Information Security Policy (not certified translation)
1. APPROVAL AND ENTRY INTO FORCE
2. INTRODUCTION
MBE Legal greatly depends on ICT systems (Information and Communication Technologies) to achieve its objectives. MBE Legal acknowledges that digital transformation has increased the risks affecting information systems that support the provision of services, particularly those related to the public sector, and as a provider to the public sector, it shall appropriately manage these risks.
Risk management aims to protect ICT systems against accidental or intentional events that may compromise the availability, integrity, confidentiality, authenticity, or traceability of information processed by MBE Legal within the services provided to clients in general, and the public sector in particular.
ICT systems shall be protected against rapidly evolving threats that may affect confidentiality, integrity, availability, intended use, and the value of information and services. To defend against these threats, a strategy adaptable to environmental changes is required to ensure continuous service delivery. This includes implementing minimum security measures required under the National Security Framework (ENS), continuously monitoring service levels, tracking vulnerabilities, and preparing effective incident responses.
MBE Legal’s departments shall ensure that ICT security is integrated into every stage of the information system lifecycle —from initial design through to decommissioning— covering development/acquisition decisions and operational activities. Security requirements and budgetary requirements shall be identified and incorporated into planning, requests for proposals, and procurement of ICT projects.
Departments shall be prepared to prevent, detect, respond to, and recover from incidents, in compliance with ENS Article 8.
3. SCOPE
3.1. Subjective Scope
3.2. Objective Scope
4. MINIMUM SECURITY REQUIREMENTS
b) Risk analysis and management (Art. 14 ENS and Art. 21a NIS2)
c) Personnel management and cybersecurity training (Art. 15 ENS and Art. 21g NIS2)
d) Professionalism (Art. 16 ENS and Art. 21j NIS2)
e) Access authorization and control (Art. 17 ENS and Art. 21j NIS2)
f) Facility protection (Art. 18 ENS)
g) Acquisition of security products and contracting of security services (Art. 19 ENS and Art. 21e NIS2)
h) Minimum privilege (Art. 20 ENS)
i) System integrity and updating (Art. 21 ENS)
j) Protection of information at rest and in transit (Art. 22 ENS)
k) Prevention related to interconnected systems (Art. 23 ENS)
l) Activity logging and malware detection (Art. 24 ENS)
m) Security incidents (Art. 25 ENS)
n) Business continuity (Art. 26 ENS and Art. 21c NIS2)
o) Continuous improvement (Art. 27 ENS).
5. BASIC PRINCIPLES
- Security as an integral process: security is a process that encompasses all human, material, technical, legal and organisational elements related to information systems.
- Comprehensive risk-based management: risk analysis and risk treatment are an essential part of the security process and shall be a continuous and constantly updated activity. Risk management will enable the maintenance of a controlled environment, minimising acceptable risks.
- Prevention, detection, response and recovery: Information system security shall include actions relating to prevention, detection and response.
- Existence of lines of defence: MBE Legal's information system shall have a protection strategy consisting of multiple layers of security.
- Continuous monitoring and periodic reassessment: Continuous monitoring will enable the detection of anomalous activities or behaviour and a timely response. Ongoing assessment will enable its evolution to be measured, and security measures will be periodically reassessed and updated, adapting their effectiveness to the evolution of risks and protection systems.
6. INFORMATION SECURITY OBJECTIVES
- Ensuring information protection.
- Physical security: MBE Legal locates information systems in secure areas, protected by physical access controls appropriate to their level of criticality.
- Access control: MBE Legal limits access to information assets by users, processes and other information systems through the implementation of identification, authentication and authorisation mechanisms adapted to the criticality of each asset.
- Acquisition, development and maintenance of information systems: MBE Legal considers security aspects in all phases of the information systems life cycle.
- Ensuring the continued provision of services: MBE Legal implements appropriate procedures to ensure the availability of information systems and maintain the continuity of business processes.
- Data protection: MBE Legal adopts the necessary technical and organisational measures to manage the risks arising from the processing of personal data.
- Compliance: MBE Legal adopts the necessary technical and organisational measures to comply with current legal regulations on information security.
7. MISSION
The mission of MBE Legal (Moreno, Boj & Equipo Legal) is to provide claims management services (TPA), expert legal advice and robust, strategic defence, protecting its clients' interests with the utmost professional rigour, transparency and a clear focus on results. The firm relies on experience, specialisation and teamwork to offer a consistent, effective service that is aligned with the needs of each case.
For MBE Legal, excellence in the provision of legal services is based on a way of working that combines talent and commitment, fostering relationships of trust and continuity in the monitoring of cases, as a guarantee of quality and security for its clients.
8. COMPLIANCE WITH ARTICLES
9. POLICY DEVELOPMENT
- First level: Information Security Policy.
- Second level: Security Regulations.
- Third level: Security Procedures.
10. SECURITY ORGANIZATION
10.1. Security Roles
• Head of Information (HoI): Ignacio Boj Albarracín
• Head of Services (HoS): Ignacio Boj Albarracín
• Head of Security (CISO/RSF): Ignacio Boj Albarracín
• Head of System (HoSy): Javier Moreno Alemán
10.2. Information Security Committee (ISC)
- Chair: Javier Moreno Alemán
• Head of Services
• Head of System
• Head of Security
Optionally, other members of MBE Legal shall join the Committee's work, including specialised working groups, whether internal, external, or mixed.
