Security policy
Mission
To meet the needs of our private and public sector clients in terms of 4.0 technologies, promoting actions that contribute to the development of their business, obtaining the best results, and adding value to society in general.
Commitment to Security
Invelon ensures the proper management of information security to protect its confidentiality, integrity, availability, authenticity, and traceability. The company is committed to preventing incidents and ensuring service continuity.
Scope
The policy applies to all ICT systems and personnel involved in public sector projects that require compliance with the National Security Scheme (ENS).
Security Objectives
Increase resilience to incidents, ensure rapid service recovery, and mitigate information security risks.
Regulatory Framework
Invelon complies with various regulations such as the European General Data Protection Regulation (GDPR) and Spanish data protection and information security laws.
Security Organization
Management is responsible for providing the resources to meet security objectives. Specific roles are assigned, such as the Security Officer and the Security Committee, which makes key decisions in this area.
Risk Management
Systems subject to this policy must perform a risk analysis annually or when significant changes occur. The Security Committee manages these analyses.
Personnel Management
All personnel must be trained in information security and sign confidentiality agreements. Annual security awareness sessions are held.
Access Control and Facility Protection
Security measures are implemented to prevent unauthorized access to systems and protect critical equipment. Security is promoted in the use of mobile devices and remote working.
Product Acquisition
Security is integrated into all phases of the system lifecycle, from acquisition to retirement.
Business Continuity
Backup and business continuity mechanisms are established in case of incidents that affect normal working conditions.
Continuous Improvement
The policy encourages continuous improvement of the security management system, in line with international standards such as ISO 27001.