Security policy

Mission

To meet the needs of our private and public sector clients in terms of 4.0 technologies, promoting actions that contribute to the development of their business, obtaining the best results, and adding value to society in general.

Commitment to Security

Invelon ensures the proper management of information security to protect its confidentiality, integrity, availability, authenticity, and traceability. The company is committed to preventing incidents and ensuring service continuity.

Scope

The policy applies to all ICT systems and personnel involved in public sector projects that require compliance with the National Security Scheme (ENS).

Security Objectives

Increase resilience to incidents, ensure rapid service recovery, and mitigate information security risks.

Regulatory Framework

Invelon complies with various regulations such as the European General Data Protection Regulation (GDPR) and Spanish data protection and information security laws.

Security Organization

Management is responsible for providing the resources to meet security objectives. Specific roles are assigned, such as the Security Officer and the Security Committee, which makes key decisions in this area.

Risk Management

Systems subject to this policy must perform a risk analysis annually or when significant changes occur. The Security Committee manages these analyses.

Personnel Management

All personnel must be trained in information security and sign confidentiality agreements. Annual security awareness sessions are held.

Access Control and Facility Protection

Security measures are implemented to prevent unauthorized access to systems and protect critical equipment. Security is promoted in the use of mobile devices and remote working.

Product Acquisition

Security is integrated into all phases of the system lifecycle, from acquisition to retirement.

Business Continuity

Backup and business continuity mechanisms are established in case of incidents that affect normal working conditions.

Continuous Improvement

The policy encourages continuous improvement of the security management system, in line with international standards such as ISO 27001.