1. Approval and entry into force

This Information Security Policy is effective from the date of signature and until it is replaced by a new Policy.

2. Mission of the organization

Xeria Digital, S.L, (technology company dedicated to the development of software for the management of exhibitors and visitor access at professional events) to achieve its objectives assumes its commitment to information security, committing to the proper management of it, in order to offer all its interest groups the greatest guarantees regarding the security of the information used. These systems must be administered diligently, taking appropriate measures to protect them against accidental or deliberate damage that may affect the availability, integrity or confidentiality of the processed information or the services provided.

The objective of information security is to guarantee the quality of information and the continued provision of services, acting preventively, monitoring daily activity and reacting promptly to incidents.

ICT systems must be protected against rapidly evolving threats with the potential to affect the confidentiality, integrity, availability, intended use, and value of information and services. Defending against these threats requires a strategy that adapts to changes in the environmental conditions to guarantee the continuous provision of services. This implies that departments must apply the minimum security measures required by the National Security Scheme, as well as continuously monitor service delivery levels, follow and analyze reported vulnerabilities, and prepare an effective response to incidents to ensure the continuity of the services provided.

The different departments must ensure that ICT security is an integral part of every stage of the system life cycle, from its conception to its decommissioning, passing through the development or acquisition decisions and the operating activities. Security requirements and funding needs must be identified, both for the products they develop and their associated services, as well as regarding third-party acquired software. Departments must be prepared to prevent, detect, respond, and recover from incidents, in accordance with Article 8 of the ENS (Article 8. Prevention, detection, response, and conservation).

3. Scope

This policy applies to all ICT systems, infrastructures, data, communications, and processes of the entity related to the organization and management of professional events.

It will be mandatory for all members of the organization, as well as for third parties (collaborators, contractors, or suppliers) involved in such services or projects.

Its application will be enforceable in services and projects intended for entities in the public sector and private entities when so established by contracts, agreements, or security best practices adopted by the entity.

4. Objectives

For all the above reasons, Management establishes the following information security objectives:

  • Provide a framework to increase the resilience capacity to provide an effective response.
  • Ensure the quick and efficient recovery of services, in the face of any physical disaster or contingency that may occur and jeopardize the continuity of operations.
  • Prevent information security incidents as far as technically and economically feasible, as well as mitigate the information security risks generated by our activities.
  • Guarantee the confidentiality, integrity, availability, authenticity, and traceability of information.

5. Regulatory framework

One of the objectives must be to comply with applicable legal requirements and with any other requirements to which we subscribe in addition to the commitments acquired with clients, as well as continuous updating of the same. For this, the legal and regulatory framework in which we develop our activities is:

  • REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016 concerning the protection of individuals with regard to the processing of personal data and on the free movement of such data.
  • Organic Law 3/2018, of December 5, on the Protection of Personal Data and the guarantee of digital rights.
  • Royal Legislative Decree 1/1996, of April 12, Intellectual Property Law.
  • Law 2/2019, of March 1, which modifies the consolidated text of the Intellectual Property Law, approved by Royal Legislative Decree 1/1996, of April 12, and by which are incorporated into the Spanish legal system Directive 2014/26/UE of the European Parliament and of the Council, of February 26, 2014, and Directive (EU) 2017/1564 of the European Parliament and of the Council, of September 13, 2017.
  • Royal Decree 311/2022, of May 3, which regulates the National Security Scheme.
  • Law 34/2002 of July 11, on Services of the Society of Information and Electronic Commerce (LSSI).
  • Law 40/2015, of October 1, on the Legal Regime of the Public Sector.
  • Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations.
  • Resolution of October 7, 2016, of the Secretary of State for Public Administrations, which approves the Technical Security Instruction of the State of Security Report. or Resolution of October 13, 2016, of the Secretary of State for Public Administrations, which approves the Technical Security Instruction in accordance with the National Security Scheme.
  • Resolution of October 13, 2016, of the Secretary of State for Public Administrations, which approves the Technical Security Instruction in accordance with the National Security Scheme.
  • Resolution of March 27, 2018, of the Secretary of State for Public Function, which approves the Technical Security Instruction for Auditing Information Systems Security. or Resolution of April 13, 2018, of the Secretary of State for Public Function, which approves the Technical Security Instruction for Notification of Security Incidents.
  • Resolution of April 13, 2018, of the Secretary of State for Public Function, which approves the Technical Security Instruction for Notification of Security Incidents.
  • REGULATION (EU) No 910/2014 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of July 23, 2014 concerning electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC

