CEDESA DIGITAL

Information Security Policy

This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails. Read the Spanish version

CEDESA DIGITAL, S.L. · Edition 02 · Standards: ISO 27001 · ENS

CEDESA DIGITAL, S.L., a company specialising in high-performance software development and digital transformation, establishes this Information Security Policy as the reference framework for protecting its own information assets and those of its clients.

Objectives

  • ▸To meet the expectations of all stakeholders with regard to security.
  • ▸To manage and minimise information security risks.
  • ▸To comply with the legislation in force: the GDPR, the LOPDGDD (Spain's data protection act), the National Security Framework (Esquema Nacional de Seguridad, ENS) and other applicable regulations.
  • ▸To protect information assets against internal and external threats.
  • ▸To guarantee the confidentiality, integrity and availability of information.
  • ▸To continually improve the Information Security Management System (ISMS).

Regulatory framework

The policy is framed within compliance with more than 15 Spanish and European regulations, notably:

  • ISO 27001 / ISO 27002
  • ENS – Royal Decree 311/2022 (Real Decreto 311/2022)
  • GDPR (RGPD)
  • LOPDGDD (Organic Law 3/2018)
  • LSSI (Law 34/2002, Spain's e-commerce act)
  • Law 39/2015 on administrative procedure (Ley 39/2015)

Code of ethics

CEDESA aligns itself with the standards of the ACM (Association for Computing Machinery) and the IEEE-CS, which are based on 8 principles: public, client and employer, product, judgment, management, profession, colleagues and self.