Information Security Policy
Reference framework for information security management at Politeia Soft
Version 2.0 — 21 September 2026Downloadable public version (PDF)
Organisation
Politeia Soft S.L.
Tax ID (CIF)
B21966023
Registered office
Jerez de la Frontera (Cádiz), Spain
Contact
info@politeiasoft.com
Purpose and scope
This Information Security Policy (PSI) sets the reference framework to protect the confidentiality, integrity, availability, authenticity and traceability of information processed by Politeia Soft S.L. in developing and operating its software products and services.
It applies to internal and external personnel with access to the organisation’s information systems, and to authorised providers.
ENS framework
The organisation commits to compliance with Royal Decree 311/2022 regulating Spain’s National Security Scheme (ENS). The information system under certification is assessed at MEDIUM category.
Confidentiality
Access only by authorised personnel
Integrity
Protection against unauthorised alteration
Availability
Systems and data accessible when required
Authenticity
Verification of identities and origins
Traceability
Logging of relevant actions
Principles
- Defence in depth
- Least privilege
- Secure by default
- Continuous improvement
- Segregation of duties (ENS roles not concentrated in a single person)
Security roles
Management assumes responsibility for information, service and system. The Security Officer (RSEG) is designated separately to strengthen independence in security governance. Named appointments are kept in the internal security file (not published in this version).
Management / Information / Service / System
Designated within the organisation
Security Officer (RSEG)
Separately designated (may be external)
Applicable laws and standards
- Royal Decree 311/2022 (ENS)
- Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD)
- E-invoicing / Verifactu rules applicable to billing services
- Criminal Code provisions on computer-related offences
- Contracts and processor agreements with providers
- Supporting CCN-STIC guides (including 803, 807, 808, 811 and 819)
Conflict resolution
- Documented attempt at agreement between the parties (e.g. RSEG and technical owners).
- If no agreement, escalation to Management.
- Final decision by Management, with written record.
- In case of doubt, the option that best preserves MEDIUM category and PSI principles prevails.
Compliance
Failure to comply with this policy may lead to disciplinary and legal measures under applicable law and internal rules.
Review
This policy is reviewed at least annually, and after serious incidents or significant infrastructure or regulatory changes.