INFORMATION SECURITY POLICY
SIGE is ISO 27001:2022 certified and thus endorses our commitment to security in our systems. This international standard describes how to manage information security in companies and seeks to ensure its confidentiality, integrity and availability, minimising possible risks and threats as much as possible.
1.Introduction
Information is one of ROCAJUNYENT GROUP’s most valuable assets, as it is essential to the provision of the services it delivers to third parties. At the same time, Information and Communication Technologies (ICT) have become indispensable to organisations, as they enable information to be processed efficiently and effectively. However, the benefits provided by ICT are accompanied by new risks. It is therefore necessary to implement specific measures to protect both information and the services that depend on it.
The objective of information security is to protect information and the services that rely on it by reducing the associated risks to an acceptable level. This document establishes the Information Security Policy of ROCAJUNYENT GROUP to ensure that all personnel, whether directly or indirectly engaged by the organisation, understand, promote and support information security.
The purpose of this Policy is to achieve the strategic alignment of information security management with internationally recognised standards and the applicable legal and regulatory framework.
2. Purpose and Objectives of the Information Security Policy
ROCAJUNYENT GROUP has aligned its information security management with the requirements of the ISO/IEC 27001 standard, recognising information and the systems that support it as strategic assets.
One of the primary objectives of implementing this Information Security Policy is to establish the foundations that enable both internal personnel and third parties to access the services provided by ROCAJUNYENT GROUP within a secure and trusted environment.
This Information Security Policy defines the overall framework for information security management by protecting all information assets and ensuring the continuity of information systems. Its purpose is to minimise the risks arising from potential security failures and to ensure that ROCAJUNYENT GROUP is able to meet its objectives in the event of an information security incident.
To this end, the following general information security objectives are established:
To contribute, through effective information security management, to the achievement of ROCAJUNYENT GROUP’s mission and strategic objectives.
To implement the necessary security controls to ensure compliance with all applicable legal and regulatory requirements, particularly those relating to the protection of personal data and the provision of electronic or online services.
To ensure the accessibility, confidentiality, integrity, availability, authenticity and traceability of information.
To ensure the continuous delivery of services through both preventive and responsive security measures.
To protect ROCAJUNYENT GROUP’s information assets and the technology supporting them against any intentional or accidental, internal or external threats, thereby ensuring their confidentiality, integrity and availability.
This Information Security Policy reflects ROCAJUNYENT GROUP’s ongoing and explicit commitment to promoting and strengthening a culture of information security throughout the organisation.
3. Scope
This Information Security Policy applies to all information managed by ROCAJUNYENT GROUP.
For the purposes of this Policy, ROCAJUNYENT GROUP comprises the following offices:
Aribau Street, 198, 1st Floor, Barcelona.
José Abascal Street, 56, 6th Floor, Madrid.
Gran Via Jaume I, 37, 5th Floor, Girona.
The scope of the information systems operated by ROCAJUNYENT is extended to include the following organisation:
SIGE BUSINESS SERVICES, S.L.P.U. (“SIGE”), with offices at the same locations.
For the purposes of this Policy, ROCAJUNYENT GROUP shall be understood as the collective entity comprising all the organisations listed above.
This Policy is not limited to personal data and applies equally to both manual and automated processing activities.
4. Regulatory Framework
The legislation governing information security, which serves as the applicable regulatory reference, is continuously updated and is detailed in the “Appendix: Applicable Legislation.”
5. Policy Review
With regard to revisions of this Information Security Policy, two types of review activities are established:
Scheduled reviews: These shall be carried out at least annually, or whenever incidents or changes in the legal or regulatory framework arise that could affect the validity of this Policy. The review process shall ensure that the Information Security Policy remains aligned with ROCAJUNYENT GROUP’s strategy, mission and vision regarding information security and continues to support the achievement of its established security control objectives.
Unscheduled reviews: These shall be performed in response to any event or security incident that may significantly increase the current level of risk or have an impact on the information security of ROCAJUNYENT GROUP.
6. Internal Security Organisation
Information security within ROCAJUNYENT GROUP is structured through an internal governance framework designed to oversee the governance, supervision, operation, maintenance and continuous improvement of the Information Security Management System (ISMS), while ensuring compliance with the requirements established by UNE-EN ISO/IEC 27001 and the Spanish National Security Framework (Esquema Nacional de Seguridad – ENS).
Responsibility for information security is assigned, in accordance with the functions defined in this section, to the following governing bodies and roles:
Information Security and Data Protection Committee.
Information Owner.
