party to the Policy and to the Regulations concerning such services.
  • Third parties may develop their own procedures to satisfy these Regulations, in such a way that Xeridia can supervise them, request evidence or carry out second- or third-party audits.

12. Security incident management

Xeridia shall have a procedure for the agile management of security events and incidents that pose a threat to information and services, aligned with Guide CCN-STIC-817, covering the phases of preparation; detection, analysis and notification; containment, mitigation and resolution; and post-incident action (lessons learned).

  • Incidents shall be classified according to a taxonomy and assigned a danger level (five-value scale: Critical, Very High, High, Medium, Low) and a level of impact on the organisation, in accordance with the criteria of CCN-STIC-817.
  • Where applicable within the scope of the ENS, incidents shall be notified to the CCN-CERT through the LUCÍA tool (or equivalent channel), respecting the deadlines and the follow-up appropriate to their danger level.
  • The procedure is integrated and coordinated with the response to personal data breaches (GDPR / LOPDGDD, via the DPO) and with any other applicable notification obligations, reporting without undue delay to the supervisory authorities and, where appropriate, to the State Security Forces and Corps or to the courts.
  • Reporting and coordination channels shall be established with clients and suppliers through the POC.

13. Compliance verification and ENS conformity

In accordance with Guide CCN-STIC-808 and with the Technical Security Instructions on conformity and audit:

  • Xeridia shall determine the category of its systems (BASIC / MEDIUM / HIGH) based on the valuation of information and services across the security dimensions. Starting category: MEDIUM (Intermediate Level), confirmed in the Statement of Applicability.
  • For the MEDIUM category, conformity is obtained through a certification audit on a biennial basis (plus extraordinary audits in the event of substantial changes), with the corresponding Declaration or Certificate of Conformity being issued and published in accordance with the Technical Security Instruction on conformity.
  • A continuous verification process shall be maintained through the security indicator dashboard, the IMS internal audits and the management review.

14. Policy approval, review and effectiveness

  • Modifications entailing adaptations due to inefficiencies shall be made by the Information Security Committee, which shall review this Policy at least annually.
  • Where changes entail a substantial modification or affect principles or designated responsibilities, the Committee shall propose the changes, which must be approved by the person or body with the appropriate powers.
  • Replacement of the Policy shall be requested by the Committee and ratified by that body, with interested parties being informed through the same channels used for its dissemination.