SECURITY POLICY
Who are we?
Object
RADIOLOGÍA S.A.U. reconoce la importancia crítica de las Tecnologías de la Información y las Comunicaciones (TIC) para el cumplimiento de sus objetivos la venta de productos y la prestación de los servicios. La seguridad de la información se concibe como un proceso integral y continuo, destinado a preservar la confidentiality, integrity, availability, traceability and authenticity of the organization's information and services.
Scope
Esta política es aplicable a todos los empleados y colaboradores de RADIOLOGÍA S.A.U. (la organización) así como al Sistema de Gestión de Seguridad de la Información (SGSI) que da soporte a los procesos y servicios de la entidad y al tratamiento de la información de clientes, empleados y terceros.
Principles
The fundamental principles of the Information Security Policy are:
- Safety as an integral processThe combination of human, technical, organizational and legal factors, promoting the awareness of all professionals.
- Risk-based security managementContinuous assessment and treatment of threats and vulnerabilities, applying measures proportional to the value and criticality of the information.
- Prevention, detection, response and recoveryThe following are some of the key elements: establishment of controls required by the ENS, monitoring mechanisms, detection of deviations and continuity plans.
- Lines of defenseMulti-layered protection (organizational, physical and logical) to mitigate the impact of incidents.
- Continuous monitoring and re-evaluationPeriodic updating of security measures according to technological and risk evolution.
Security Requirements
RADIOLOGÍA S.A.U. aplica medidas en los siguientes ámbitos clave:
- Security governance and organizationClear roles and responsibilities, clear policies and procedures.
- Risk managementPeriodic analysis and mitigation measures.
- Personnel managementSecurity training and awareness-raising.
- Access control and principle of least privilege.
- Physical and logical protection of installations and systems.
- Selection of reliable security products and services.
- System integrity and upgrades.
- Protection of information at rest and in transit.
- Incident management and business continuity.
Legal and Regulatory Framework
The policy aligns with:
- Royal Decree 311/2022, of May 3 (National Security Scheme).
- Regulation (EU) 2016/679 (GDPR).) y Organic Law 3/2028 (LOPDGDD)
- ISO/IEC 27001:2022 Standards and internal safety regulations.
Organizational structure
The security model is articulated through:
- Information Security Committee
- Responsible for the information
- Responsible for the Service
- Security Manager
- System Manager
- Data Protection Delegate.
The Security Manager is the single point of contact for security matters for the entire organization in case any additional information is required.
Risk management
All systems subject to this policy must undergo risk assessment on a regular basis (at least annually or after significant changes), under the coordination of the Security Committee. This Committee shall establish homogeneous criteria and promote the necessary resources to maintain adequate security levels.
Commitment to Continuous Improvement
RADIOLOGÍA maintains a constant commitment to the resilience of its systems, ICT security training and awareness, agile response to incidents, collaboration with the competent authorities and continuous updating of its management model and security controls.
Documentation and control
The ISMS is organized hierarchically in an Information Security Policy, internal rules and procedures, and technical manuals with their corresponding records, whose documentation is managed in accordance with the Documentation Control procedure to ensure its correct approval, review, classification, accessibility and distribution.
Obligations of users
Todos los empleados de RADIOLOGÍA S.A.U. deben:
- Know and comply with the Security Policy and the Information Security Manual.
- Participate in annual training and awareness sessions.
- Report security incidents to the Security Manager.
- Use technological resources in accordance with established standards.
Relations with third parties
Cuando la organización RADIOLOGÍA S.A.U. preste o reciba servicios que impliquen el tratamiento de información, los contratos incluirán cláusulas específicas sobre seguridad, reporte de incidentes y responsabilidades. Los terceros deberán cumplir los mismos niveles de seguridad y formar a su personal de forma equivalente a los estándares de la organización.
Approval and validity
This policy, of a public nature, was approved by the General Management on November 11, 2025, and will be reviewed annually by the Information Security Committee or earlier if significant changes occur.