Service Owner.
Information Security Officer.
System Owner.
Senior Management / Management Representative.
Data Protection Officer.
Delegated Officers, where formally appointed.
Where a single individual or body performs more than one role, the responsibilities assigned to each role shall remain clearly separated in order to avoid conflicts of interest and ensure an appropriate segregation between governance, oversight, business decision-making and technical operational functions.
6.1. Information Security and Data Protection Committee
The Information Security and Data Protection Committee is the governing body responsible for the overall governance, coordination, monitoring and continuous improvement of information security within ROCAJUNYENT GROUP.
It shall act as the governing body for information security, overseeing compliance with this Information Security Policy, the Information Security Management System (ISMS), and the applicable requirements of the Spanish National Security Framework (ENS).
The Committee shall be responsible for reviewing the status of the ISMS, promoting its continual improvement, monitoring risks, security incidents, audits, metrics, non-conformities and improvement actions, and ensuring that the necessary resources are available for its effective operation.
Where justified by the complexity of the organisation, the physical distribution of the systems, the number of users or the organisational structure, delegated security committees may be established, reporting functionally to the main Information Security and Data Protection Committee.
6.2. Information Owner
The Information Owner is responsible for determining or validating the security requirements applicable to the information processed by ROCAJUNYENT GROUP, taking into consideration its value, criticality, classification, purpose, intended use and impact on the organisation.
Where appropriate, the Information Owner shall participate in the valuation of information assets, the risk assessment process affecting such information, and the acceptance of any associated residual risks.
6.3. Information Security Officer
The Information Security Officer shall be responsible for coordinating and supervising information security, ensuring compliance with all applicable regulations, including the Spanish National Security Framework (ENS), and overseeing the effective implementation, maintenance and continual improvement of the ISMS.
This role may be performed by the ISMS Manager, provided that an appropriate segregation of duties is maintained with respect to the System Owner, the Information Owner and the Service Owner.
Where justified by the complexity of the organisation, the physical distribution of its systems or the number of users of electronically processed information, delegated Information Security Officers may be appointed and shall report functionally to the principal Information Security Officer.
6.4. Service Owner
The Service Owner is responsible for determining or validating the security, continuity, availability, recovery and impact requirements applicable to the services included within the scope of the ISMS and, where appropriate, for contributing to the categorisation of the information system in accordance with the Spanish National Security Framework (ENS).
For the purposes of this Policy, a service shall mean any business activity or service provided by ROCAJUNYENT GROUP that falls within the scope of the ISMS and is supported by information systems. This shall not be confused with internal technical services, software applications, departments or technological components that support such business activities.
Where appropriate, the Service Owner shall participate in the valuation of services, the risk assessments affecting those services and the acceptance of any associated residual risks.
6.5. System Owner
The System Owner shall be responsible for the operation, administration, maintenance and technical performance of the information systems, ensuring the correct implementation, operation and maintenance of applicable security controls, as well as the configuration and management of the systems.
This role may be assigned to the Technical Systems Manager or to any other formally designated individual, depending on the information system concerned and the organisational structure in place.
6.6. Senior Management / Management Representative
Senior Management shall be responsible for approving the Information Security Policy, promoting a culture of information security, ensuring that adequate resources are available, reviewing the performance of the ISMS and taking the necessary decisions to support its continual improvement.
Where formally appointed, the Management Representative shall act as the liaison between Senior Management and the Information Security and Data Protection Committee.
6.7. Data Protection Officer
The Data Protection Officer (DPO) shall participate in the Information Security and Data Protection Committee, providing guidance on compliance with personal data protection legislation, the management of incidents involving personal data, and the measures required to safeguard privacy and the rights of data subjects.
6.8. Other Areas
The protection of the integrity, availability and confidentiality of information assets is the responsibility of all users and asset owners within the scope of their respective duties and in accordance with the applicable internal policies.
All security incidents, suspicious events or identified security weaknesses shall be reported to the Information Security Officer or through the incident reporting channels established by the organisation.
7. Conflict Resolution
In the event of any conflict between the various roles and responsibilities defined within the organisational structure of this Information Security Policy, the matter shall be resolved by the Management of ROCAJUNYENT GROUP. Where applicable, the strictest requirements arising from personal data protection legislation shall prevail.
8. Information Classification
ROCAJUNYENT GROUP shall classify and maintain an inventory of its information assets according to their nature. The level of protection and the security measures to be applied shall be determined on the basis of the resulting classification.
