{"id":367,"date":"2026-06-09T06:04:54","date_gmt":"2026-06-09T06:04:54","guid":{"rendered":"https:\/\/rjvv-websit.es\/imts\/?page_id=367"},"modified":"2026-06-30T06:09:03","modified_gmt":"2026-06-30T06:09:03","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/www.imts.es\/en\/security-policy\/","title":{"rendered":"Security Policy"},"content":{"rendered":"<h2>INFORMATION SECURITY AND ENS COMPLIANCE POLICY<\/h2>\n<h3>1. OUR VISION OF SECURITY<\/h3>\n<p>At <b>Infraestructuras de Medios T\u00e9cnicos y Servicios (IMTS)<\/b>, information security is not merely a compliance requirement; it is the essence of our business. We provide GRC, Security Management (Virtual CSO), Intelligence (OSINT), Internal Audit, and Managed Technical Support services to public and private organizations that entrust us with their most critical and sensitive assets.<\/p>\n<p>We understand that our clients\u2019 trust can only be sustained if we demonstrate, through our own example, the same technical and regulatory rigor that we demand and design for them.<\/p>\n<p>For this reason, management has established and promoted an <b>Information Security Management System (ISMS)<\/b> that is integrated and audited, based strictly on the international standard <b>ISO\/IEC 27001<\/b> and the <b>National Security Scheme (ENS\u2014Royal Decree 311\/2022).<\/b><\/p>\n<h3>2. POLICY OBJECTIVE<\/h3>\n<p>The purpose of this Policy is to establish a framework for protecting the information assets of IMTS and our clients against all threats\u2014whether internal or external, deliberate or accidental\u2014in order to ensure:<\/p>\n<ul>\n<li><b>Confidentiality:<\/b> Information (especially audit findings, operational investigations, and client network architectures) is accessible only to expressly authorized personnel.<\/li>\n<li><b>Integrity:<\/b> Information is kept accurate and complete, and systems operate correctly without unauthorized tampering.<\/li>\n<li><b>Availability:<\/b> The information and services that support our clients\u2019 operations are available in accordance with the agreed-upon terms and Service Level Agreements (SLAs).<\/li>\n<li><b>Traceability and Authenticity:<\/b> Every action performed on internal or client systems is logged and can be audited, ensuring the principle of non-repudiation.<\/li>\n<\/ul>\n<h3>3. BASIC PRINCIPLES (ALIGNMENT WITH THE NATIONAL SECURITY FRAMEWORK)<\/h3>\n<p>Our security strategy is guided by the basic principles of the National Security Framework:<\/p>\n<ol>\n<li><b>Comprehensive Security:<\/b> Security at IMTS is a comprehensive process consisting of technical, human, material, and organizational elements. Physical security (access control, facilities) and logical security are managed as an indivisible whole.<\/li>\n<li><b>Risk-Based Management:<\/b> All preventive, detective, and reactive measures implemented within the organization are proportional to the results of a formal, ongoing, and documented Risk Analysis.<\/li>\n<li><b>Prevention, Detection, Response, and Recovery:<\/b><\/li>\n<\/ol>\n<ul>\n<li><i>We prevent<\/i> threats by applying the \u201cPrinciple of Least Privilege\u201d and hardening (<i>our systems<\/i>).<\/li>\n<li><i>We detect<\/i> anomalies through continuous monitoring and audits.<\/li>\n<li><i>We respond<\/i> decisively to incidents using predefined protocols.<\/li>\n<li><i>We restore<\/i> operations through our rigorous Business Continuity Plan (BCP).<\/li>\n<\/ul>\n<ol start=\"4\">\n<li><b>Defense in Depth:<\/b> We implement multiple overlapping layers of controls so that if a technical or procedural barrier is breached, additional controls are in place to limit or prevent the impact.<\/li>\n<li><b>Continuous Reassessment:<\/b> Our technological and organizational security posture is constantly reviewed, audited, and improved in response to evolving cyber threats and changes in the regulatory environment.<\/li>\n<\/ol>\n<h3>4. SECURITY ORGANIZATION AND SEGREGATION OF DUTIES<\/h3>\n<p>To ensure impartiality and sound decision-making, IMTS has established a defined security organizational structure, complying with the principle of segregation of duties required by the ENS:<\/p>\n<ul>\n<li><b>Information Security Committee (or Security Department):<\/b> Coordinates and supervises all activities related to this area.<\/li>\n<li>There is a clear separation between those responsible for technological operations (<b>System Manager<\/b>) and those who audit and ensure compliance and security (<b>Security Officer<\/b> and <b>Information Officer<\/b>), ensuring that analyses are not biased by conflicts of interest.<\/li>\n<\/ul>\n<h3>5. HUMAN DIMENSION: TRAINING AND AWARENESS<\/h3>\n<p>At IMTS, we believe that the human factor is our first and best line of defense. All staff\u2014including auditors, intelligence analysts, support technicians, and administrative personnel\u2014are bound by strict confidentiality agreements and receive ongoing training in cyber surveillance, cybersecurity regulations, the handling of sensitive information, and social engineering.<\/p>\n<h3>6. LEGAL AND REGULATORY COMPLIANCE<\/h3>\n<p>IMTS is committed to strict compliance with the legislation applicable to its information systems, paying special attention to:<\/p>\n<ul>\n<li>National and European regulations on personal data protection: <b>GDPR and LOPDGDD<\/b>.<\/li>\n<li>Law <b>5\/2014 on Private Security<\/b>, which is fundamental to our External Security Management services.<\/li>\n<li>Security regulations relevant to our market of operations, including current resolutions and directives (<b>NIS2<\/b>, <b>DORA<\/b>).