{"id":4325,"date":"2026-02-03T09:17:12","date_gmt":"2026-02-03T08:17:12","guid":{"rendered":"https:\/\/newrad.radiologia-sa.com\/?page_id=4325"},"modified":"2026-02-13T08:04:43","modified_gmt":"2026-02-13T07:04:43","slug":"politica-de-seguridad","status":"publish","type":"page","link":"https:\/\/newrad.radiologia-sa.com\/en\/politica-de-seguridad\/","title":{"rendered":"SECURITY POLICY"},"content":{"rendered":"<div data-elementor-type=\"wp-page\" data-elementor-id=\"4325\" class=\"elementor elementor-4325\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2d59f558 e-flex e-con-boxed e-con e-parent\" data-id=\"2d59f558\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;shape_divider_bottom&quot;:&quot;arrow&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-shape elementor-shape-bottom\" aria-hidden=\"true\" data-negative=\"false\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewbox=\"0 0 700 10\" preserveaspectratio=\"none\">\n\t<path class=\"elementor-shape-fill\" d=\"M350,10L340,0h20L350,10z\"\/>\n<\/svg>\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6623c50 elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"6623c50\" data-element_type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">SECURITY POLICY<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6d9f252 animated-slow elementor-hidden-desktop elementor-hidden-tablet elementor-hidden-mobile elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"6d9f252\" data-element_type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Who are we?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-572b9d8a e-flex e-con-boxed e-con e-parent\" data-id=\"572b9d8a\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6ad25dba sci-fi-border bottom elementor-widget elementor-widget-text-editor\" data-id=\"6ad25dba\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2><strong>Object<\/strong><\/h2><p>RADIOLOG\u00cdA S.A. recognizes the critical importance of Information and Communication Technologies (ICT) for the fulfillment of its objectives, the sale of products and the provision of services. Information security is conceived as an integral and continuous process, aimed at preserving the security of information. <strong>confidentiality, integrity, availability, traceability and authenticity<\/strong> of the organization's information and services.<\/p><h2><a name=\"_Toc213830187\"><\/a><strong>Scope<\/strong><\/h2><p>This policy is applicable to all employees and collaborators of RADIOLOG\u00cdA S.A. (the organization) as well as to the Information Security Management System (ISMS) that supports the processes and services of the entity and the processing of customer, employee and third party information.<\/p><h2><a name=\"_Toc213830188\"><\/a><strong>Principles<\/strong><\/h2><p>The fundamental principles of the Information Security Policy are:<\/p><ol><li><strong>Safety as an integral process<\/strong>The combination of human, technical, organizational and legal factors, promoting the awareness of all professionals.<\/li><li><strong>Risk-based security management<\/strong>Continuous assessment and treatment of threats and vulnerabilities, applying measures proportional to the value and criticality of the information.<\/li><li><strong>Prevention, detection, response and recovery<\/strong>The following are some of the key elements: establishment of controls required by the ENS, monitoring mechanisms, detection of deviations and continuity plans.<\/li><li><strong>Lines of defense<\/strong>Multi-layered protection (organizational, physical and logical) to mitigate the impact of incidents.<\/li><li><strong>Continuous monitoring and re-evaluation<\/strong>Periodic updating of security measures according to technological and risk evolution.<\/li><\/ol><h2><a name=\"_Toc213830189\"><\/a><strong>Security Requirements<\/strong><\/h2><p>RADIOLOG\u00cdA S.A. applies measures in the following key areas:<\/p><ul><li><strong>Security governance and organization<\/strong>Clear roles and responsibilities, clear policies and procedures.<\/li><li><strong>Risk management<\/strong>Periodic analysis and mitigation measures.<\/li><li><strong>Personnel management<\/strong>Security training and awareness-raising.<\/li><li><strong>Access control and principle of least privilege<\/strong>.<\/li><li><strong>Physical and logical protection of installations and systems<\/strong>.<\/li><li><strong>Selection of reliable security products and services<\/strong>.