6. Development

To achieve these objectives, it is necessary to:

  • Continuously improve our information security system.
  • Identify potential threats, as well as the impact on business operations that such threats, if materialized, may cause.
  • Preserve the interests of its main stakeholders (customers, shareholders, employees, and suppliers), reputation, brand, and value-creation activities.
  • Work together with our suppliers and subcontractors to improve IT service delivery, service continuity, and information security, resulting in greater efficiency in our activity.
  • Assess and ensure the technical competence of the personnel, as well as ensure their adequate motivation for their participation in the continuous improvement of our processes, providing the necessary training and internal communication so that they develop good practices defined in the system.
  • Ensure the proper state of the facilities and the adequate equipment, ensuring that they correspond to the activity, objectives, and goals of the company.
  • Guarantee continuous analysis of all relevant processes, establishing the relevant improvements in each case, based on the results obtained and the objectives set.
  • Structure our management system so that it is easy to understand. Our management system has the following structure:
Pyramid

The management of our system is entrusted to the Responsible for Computer Systems and the system will be available in our information system in a repository, which can be accessed according to the access profiles granted according to our current access management procedure.

7. Security organization

The essential responsibility lies with the General Management of the organization, as it is responsible for organizing the functions and responsibilities and providing the adequate resources to achieve the ENS objectives. Managers are also responsible for setting a good example by following the established security rules.

These principles are assumed by the Management, which provides the necessary means and equips its employees with sufficient resources for their compliance, being embodied and made publicly known through these Security Policies.

The defined security roles or functions are:

Table

This definition of duties and responsibilities is completed in the job profiles and in the system documents Register of responsible parties, roles, and responsibilities.

8. Security Committee

The procedure for their designation and renewal will be ratification in the security committee.

The committee for the management and coordination of security is the body with the greatest responsibility within the information security management system, so that all the most important decisions related to security are agreed upon by this committee.

The members of the information security committee are:

  • Information Responsible
  • Services Responsible
  • Security Responsible
  • System Responsible
  • Company Management (Partners-Administrators)

These members are appointed by the committee, the only body that can appoint, renew, and dismiss them.

The security committee is an autonomous, executive body with decision-making autonomy that does not have to subordinate its activity to any other element of our company.

The organization of Information Security is developed in the complementary document, among its functions is highlighted the ENS vigilance and among its main tasks stands out the conflict resolution, since differences in criteria that may lead to a conflict will be addressed within the Security committee and in any case, the criteria of the General Management will prevail.

The organization of Information Security is developed in the complementary document to this Security Organization Policy.

This policy is complemented by the rest of the policies, procedures, and documents in force to develop our management system.

9. Risk Management

All systems subject to this Policy must carry out a risk analysis, evaluating the threats and risks to which they are exposed. This analysis is reviewed regularly:

  • at least once a year;
  • when the information handled changes;
  • when the services provided change;
  • when a serious security incident occurs;
  • when serious vulnerabilities are reported.

For the harmonization of risk analyses, the ICT Security Committee will establish a reference rating for the different types of information handled and the different services provided. The ICT Security Committee will promote the availability of resources to meet the security needs of the different systems, promoting horizontal investments.

For the conduct of the risk analysis, the risk analysis methodology developed in the Risk Analysis procedure will be taken into account.