<\/li>\n<li>Intellectual property, copyright, and the protection of technical data and trade secrets\u2014both our own and those of our clients, suppliers, and technology partners.<\/li>\n<\/ul>\n<h3>7. MANAGEMENT COMMITMENT AND LEADERSHIP<\/h3>\n<p>IMTS management formally reviews and approves this Security Policy, assuming responsibility for providing the organization with the technical, financial, and human resources necessary to maintain a robust, effective Information Security Management System that is subject to continuous improvement.<\/p>\n<p>Furthermore, this policy is mandatory for all IMTS employees, contractors, and any third party providing services to or on behalf of Infraestructuras de Medios T\u00e9cnicos y Servicios. Any violation of this policy will be subject to an investigation that may result in disciplinary or legal sanctions.<\/p>\n<p>This policy is permanently accessible to the general public through this website, demonstrating IMTS\u2019s transparency and firm corporate commitment to its customers and society.<\/p>\n<p><i>Approved by IMTS Senior Management.<\/i><br \/>\n<i>Last revised: May 2026<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>INFORMATION SECURITY AND ENS COMPLIANCE POLICY 1. OUR VISION OF SECURITY At Infraestructuras de Medios T\u00e9cnicos y Servicios (IMTS), information security is not merely a compliance requirement; it is the essence of our business. We provide GRC, Security Management (Virtual CSO), Intelligence (OSINT), Internal Audit, and Managed Technical Support services to public and private organizations [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-367","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Policy - IMTS<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.imts.es\/en\/security-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Policy - IMTS\" \/>\n<meta property=\"og:description\" content=\"INFORMATION SECURITY AND ENS COMPLIANCE POLICY 1. OUR VISION OF SECURITY At Infraestructuras de Medios T\u00e9cnicos y Servicios (IMTS), information security is not merely a compliance requirement; it is the essence of our business. We provide GRC, Security Management (Virtual CSO), Intelligence (OSINT), Internal Audit, and Managed Technical Support services to public and private organizations [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.imts.es\/en\/security-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"IMTS\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-30T06:09:03+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.imts.es\\\/en\\\/security-policy\\\/\",\"url\":\"https:\\\/\\\/www.imts.es\\\/en\\\/security-policy\\\/\",\"name\":\"Security Policy - IMTS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.imts.es\\\/en\\\/#website\"},\"datePublished\":\"2026-06-09T06:04:54+00:00\",\"dateModified\":\"2026-06-30T06:09:03+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.imts.es\\\/en\\\/security-policy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.imts.es\\\/en\\\/security-policy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.imts.es\\\/en\\\/security-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.imts.es\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.imts.es\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.imts.es\\\/en\\\/\",\"name\":\"IMTS\",\"description\":\"Infraestructuras de Medios T\u00e9cnicos\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.imts.es\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Policy - IMTS","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.imts.es\/en\/security-policy\/","og_locale":"en_US","og_type":"article","og_title":"Security Policy - IMTS","og_description":"INFORMATION SECURITY AND ENS COMPLIANCE POLICY 1. OUR VISION OF SECURITY At Infraestructuras de Medios T\u00e9cnicos y Servicios (IMTS), information security is not merely a compliance requirement; it is the essence of our business. We provide GRC, Security Management (Virtual CSO), Intelligence (OSINT), Internal Audit, and Managed Technical Support services to public and private organizations [&hellip;]","og_url":"https:\/\/www.imts.es\/en\/security-policy\/","og_site_name":"IMTS","article_modified_time":"2026-06-30T06:09:03+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.imts.es\/en\/security-policy\/","url":"https:\/\/www.imts.es\/en\/security-policy\/","name":"Security Policy - IMTS","isPartOf":{"@id":"https:\/\/www.imts.es\/en\/#website"},"datePublished":"2026-06-09T06:04:54+00:00","dateModified":"2026-06-30T06:09:03+00:00","breadcrumb":{"@id":"https:\/\/www.imts.es\/en\/security-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.imts.es\/en\/security-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.imts.es\/en\/security-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.imts.es\/en\/"},{"@type":"ListItem","position":2,"name":"Security Policy"}]},{"@type":"WebSite","@id":"https:\/\/www.imts.es\/en\/#website","url":"https:\/\/www.imts.es\/en\/","name":"IMTS","description":"Infraestructuras de Medios T\u00e9cnicos","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.imts.es\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/pages\/367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/comments?post=367"}],"version-history":[{"count":14,"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/pages\/367\/revisions"}],"predecessor-version":[{"id":624,"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/pages\/367\/revisions\/624"}],"wp:attachment":[{"href":"https:\/\/www.imts.es\/en\/wp-json\/wp\/v2\/media?parent=367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}