Furthermore, information systems shall be categorised in accordance with the criteria established by the Spanish National Security Framework (ENS).
9. Personal Data
Where an information system within the scope of ISO/IEC 27001 processes personal data, it shall comply with the provisions of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights, together with their implementing regulations, without prejudice to the requirements established under the ISO/IEC 27001 framework in relation to Electronic Administration.
All information systems shall comply with the security requirements established by the applicable personal data protection legislation.
10. Risk Management
All systems subject to this Policy shall undergo a risk assessment and risk management process, evaluating the assets, threats and vulnerabilities to which they are exposed and identifying the appropriate safeguards required to mitigate the associated risks.
Although changes to information systems shall be continuously monitored, the risk assessment process shall be repeated:
At least once a year (through formal review and approval).
Whenever the information processed changes.
Whenever the services provided change.
Whenever a major security incident occurs.
Whenever critical vulnerabilities are identified.
To ensure consistency in risk assessments, reference values shall be established for the various types of information processed and for the different services provided.
11. Implementation Framework
An information security governance framework is established, structured at different levels to ensure that the objectives defined in this Information Security Policy are implemented through specific controls and procedures. The Information Security Policy shall be supported by the following hierarchical framework:
This Information Security Policy, which establishes the overall security principles, requirements and protection criteria.
Security Standards, which define what must be protected and the required security controls. Collectively, these standards shall provide protection for all information system environments across the organisation. They establish the requirements and expected outcomes necessary to achieve each of the information security objectives defined in this Policy. The Security Standards shall be proposed by the Information Security Officer and approved by the Information Security and Data Protection Committee.
Security Procedures, which describe in detail how the controls established in the Security Standards are to be implemented, as well as identifying the individuals or teams responsible for their implementation, maintenance and ongoing monitoring. These documents specify how routine tasks shall be performed, who is responsible for carrying them out, and how abnormal situations or security events shall be identified and reported.
Approval of these procedures shall depend on their scope of application, which may relate either to a specific organisational area or to a particular information system.
In addition, guidance documents containing recommendations and best practices may be developed where appropriate.
Wherever practicable, all such documentation shall be managed in accordance with ROCAJUNYENT GROUP’s Document and Records Control Procedure, which establishes the requirements governing the control of documentation and security records forming part of the Information Security Management System (ISMS) and applies to all documentation supporting compliance with ISO/IEC 27001.
12. Responsibilities of Personnel
All personnel responsible for the use, operation or administration of information and communication technology systems are required to be familiar with and comply with this Information Security Policy and all associated security policies, standards and procedures, regardless of the legal nature of their relationship with ROCAJUNYENT GROUP.
All personnel shall receive appropriate training in the secure use of information systems to the extent required for the performance of their duties.
This Information Security Policy shall be made available to all personnel providing services within the organisational units and entities included within the scope defined in the Scope section.
To promote a strong information security culture, the Information Security and Data Protection Committee shall establish an ongoing security awareness programme to ensure that all personnel receive appropriate information security training.
Failure to comply with this Information Security Policy or its supporting documentation may result in the implementation of preventive and corrective measures designed to safeguard and protect the organisation’s networks and information systems, without prejudice to any applicable disciplinary actions.
13. Third-Party Relationships
Whenever ROCAJUNYENT GROUP provides services to, or discloses information to, third parties, those parties shall be informed of this Information Security Policy and of any related security standards and instructions.
Likewise, whenever ROCAJUNYENT GROUP engages third-party service providers or discloses information to third parties, they shall be informed of this Information Security Policy and of any security requirements and instructions applicable to the relevant services or information. Third parties shall be required to comply with the obligations and security measures established therein and may develop their own operational procedures to ensure such compliance. Specific procedures for incident detection and resolution shall also be established.
ROCAJUNYENT GROUP shall ensure that third-party personnel maintain an appropriate level of information security awareness, at least equivalent to that required under this Information Security Policy.
In particular, third parties shall demonstrate compliance with this Information Security Policy through recognised auditable standards that allow such compliance to be verified. Furthermore, upon termination of the contractual relationship, they shall provide evidence, by means of an audit or a certificate of secure destruction or deletion, that all information belonging to ROCAJUNYENT GROUP has been permanently erased or destroyed.
Where a third party is unable to comply with any provision of this Information Security Policy, the Information Security Officer shall prepare a formal assessment identifying the associated risks and the measures proposed to manage them. Such assessment shall require the approval of Management before the engagement may proceed.
Approved by:
Information Security and Data Protection Committee
Management Review – 18 June 2026