10. Personnel Management

All members of Xeria Digital, S.L have the obligation to know and comply with this Policy of Information Security and the Security Regulations, being the responsibility of the TIC Security Committee to provide the necessary means for the information to reach those affected.

All members of Xeria Digital, S.L will attend a session to raise awareness on ICT security at least once a year. A continuous awareness program will be established to serve all members of Xeria Digital, S.L, particularly those newly incorporated.

Those responsible for the use, operation, or administration of ICT systems will receive training for the safe handling of the systems as needed to perform their job. Training will be mandatory before assuming a responsibility, whether it is their first assignment or a change of job or responsibilities within the same role.

11. Professionalism and security of human resources

This Policy applies to all personnel of Xeria Digital, S.L and external personnel performing tasks within the company. HR will include information security functions in the job descriptions of employees, will inform all personnel it hires of their obligations regarding compliance with the Information Security Policy, will manage Confidentiality Commitments with the personnel, and will coordinate training tasks for users regarding this Policy.

  • The Security Management Responsible (RGS) is responsible for monitoring, documenting, and analyzing reported security incidents, as well as communicating them to the Information Security Committee and the information owners.
  • The Information Security Committee will be responsible for implementing the means and channels necessary for the Security Management Responsible (RGS) to handle reports of incidents and system anomalies. The Committee will also oversee, supervise the investigation, monitor the progress of the information, and promote the resolution of information security incidents.
  • The Security Management Responsible (RGS) will participate in the preparation of the Confidentiality Commitment to be signed by employees and third parties performing functions at Xeria Digital, S.L , in advising on the sanctions to be applied for non-compliance with this Policy and in the handling of information security incidents.
  • All personnel of Xeria Digital, S.L are responsible for reporting vulnerabilities and information security incidents that are detected in a timely manner.
  • Professionalism of human resources:
  • Determine the necessary competence of the personnel to carry out the work affecting Information Security.
  • Ensure that people are competent based on adequate education, training, or experience.
  • Documented information must demonstrate the competence of personnel in Information Security.

The objectives of controlling personnel security are:

  • Reduce the risks of human error, irregularity, misuse of facilities and resources, and unauthorized handling of information.
  • Explain security responsibilities at the recruitment stage and include them in the agreements to be signed and verify their compliance during the performance of the employee's tasks.
  • Ensure that users are aware of the threats and concerns of information security and are trained to support the organization's Information Security Policy in the course of their normal tasks.
  • Establish confidentiality commitments with all staff and users outside the information processing facilities.
  • Establish the necessary tools and mechanisms to promote the communication of existing security weaknesses, as well as incidents, in order to minimize their effects and prevent their recurrence.

12. Authorization and access control to Information Systems

The objective of controlling access to information systems is:

  • Prevent unauthorized access to information systems, databases, and information services.
  • Implement security in user access through authentication and authorization techniques.
  • Control security in the connection between the Xeria Digital, S.L network and other public or private networks.
  • Review critical events and activities carried out by users on the systems.
  • Raise awareness of their responsibility for the use of passwords and equipment.
  • Guarantee the security of information when using laptops and personal computers for remote work.

13. Protection of facilities

The objectives of this facility protection policy are:

  • Prevent unauthorized access, damage, and interference to the headquarters, facilities, and information of Xeria Digital, S.L.
  • Protect critical information processing equipment of Xeria Digital, S.L, by placing it in protected areas and securing it with defined security perimeters, with appropriate security measures and access controls. It also includes protecting it during transport and keeping it out of protected areas, for maintenance or other reasons.
  • Control environmental factors that could adversely affect the proper functioning of the computing equipment that houses the information of Xeria Digital, S.L.
  • Implement measures to protect information handled by personnel in offices, in the normal course of their usual tasks.
  • Provide protection proportional to the identified risks.

This Policy applies to all physical resources related to the information systems of Xeria Digital, S.L : installations, equipment, cabling, files, storage media, etc.

