SECURITY POLICY
Who are we?
Object
RADIOLOGÍA S.A. recognizes the critical importance of Information and Communication Technologies (ICT) for the fulfillment of its objectives, the sale of products and the provision of services. Information security is conceived as an integral and continuous process, aimed at preserving the security of information. confidentiality, integrity, availability, traceability and authenticity of the organization's information and services.
Scope
This policy is applicable to all employees and collaborators of RADIOLOGÍA S.A. (the organization) as well as to the Information Security Management System (ISMS) that supports the processes and services of the entity and the processing of customer, employee and third party information.
Principles
The fundamental principles of the Information Security Policy are:
- Safety as an integral processThe combination of human, technical, organizational and legal factors, promoting the awareness of all professionals.
- Risk-based security managementContinuous assessment and treatment of threats and vulnerabilities, applying measures proportional to the value and criticality of the information.
- Prevention, detection, response and recoveryThe following are some of the key elements: establishment of controls required by the ENS, monitoring mechanisms, detection of deviations and continuity plans.
- Lines of defenseMulti-layered protection (organizational, physical and logical) to mitigate the impact of incidents.
- Continuous monitoring and re-evaluationPeriodic updating of security measures according to technological and risk evolution.
Security Requirements
RADIOLOGÍA S.A. applies measures in the following key areas:
- Security governance and organizationClear roles and responsibilities, clear policies and procedures.
- Risk managementPeriodic analysis and mitigation measures.
- Personnel managementSecurity training and awareness-raising.
- Access control and principle of least privilege.
- Physical and logical protection of installations and systems.
- Selection of reliable security products and services.
- System integrity and upgrades.
- Protection of information at rest and in transit.
- Incident management and business continuity.
Legal and Regulatory Framework
The policy aligns with:
- Royal Decree 311/2022, of May 3 (National Security Scheme).
- Regulation (EU) 2016/679 (GDPR).) y Organic Law 3/2028 (LOPDGDD)
- ISO/IEC 27001:2022 Standards and internal safety regulations.
Organizational structure
The security model is articulated through:
- Information Security Committee
- Responsible for the information
- Responsible for the Service
- Security Manager
- System Manager
- Data Protection Delegate.
The Security Manager is the single point of contact for security matters for the entire organization in case any additional information is required.
Risk management
All systems subject to this policy must undergo risk assessment on a regular basis (at least annually or after significant changes), under the coordination of the Security Committee. This Committee shall establish homogeneous criteria and promote the necessary resources to maintain adequate security levels.
Commitment to Continuous Improvement
RADIOLOGÍA maintains a constant commitment to the resilience of its systems, ICT security training and awareness, agile response to incidents, collaboration with the competent authorities and continuous updating of its management model and security controls.
Documentation and control
The ISMS is organized hierarchically in an Information Security Policy, internal rules and procedures, and technical manuals with their corresponding records, whose documentation is managed in accordance with the Documentation Control procedure to ensure its correct approval, review, classification, accessibility and distribution.
Obligations of users
All employees of RADIOLOGÍA S.A. must:
- Know and comply with the Security Policy and the Information Security Manual.
- Participate in annual training and awareness sessions.
- Report security incidents to the Security Manager.
- Use technological resources in accordance with established standards.
Relations with third parties
When the RADIOLOGÍA organization provides or receives services involving the processing of information, contracts shall include specific clauses on security, incident reporting and responsibilities. Third parties shall comply with the same security levels and train their personnel in a manner equivalent to the standards of the organization.
Approval and validity
This policy, of a public nature, was approved by the General Management on November 11, 2025, and will be reviewed annually by the Information Security Committee or earlier if significant changes occur.