<\/li><li><strong>System integrity and upgrades<\/strong>.<\/li><li><strong>Protection of information at rest and in transit<\/strong>.<\/li><li><strong>Incident management and business continuity<\/strong>.<\/li><\/ul><h2><a name=\"_Toc213830190\"><\/a><strong>Legal and Regulatory Framework<\/strong><\/h2><p>The policy aligns with:<\/p><ul><li><strong>Royal Decree 311\/2022<\/strong>, of May 3 (National Security Scheme).<\/li><li><strong>Regulation (EU) 2016\/679 (GDPR).<\/strong>) y<strong> Organic Law 3\/2028 (LOPDGDD)<\/strong><\/li><li><strong>ISO\/IEC 27001:2022 Standards<\/strong> and internal safety regulations.<\/li><\/ul><h2><a name=\"_Toc213830191\"><\/a><strong>Organizational structure<\/strong><\/h2><p>The security model is articulated through:<\/p><ul><li>Information Security Committee<\/li><li>Responsible for the information<\/li><li>Responsible for the Service<\/li><li>Security Manager<\/li><li>System Manager<\/li><li>Data Protection Delegate.<\/li><\/ul><p>The Security Manager is the single point of contact for security matters for the entire organization in case any additional information is required.<\/p><h2><a name=\"_Toc213830192\"><\/a><strong>Risk management <\/strong><\/h2><p>All systems subject to this policy must undergo risk assessment on a regular basis (at least annually or after significant changes), under the coordination of the Security Committee. This Committee shall establish homogeneous criteria and promote the necessary resources to maintain adequate security levels.<\/p><h2><a name=\"_Toc213830193\"><\/a><strong>Commitment to Continuous Improvement<\/strong><\/h2><p>RADIOLOG\u00cdA maintains a constant commitment to the resilience of its systems, ICT security training and awareness, agile response to incidents, collaboration with the competent authorities and continuous updating of its management model and security controls.<\/p><h2><a name=\"_Toc213830194\"><\/a><strong>Documentation and control<\/strong><\/h2><p>The ISMS is organized hierarchically in an Information Security Policy, internal rules and procedures, and technical manuals with their corresponding records, whose documentation is managed in accordance with the Documentation Control procedure to ensure its correct approval, review, classification, accessibility and distribution.<\/p><h2><a name=\"_Toc213830195\"><\/a><strong>Obligations of users <\/strong><\/h2><p>All employees of RADIOLOG\u00cdA S.A. must:<\/p><ul><li>Know and comply with the Security Policy and the Information Security Manual.<\/li><li>Participate in annual training and awareness sessions.<\/li><li>Report security incidents to the Security Manager.<\/li><li>Use technological resources in accordance with established standards.<\/li><\/ul><h2><a name=\"_Toc213830196\"><\/a><strong>Relations with third parties <\/strong><\/h2><p>When the RADIOLOG\u00cdA organization provides or receives services involving the processing of information, contracts shall include specific clauses on security, incident reporting and responsibilities. Third parties shall comply with the same security levels and train their personnel in a manner equivalent to the standards of the organization.<\/p><h2><a name=\"_Toc213830197\"><\/a><strong>Approval and validity <\/strong><\/h2><p>This policy, of a public nature, was approved by the General Management on November 11, 2025, and will be reviewed annually by the Information Security Committee or earlier if significant changes occur.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>SECURITY POLICY Who are we? Purpose RADIOLOG\u00cdA S.A. recognizes the critical importance of Information and Communication Technologies (ICT) for the fulfillment of its objectives, the sale of products and the provision of services. Information security is conceived as an integral and continuous process, aimed at preserving the confidentiality of information and [...]<\/p>","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-4325","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/pages\/4325","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/comments?post=4325"}],"version-history":[{"count":7,"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/pages\/4325\/revisions"}],"predecessor-version":[{"id":4456,"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/pages\/4325\/revisions\/4456"}],"wp:attachment":[{"href":"https:\/\/newrad.radiologia-sa.com\/en\/wp-json\/wp\/v2\/media?parent=4325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}