Document: SGSI.005 Política de Seguridad de la Información
Version: 1.0
Approved on: 23 July 2026
Text approved on 23 July 2026 by the management of Flameera S.L (hereinafter, Flameera). This text is an extract from Flameera’s Information Security Policy “SGSI.005 Política de Seguridad de la Información”, available to employees and suppliers, as well as to any person or entity that requests it.
Mission, vision and values
Flameera’s mission is to empower organisations through proactive, close and tailored cybersecurity, supporting them in protecting and continuously improving their security so that they can grow and move forward with confidence.
Its vision is to be the benchmark strategic partner in cybersecurity services, recognised for its closeness, technical excellence and ability to support organisations comprehensively as they evolve.
For Flameera, values are not a word, they are the behaviour they require, and therefore the following values apply:
Innovation, through genuine continuous improvement, constant updating and the practical application of new technologies to generate tangible value.
Closeness in human relationships, with direct communication and an active presence in every project.
Integrity as the basis for honesty, consistency and responsibility in every decision and relationship.
Support, based on guidance, explanation and capability building, helping clients improve their security without creating dependency.
Humility as the basis for listening, learning and acknowledging limits with transparency and professionalism.
Collaboration through joint work, sharing knowledge and contributing to the progress of the ecosystem.
Flameera identifies information security and privacy as key factors for the competitiveness and sustainability of the business, as well as for regulatory compliance.
Flameera has an Information Security Management System in place to guarantee the availability of the services it provides and the confidentiality, integrity, traceability and authenticity of the information it handles, implementing organisational, technical and legal measures to protect business assets.
Flameera has established the processes for planning and implementing information security controls, safeguards and measures, as well as for monitoring and improving security, in order to guarantee the confidentiality, integrity, authenticity and traceability of information, and the availability of the services provided to clients.
Flameera is responsible for the Information Security Management System as the framework for achieving the following main objectives:
- Comply with legislation, in particular that relating to the security of networks and systems, the protection of personal data, intellectual and industrial property, and any other applicable regulations
- Assess and treat information security and privacy risks
- Manage information security and privacy incidents
- Guarantee service continuity
- Measure, analyse and optimise the effectiveness and efficiency indicators of information security and privacy
- Improve management processes and information security and privacy controls.
- Monitor, audit and certify compliance with the ISO/IEC 27001 standard and the Spanish National Security Framework (ENS).
For the implementation, maintenance, monitoring and improvement of the Information Security Management System, Flameera has taken the following decisions:
- Establishment of an Information Security Committee as the senior collegiate body for the supervision, coordination and decision-making on information security and privacy
- Appointment of those responsible for the Service, the Information, Information Security and the Information System
- Appointment of a Data Protection Officer
- Analysing and treating the information security and privacy risks arising from the provision of services, and implementing the controls, measures or safeguards required to mitigate, transfer or eliminate them.
- Allocation of personnel and material resources to meet information security requirements, maintaining the balance between cost and benefit.
- Raising awareness and training all staff and collaborators on information security risks and threats and on the measures to be followed for their prevention and mitigation or, where applicable, for reporting incidents.
- Implementation of appropriate measures to guarantee the information security levels of contracted components and services, preventing, responding to and resolving any incidents that may arise.
- Measuring and analysing information security objectives and indicators that enable Management to monitor security risks and incidents, as well as control activities.
This policy is complemented by the remaining policies, procedures and documents in force within Flameera’s Information Security Management System.
Scope
The provisions of this Policy apply to all Flameera solutions and services provided to Public Administrations, and must be followed by all Flameera personnel.
Reference standards and regulations
The procedure is aligned with the internal and external standards, laws and regulations applicable to Flameera, which are detailed in the latest version of the document “SGSI.002 Regulations”.
Roles: functions and responsibilities
Flameera’s designated roles and responsibilities are detailed in the latest version of the document “SGSI.006 Statutes governing the operation of the Information Security Committee”.
Information security principles
Principle of confidentiality: information systems shall be accessible only to those users, bodies, entities or processes expressly authorised to do so, in compliance with the obligations of professional secrecy and confidentiality.
Principle of integrity: the integrity of information and of the processes for handling it shall be maintained, establishing the mechanisms to ensure that the creation, processing, storage and distribution of information help preserve its accuracy and correctness.
Principle of availability and continuity: a high level of availability shall be guaranteed in information systems, which shall be provided with the plans and measures needed to ensure service continuity and recovery from possible serious contingencies.
Principle of risk management: a continuous process of risk analysis and treatment shall be articulated as the basic mechanism on which the security management of information systems must rest.
Principle of cost proportionality: the implementation of measures to mitigate information system security risks shall be carried out with a proportionate approach to economic and operational costs.
Principle of awareness and training: initiatives shall be articulated to enable users to know their duties and obligations regarding the secure handling of information. Likewise, specific security training shall be promoted for all those who manage and administer information and telecommunications systems.
Principle of prevention: specific plans and lines of work shall be developed to prevent fraud, non-compliance or security-related incidents.
