COM3 Systems Security Principles
COM3 Systems Engineering LTDA will protect information throughout all phases of its lifecycle — creation/reception, use and processing, communication and transport, storage and authorized dissemination, and deletion or destruction — ensuring its confidentiality, integrity, availability, authenticity, and traceability. This protection will apply to physical and logical media, both proprietary and third-party (including cloud), through organizational, technical, and physical controls proportional to its classification (e.g., access control, encryption, logging and monitoring, and certified destruction where applicable).
Therefore, the following minimum principles are established:
a) Security as an integrated process (Art. 6)
Security is conceived as an integrated and continuous process encompassing the human, material, technical, legal, and organizational elements of the information system. All information processing will be governed by this principle, avoiding ad hoc or circumstantial actions.
Management and the responsible parties (CISO, SSO, IO, SO) will ensure effective coordination, definition of responsibilities, and provision of necessary resources. Awareness and training of all involved persons will be promoted, so that lack of knowledge, organization, coordination, or instructions does not become a source of risk.
Security will be implemented under a continuous improvement approach (PDCA), with documented and measurable preventive, detective, and corrective controls.
b) Risk-based security management (Art. 7)
Risk analysis and management is an essential, continuous, and up-to-date process that underpins security. Its objective is to maintain a controlled environment, reducing risks to acceptable levels defined by Management (risk appetite).
Risk reduction will be achieved through the proportionate and balanced application of security measures (organizational, operational, and technical) consistent with the classification of information, the services provided, and exposure to threats.
Identified risks will be recorded and addressed according to a risk analysis methodology, applying mitigation, transfer, avoidance, or acceptance treatments, with defined responsible parties, deadlines, and evidence.
c) Prevention, detection, response, and preservation (Art. 8)
System security will be implemented as a continuous cycle of prevention, detection, and response, in order to minimize vulnerabilities, deter and reduce the exposure surface, and prevent threats from materializing or, if they do, limit their impact on information and services.
Prevention measures will eliminate or reduce the likelihood of materialization (hardening, patches, access control, segmentation, encryption, principle of least privilege, and Zero Trust).
Detection measures will allow cyber incidents to be discovered and qualified in a timely manner (logging and event correlation, alerts, and defined thresholds).
Response measures will restore affected information and services according to the maximum allowable time to restore service and the maximum acceptable data loss age, including containment, eradication, recovery, and lessons learned.
Without prejudice to the principles of the National Security Scheme (ENS), the system will guarantee the preservation and authenticity of electronic data and the availability of services throughout the information lifecycle.
d) Existence of defense lines (Art. 9)
The system will have a multi-layer protection strategy. If one layer is compromised, the remaining layers will allow for an appropriate reaction and incident containment, reducing the probability of total compromise and minimizing the impact on information and services.
These lines of defense will include coordinated organizational, physical, and logical/technological measures.
e) Continuous monitoring and periodic reassessment (Art. 10)
Continuous system monitoring will detect anomalous activities or behaviors and enable timely response to contain them.
Permanent security assessment of assets will measure their evolution, identifying vulnerabilities and configuration deviations.
Security measures will be periodically reviewed and updated, adjusting their effectiveness to the evolution of risks, threats, and protection technologies, and the security approach may be reconsidered when necessary.
f) Segregation of responsibilities (Art. 11)
In the information system, a clear segregation of responsibilities will be maintained:
-
Information Owner (IO): Defines the classification and security requirements of the processed information.
-
Service Owner (SO): Establishes the security requirements of the service and ensures they are met during operation.
-
System Owner (SSO): Responsible for the implementation and technical operation supporting services (infrastructure, applications, networks).
-
Chief Information Security Officer (CISO): Guides and decides on security matters to meet defined requirements, coordinates risk management and incident response.
When personal data processing occurs, the roles of Data Controller and, where applicable, Data Processor will also be identified, in accordance with GDPR/LOPDGDD, ensuring consistency between these functions and the above responsibilities.
