Information Security Policy
This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails. Read the Spanish version
CEDESA DIGITAL, S.L. · Edition 02 · Standards: ISO 27001 · ENS
CEDESA DIGITAL, S.L., a company specialising in high-performance software development and digital transformation, establishes this Information Security Policy as the reference framework for protecting its own information assets and those of its clients.
Objectives
- ▸To meet the expectations of all stakeholders with regard to security.
- ▸To manage and minimise information security risks.
- ▸To comply with the legislation in force: the GDPR, the LOPDGDD (Spain's data protection act), the National Security Framework (Esquema Nacional de Seguridad, ENS) and other applicable regulations.
- ▸To protect information assets against internal and external threats.
- ▸To guarantee the confidentiality, integrity and availability of information.
- ▸To continually improve the Information Security Management System (ISMS).
Regulatory framework
The policy is framed within compliance with more than 15 Spanish and European regulations, notably:
- ISO 27001 / ISO 27002
- ENS – Royal Decree 311/2022 (Real Decreto 311/2022)
- GDPR (RGPD)
- LOPDGDD (Organic Law 3/2018)
- LSSI (Law 34/2002, Spain's e-commerce act)
- Law 39/2015 on administrative procedure (Ley 39/2015)
Code of ethics
CEDESA aligns itself with the standards of the ACM (Association for Computing Machinery) and the IEEE-CS, which are based on 8 principles: public, client and employer, product, judgment, management, profession, colleagues and self.