Principle of continuous improvement: the effectiveness of the security controls implemented shall be reviewed in order to adapt them to the constant evolution of risks and of the technological environment.
Principle of security throughout the information systems life cycle: security specifications shall be included in all phases of the life cycle of services and systems, accompanied by the corresponding control procedures.
Principle of differentiated function: responsibility for the security of information systems shall be separate from responsibility for the provision of services.
Principle of continuous monitoring and periodic reassessment: Continuous monitoring shall enable the detection of anomalous activities or behaviours and a timely response. Ongoing assessment of the security status of assets shall make it possible to measure their evolution, detecting vulnerabilities and identifying configuration deficiencies.
Security measures shall be periodically reassessed and updated, adapting their effectiveness to the evolution of risks and protection systems, which may lead to a rethinking of security if necessary.
The basic principles are fundamental security guidelines that must always be borne in mind in any activity involving the use of information assets. The following are established:
- Strategic scope: Information security must have the commitment and support of all levels so that it can be coordinated and integrated with the other strategic initiatives to form a coherent and effective whole.
- Proactive accountability: Complying and demonstrating compliance; to this end, proactive measures aimed at guaranteeing compliance shall be implemented. In addition, the actions and measures implemented to achieve such compliance shall be identified, reported and documented through evidence, so that it can be demonstrated at all times.
- Comprehensive security: Security shall be understood as a comprehensive process made up of all the technical, human, material and organisational elements related to the system, avoiding, except in cases of urgency or necessity, any one-off action or short-term treatment. Information security must be considered part of routine operations, being present and applied from the initial design of information systems.
- Risk Management: Risk analysis and management shall be an essential part of the security process. Risk management shall enable a controlled environment to be maintained, minimising risks to acceptable levels. These levels shall be reduced by deploying security measures that strike a balance between the nature of the data and the processing, the impact and likelihood of the risks to which they are exposed, and the effectiveness and cost of the security measures. When assessing risk in relation to data security, the risks arising from the processing of personal data must be taken into account.
- Proportionality: The establishment of protection, detection and recovery measures shall be proportionate to the potential risks and to the criticality and value of the information and services affected.
- Continuous improvement: Security measures shall be periodically reassessed and updated to adapt their effectiveness to the constant evolution of risks and protection systems. Information security shall be attended to, reviewed and audited by qualified, trained and dedicated personnel.
- Security and data protection by design and by default: Systems must be designed and configured in such a way as to guarantee a sufficient degree of security by default.
Minimum security requirements
The Information Security Policy shall be established in accordance with the basic principles set out above and shall be developed by applying the following minimum requirements:
- Organisation and implementation of the security process.
- Risk analysis and management.
- Personnel management.
- Professionalism.
- Authorisation and access control.
- Protection of facilities.
- Acquisition of security products and contracting of security services.
- Least privilege.
- System integrity and updating.
- Protection of stored and in-transit information.
- Prevention against other interconnected information systems.
- Activity logging and malicious code detection.
- Security incidents.
- Business continuity.
- Continuous improvement of the security process.
Development and regulatory structure
The hierarchical structure of Flameera’s security documentation is as follows:
| DOCUMENT | DESCRIPTION |
|---|---|
| Policy | Defines security goals and expectations. Describes what kind of security management is to be achieved and what objectives are pursued. It must be drawn up and approved by the Security Committee. |
| Regulations | Establish what must be done and standardise the use of specific aspects of the system. They are mandatory. They must be drawn up by subject matter experts or by the Security Officer and approved by the Security Committee. Where the modification constitutes a minor change that does not require a new version, it may be approved directly by the Security Officer, who must inform the members of the Security Committee beforehand. |
| Procedures | Determine the actions or tasks to be carried out in the performance of a security-related process and the persons or groups responsible for their execution. A procedure must be clear, easy to interpret and unambiguous in its execution. It need not be lengthy, since the intention of the document is to indicate the actions to be carried out. A procedure may draw on other documents to specify the different tasks in as much detail as required. To this end, it may be linked to other procedures or to technical security instructions. It must be drawn up by subject matter experts or by the Security Officer or System Officer and approved by the Security Committee. Where the modification constitutes a minor change that does not require a new version, it may be approved directly by the Security Officer, who must inform the members of the Security Committee beforehand. |
| Technical instructions | Determine the actions or tasks required to complete an activity or process of a specific procedure on a specific part of the information system (hardware, operating system, application, data, user, etc.). Like a procedure, they are the detailed specification of the steps to be executed. A technical instruction must be clear and easy to interpret. It must document the technical aspects needed so that the person executing the technical instruction does not have to make decisions regarding its execution. The greater the level of detail, the greater the precision and the assurance of its correct execution. They may be drawn up by the System Officer or System Administrator and must be approved by the Security Officer. |
| Guides or Best practices | These are educational in nature and seek to help users apply security measures correctly by providing reasoning where precise procedures do not exist. For example, there is usually a guide on how to write security procedures. Guides help prevent important security aspects, which can materialise in various ways, from being overlooked. They must be approved by the Security Officer. |