Madrid · Domestic and International Service info@imts.es
ES / EN / PT

Security Policy of
Information and ENS

INFORMATION SECURITY AND ENS COMPLIANCE POLICY

1. OUR VISION OF SECURITY

At Infraestructuras de Medios Técnicos y Servicios (IMTS), information security is not merely a compliance requirement; it is the essence of our business. We provide GRC, Security Management (Virtual CSO), Intelligence (OSINT), Internal Audit, and Managed Technical Support services to public and private organizations that entrust us with their most critical and sensitive assets.

We understand that our clients’ trust can only be sustained if we demonstrate, through our own example, the same technical and regulatory rigor that we demand and design for them.

For this reason, management has established and promoted an Information Security Management System (ISMS) that is integrated and audited, based strictly on the international standard ISO/IEC 27001 and the National Security Scheme (ENS—Royal Decree 311/2022).

2. POLICY OBJECTIVE

The purpose of this Policy is to establish a framework for protecting the information assets of IMTS and our clients against all threats—whether internal or external, deliberate or accidental—in order to ensure:

  • Confidentiality: Information (especially audit findings, operational investigations, and client network architectures) is accessible only to expressly authorized personnel.
  • Integrity: Information is kept accurate and complete, and systems operate correctly without unauthorized tampering.
  • Availability: The information and services that support our clients’ operations are available in accordance with the agreed-upon terms and Service Level Agreements (SLAs).
  • Traceability and Authenticity: Every action performed on internal or client systems is logged and can be audited, ensuring the principle of non-repudiation.

3. BASIC PRINCIPLES (ALIGNMENT WITH THE NATIONAL SECURITY FRAMEWORK)

Our security strategy is guided by the basic principles of the National Security Framework:

  1. Comprehensive Security: Security at IMTS is a comprehensive process consisting of technical, human, material, and organizational elements. Physical security (access control, facilities) and logical security are managed as an indivisible whole.
  2. Risk-Based Management: All preventive, detective, and reactive measures implemented within the organization are proportional to the results of a formal, ongoing, and documented Risk Analysis.
  3. Prevention, Detection, Response, and Recovery:
  • We prevent threats by applying the “Principle of Least Privilege” and hardening (our systems).
  • We detect anomalies through continuous monitoring and audits.
  • We respond decisively to incidents using predefined protocols.
  • We restore operations through our rigorous Business Continuity Plan (BCP).
  1. Defense in Depth: We implement multiple overlapping layers of controls so that if a technical or procedural barrier is breached, additional controls are in place to limit or prevent the impact.
  2. Continuous Reassessment: Our technological and organizational security posture is constantly reviewed, audited, and improved in response to evolving cyber threats and changes in the regulatory environment.

4. SECURITY ORGANIZATION AND SEGREGATION OF DUTIES

To ensure impartiality and sound decision-making, IMTS has established a defined security organizational structure, complying with the principle of segregation of duties required by the ENS:

  • Information Security Committee (or Security Department): Coordinates and supervises all activities related to this area.
  • There is a clear separation between those responsible for technological operations (System Manager) and those who audit and ensure compliance and security (Security Officer and Information Officer), ensuring that analyses are not biased by conflicts of interest.

5. HUMAN DIMENSION: TRAINING AND AWARENESS

At IMTS, we believe that the human factor is our first and best line of defense. All staff—including auditors, intelligence analysts, support technicians, and administrative personnel—are bound by strict confidentiality agreements and receive ongoing training in cyber surveillance, cybersecurity regulations, the handling of sensitive information, and social engineering.

6. LEGAL AND REGULATORY COMPLIANCE

IMTS is committed to strict compliance with the legislation applicable to its information systems, paying special attention to:

  • National and European regulations on personal data protection: GDPR and LOPDGDD.
  • Law 5/2014 on Private Security, which is fundamental to our External Security Management services.
  • Security regulations relevant to our market of operations, including current resolutions and directives (NIS2, DORA).
  • Intellectual property, copyright, and the protection of technical data and trade secrets—both our own and those of our clients, suppliers, and technology partners.

7. MANAGEMENT COMMITMENT AND LEADERSHIP

IMTS management formally reviews and approves this Security Policy, assuming responsibility for providing the organization with the technical, financial, and human resources necessary to maintain a robust, effective Information Security Management System that is subject to continuous improvement.

Furthermore, this policy is mandatory for all IMTS employees, contractors, and any third party providing services to or on behalf of Infraestructuras de Medios Técnicos y Servicios. Any violation of this policy will be subject to an investigation that may result in disciplinary or legal sanctions.

This policy is permanently accessible to the general public through this website, demonstrating IMTS’s transparency and firm corporate commitment to its customers and society.

Approved by IMTS Senior Management.
Last revised: May 2026