Regulatory Framework
COM3 Systems Engineering LTDA is subject to the following regulations in the provision of services to its clients:
-
Royal Decree 311/2022, of May 3, which regulates the National Security Scheme (ENS).
-
Resolution of October 7, 2016, of the Secretary of State for Public Administrations, approving the Technical Security Instruction on Security Status Report.
-
Resolution of October 13, 2016, of the Secretary of State for Public Administrations, approving the Technical Security Instruction in accordance with the National Security Scheme.
-
Resolution of March 27, 2018, of the Secretary of State for Civil Service, approving the Technical Security Instruction on Information System Security Auditing.
-
Resolution of April 13, 2018, of the Secretary of State for Civil Service, approving the Technical Security Instruction on Security Incident Notification.
-
Organic Law 3/2018, of December 5, on Personal Data Protection and guarantee of digital rights.
-
REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
-
CCN-STIC Security Guides.
-
Occupational Risk Prevention Law 31/1995 of November 8 and Royal Decree 39/1997.
-
Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSI-CE).
-
Royal Decree-Law 13/2012 of March 30, Cookie Law.
-
Royal Legislative Decree 1/1996, of April 12, approving the revised text of the Intellectual Property Law.
Security Roles and Functions
The different roles determined along with their respective functions and responsibilities are:
CISO — Chief Information Security Officer
-
Design, implement, and maintain the ISMS according to the ENS.
-
Maintain risk analysis and treatment, training/awareness plan.
-
Establish standards/procedures (access, changes, incidents, backups, logs, continuity).
-
Coordinate security incidents.
-
Measure and report indicators.
SO — Service Owner
-
Be the functional owner of the service.
-
Define, integrate, and maintain security requirements in contracts with suppliers.
-
Align operation with business needs and with the ENS.
SSO — System Owner
-
Be the technical owner of the platform/system: architecture, hardening, patches, backups, logs.
-
Manage configuration and inventory, vulnerabilities, monitoring, and capacity.
-
Execute daily operations.
IO — Information Owner
-
Establish access criteria and authorize access to their data.
-
Define information retention and destruction.
-
Participate in impact assessments and incident management.
Awareness and Training
All workers of COM3 Systems Engineering LTDA are obliged to know and comply with this Information Security Policy. All will attend an ICT security awareness session at least once a year.
System Security Documentation
COM3 Systems Engineering LTDA has a document management system through which documents are edited, reviewed, and approved.
Risk Management
All systems subject to this Policy will be included in a risk analysis that evaluates threats, vulnerabilities, and impacts. This analysis will be repeated:
-
Periodically, at least annually.
-
When the processed information changes.
-
When the services provided or their criticality change.
-
After a serious security incident.
-
In the face of serious vulnerabilities or new relevant threats.
Organizational, Operational, and Protection Controls (ENS)
Principles and requirements aligned with the ENS are established, applicable to all services, assets, and people involved, including: organization, risk analysis, personnel management, access control, facility protection, system integrity and updating, information protection, activity logging, incident management, business continuity, and continuous improvement.
Personal Data
COM3 Systems Engineering LTDA processes personal data and will guarantee its protection in accordance with GDPR/LOPDGDD and the ENS.
Third Parties (Suppliers and Clients)
When services are provided or information from other organizations is processed, said parties will know and accept this Security Policy and the applicable associated regulations.
Prevention, Detection, Response, and Recovery
COM3 Systems Engineering LTDA will be prepared to prevent, detect, respond to, and recover from security incidents, with defined responsibilities and coordination by the Security Committee.
Information Security Policy Review
The Information Security Committee will prepare the Information Security Policy (ISP) in accordance with Art. 12 of the ENS and control ORG.1 of Annex II. It will be reviewed at least annually.
The ISP will be approved by Management (CEO of COM3 Systems Engineering LTDA) and communicated to all affected parties.
Quer saber mais sobre os produtos e soluções?