The Information Security Committee shall hold its meetings at the premises of MBE Legal or remotely every six months, following a call to that effect by the Committee Chair. In any case, the Committee shall hold extraordinary meetings when circumstances so require.
10.3. ENS Responsibilities
● Establish and approve the security requirements applicable to the service and information within the framework set out in Annex II of the ENS, following a proposal to the ENS Security Officer and/or Information Security Committee.
● Accept the residual risk levels affecting the Service and Information.
Duties of Head of Security (CISO/ RSF)
● Maintain and verify the appropriate level of security for the information handled and the electronic services provided by the information systems.
● Manage, supervise, and maintain the physical security of MBE Legal's facilities.
● Promote training and awareness in security matters.
● Appoint those responsible for carrying out risk analysis, the statement of applicability, identifying security measures, determining necessary configurations and preparing system documentation.
● Provide advice on determining the category of the system, in collaboration with the Head of System and/or Information Security Committee.
● Participate in the development and implementation of security improvement plans and, where appropriate, continuity plans, proceeding with their validation.
● Manage external or internal reviews of the system.
● Manage certification processes.
● Submit changes and other system requirements to the Security Committee for approval.
Duties of Head of System
● Restrict or suspend access to information or service provision if it becomes aware that these present serious security deficiencies.
● Implement and manage MBE Legal's Information Systems throughout their life cycle, including the implementation of cybersecurity controls, as well as their operation and verification of their correct functioning.
● Define the topology and management of the Information System, establishing the criteria for use and the services available therein.
● Ensure that specific security measures are properly integrated into the overall security framework.
● Collaborate with the Security Manager to investigate and resolve cyber incidents affecting MBE Legal's Information Systems and apply the knowledge gained from the analysis of cyber incidents that have occurred to reduce the likelihood or impact of future incidents.
● Perform the duties of system security administrator:
✔ Manage authorisations granted to system users, in particular the privileges granted, including the monitoring of activity carried out on the system and its correspondence with what has been authorised.
✔ Approve changes to the current configuration of the Information System.
✔ Ensure that established security controls are strictly complied with.
✔ Ensure that approved procedures for handling the Information System are applied.
✔ Supervise hardware and software installations, modifications and upgrades to ensure that security is not compromised and that they always comply with the relevant authorisations.
✔ Monitor the security status provided by security event management tools and technical audit mechanisms.
✔ When justified by the complexity of the system, the Head of System shall appoint as many deputy system managers as they deem necessary, who will report directly to them and be responsible within their area for all actions delegated to them. Similarly, they shall also delegate specific functions of their responsibilities to others.
The Security Committee shall have the following functions:
● Respond to requests regarding Information Security from the Administration and the various security roles and/or areas, reporting regularly on the status of Information Security.
● Advise on information security matters.
● Resolve conflicts of responsibility that may arise between the different administrative units.
● Promote the continuous improvement of the information security management system. To this end, it shall be responsible to:
✔ Propose plans to improve Information Security, with the corresponding budget allocation, prioritising security measures when resources are limited.
✔ Ensure that information security is considered in all projects from their initial specification to their implementation. It shall ensure the creation and use of horizontal services that reduce duplication and support the uniform operation of all ICT systems.
✔ Monitor the main residual risks assumed by the Administration and recommend possible actions in relation to them.
✔ Monitor the management of security incidents and recommend possible actions to be taken in relation to them.
✔ Develop and regularly review the Information Security Policy for approval by the competent body.
✔ Develop Information Security regulations for approval in coordination with the General Management.
✔ Verify information security procedures and other documentation for approval.
✔ Develop training programmes to educate and raise awareness among staff on Information Security and on the protection of personal data.
✔ Develop and approve training and qualification requirements for administrators, operators and users from an information security perspective.
✔ Promote the performance of periodic ENS and data protection audits to verify compliance with the Administration's information security obligations.
10.4. Designation Procedures
10.5. RACI Matrix
| Tasks | CEO | HoI | HoR | CISO/RSF | ISC |
| Security Policy | A | C | C | R | C |
| Determination of the System category | C | C | A/R | C | |
| Risk Analysis | I | R | A/R | R | |
| Statement of applicability | I | R | A/R | R | |
| IS standards and procedures | I | A/R | R | ||
| Security incident responses | I | I | C | A/R | R |
| Security of the lifecycle of information services and systems | C | A/R | |||
| A: Accountable (makes the decision, authorises and approves) R: Responsible (is responsible for carrying out the work) |
C: Consulted (consulted before decisions are made) I: Informed (informed of decisions made) |
||||
11. CONFLICT RESOLUTION
12. PERSONAL DATA
13. THIRD PARTIES
Such third parties shall be subject to the obligations set out in the aforementioned regulations and shall develop their own operating procedures to comply with them. Specific procedures for communication and incident resolution shall be established. It shall be ensured that third-party personnel are adequately aware of security matters, at least to the same level as that established in this Security Policy.
14. CONTINUOUS IMPROVEMENT
- Review of the Information Security Policy.
- Review of services and information and their categorisation.
- Annual risk analysis.
- Conducting internal and external audits.
- Reviewing security measures.
- Reviewing and updating rules and procedures..