It should be noted that in the case of Xeria Digital, S.L, all development, quality, etc. environments are located externally in secure hosting, so only laptops and peripherals need to be protected locally.

The Security Management Responsible (RGS), together with the Information Owners, as appropriate, will define the physical and environmental security measures for the protection of critical assets, based on a risk analysis, and will supervise their application. It will also verify compliance with physical and environmental security provisions.

The heads of the different departments will define the levels of physical access of Xeria Digital, S.L personnel to restricted areas under their responsibility. Information Owners will formally authorize off-site work with business-sensitive information for Xeria Digital employees when deemed appropriate.

All personnel of Xeria Digital, S.L are responsible for complying with the clean screen and desktop policy, to protect information related to daily work in offices.

14. Acquisition of products

The different departments must ensure that ICT security is an integral part of every stage of the system life cycle, from its conception to its decommissioning, passing through the development or acquisition decisions and the operating activities. Security requirements and funding needs must be identified and included in planning, in the request for proposals, and in bidding documents for ICT projects.

On the other hand, information security must be taken into account in the acquisition and maintenance of information systems, limiting and managing change.

The information systems development and acquisition policy is developed in the document: Development and Maintenance Policy for Systems.

15. Security by default

Xeria Digital, S.L considers it strategic for the entity that processes integrate information security as part of their life cycle. Information systems and services must include security by default from their creation to their decommissioning, including security in the development and/or acquisition decisions and in all operational activities, establishing security as an integral and transversal process.

16. Integrity and updating of the system

Xeria Digital, S.L is committed to ensuring the integrity of the system through a change management process that allows for control of the updating of physical or logical elements through prior authorization for their installation in the system. This assessment will be mainly carried out by the technical management, which will evaluate the impact on system security before making changes and will control, in a documented manner, those changes assessed as important or with security implications for the systems.

Periodic security reviews will evaluate the security status of the systems, in relation to the manufacturer's specifications, vulnerabilities, and updates affecting them, promptly reacting to manage the risk based on the security status of these.

17. Protection of stored and in-transit information

Xeria Digital, S.L establishes protection measures for Information Security stored or in transit through insecure environments. Laptops, peripheral devices, information storage media, and communications over open or weakly encrypted networks will be considered insecure environments.

18. Prevention of interconnected information systems

Xeria Digital, S.L, establishes protection measures for Information Security especially to protect the perimeter, particularly if connected to public networks, especially if used wholly or mainly, for the provision of electronic communication services available to the public.

In any case, the risks derived from the interconnection of the system, through networks, with other systems will be analyzed, and its junction point will be controlled. Electronic connections available to the public.

19. Activity logs

Xeria Digital, S.L, will log user activities, retaining the information necessary to monitor, analyze, investigate, and document improper or unauthorized activities, allowing the identification of the acting person at any given time.

The main objectives of Incident Management are to:

  • Establish a detection and reaction system against harmful code.
  • Have security incident management procedures and weaknesses detected in the elements of the information system.
  • These procedures will cover detection mechanisms, classification criteria, analysis and resolution procedures, as well as communication channels to interested parties and the registration of actions taken.
  • This registration is used for the continuous improvement of system security.
  • Ensure that IT services return to optimal performance.
  • Reduce the possible risks and impacts that the incident may cause.
  • Safeguard the integrity of the systems in the event of a security incident.
  • Communicate the impact of an incident as soon as it is detected to activate the alarm; and implement an appropriate corporate communication plan.
  • Promote business efficiency.

20. Continuity of activity

Xeria Digital, S.L, with the aim of ensuring the continuity of activities, establishes measures so that systems have backup copies and establishes the necessary mechanisms to guarantee the continuity of operations, in case of loss of the usual means of work.

21. Continuous improvement of the security process

Xeria Digital, S.L establishes a continuous improvement process for information security applying the criteria and methodology established in the National Security Scheme.