{"id":83321,"date":"2025-11-07T18:02:22","date_gmt":"2025-11-07T17:02:22","guid":{"rendered":"https:\/\/dbus.eus\/?page_id=83321"},"modified":"2025-12-11T14:44:28","modified_gmt":"2025-12-11T13:44:28","slug":"information-security-policy","status":"publish","type":"page","link":"https:\/\/dbus.eus\/en\/information-security-policy\/","title":{"rendered":"Information security policy"},"content":{"rendered":"<h2><span style=\"color: #72bf44;\">1. Introduction<\/span><\/h2>\n<p>San Sebasti\u00e1n Tram Company (hereinafter, CTSS or Dbus) recognises the importance of information security for the effective performance of its operations. For this reason, it has developed this Information Security Policy (hereinafter, ISP), which establishes and integrates the basic security principles with the operational requirements of confidentiality, integrity, availability, authenticity, and traceability of information.<\/p>\n<h2><span style=\"color: #72bf44;\">2. Scope of application<\/span><\/h2>\n<p>This ISP applies to all Dbus employees. The scope also includes personnel and third-party organisations that temporarily or permanently provide services or have access to information or assets related to Dbus by virtue of their duties or the fulfilment of a contractual agreement.<\/p>\n<p>It is therefore necessary for all individuals who interact, either directly or indirectly, with Dbus and its affiliated business units to be familiar with the relevant Information Security Policy and regulations, and to apply their guidelines as an integral part of their duties in relation to Dbus.<\/p>\n<h2><span style=\"color: #72bf44;\">3. Dbus&#8217;s mission<\/span><\/h2>\n<p>Dbus provides the public passenger transport service in the city of San Sebasti\u00e1n.<\/p>\n<p>Its fundamental mission is to fully satisfy current and future passengers\u2019 mobility needs by offering high-quality services, practical information, and competitive fares, while also contributing to the sustainability of our environment.<\/p>\n<p>Its vision includes the ambition to be a leader in mobility within San Sebasti\u00e1n. This is achieved through various initiatives to enhance the public\u2019s perception of the company, with the objective of being a socially active, responsible, and committed organisation dedicated to the development of the city, society, the environment, our customers, our staff, and all other stakeholders.<\/p>\n<h2><span style=\"color: #72bf44;\">4. Regulatory and normative reference<\/span><\/h2>\n<p>Dbus&#8217;s ISP has been defined to comply with current legislation and regulations on information processing and to conform to the requirements established by <strong>Royal Decree 311\/2022, of 3 May, which regulates the National Security Framework<\/strong> (hereinafter, <strong>NSF<\/strong>), along with all implementing and supplementary regulations.<\/p>\n<p>Below is a list of the main laws and regulations in force as of the date this document was drafted. Although this ISP aims for a global scope, it must be adapted to comply with the regulatory requirements of each jurisdiction. From the perspective of Spanish jurisdiction, these are as follows:<\/p>\n<style>\n  ul.spaced li {\n    margin-bottom: 1em; \/* espacio entre cada \u00edtem *\/\n  }\n<\/style>\n<ul class=\"spaced\">\n<li>Royal Decree 311\/2022, of 3 May, regulating the National Security Framework.<\/li>\n<li>Resolution of 13 October 2016, of the State Secretariat of Public Administrations, approving the Technical Security Instruction in accordance with the National Security Framework.<\/li>\n<li>Resolution of 7 October 2016, of the State Secretariat of Public Administrations, approving the Technical Security Instruction for Reporting on the State of Security.<\/li>\n<li>Resolution of 27 March 2018, of the State Secretariat of the Civil Service, approving the Technical Security Instruction for Auditing Information Systems Security.<\/li>\n<li>Resolution of 13 April 2018, of the State Secretariat of the Civil Service, approving the Technical Security Instruction for Notifying Security Incidents.<\/li>\n<\/ul>\n<p>Personal data protection:<\/p>\n<ul class=\"spaced\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, which repeals Directive 95\/46\/EC (General Data Protection Regulation, GDPR).<\/li>\n<li>Act 3\/2018, of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).<\/li>\n<li>Act 16\/2023, of 21 December, on the Basque Data Protection Authority (hereinafter, LAVPD).<\/li>\n<\/ul>\n<p>Others:<\/p>\n<ul class=\"spaced\">\n<li>Directive (EU) 2022\/2555 of the European Parliament and of the Council, of 14 December 2022, on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910\/2014 and Directive (EU) 2018\/1972, and repealing Directive (EU) 2016\/1148 (NIS 2 Directive).<\/li>\n<li>Act 34\/2002, of 11 July, on information society and e-commerce services.<\/li>\n<li>Act 37\/2007, of 16 November, on the reuse of public sector information.<\/li>\n<li>Act 56\/2007, of 28 December, on measures to promote the information society.<\/li>\n<\/ul>\n<p>The current regulations governing Dbus\u2019s activities within its areas of competence, aimed at ensuring information security and protecting personal data, will also apply.<\/p>\n<p>The following document includes a comprehensive list of security regulations and standards applicable at Dbus: <strong>RN8.14-5-01 Regulatory and normative framework applicable to Dbus.<\/strong><\/p>\n<h2><span style=\"color: #72bf44;\">5. Basic principles<\/span><\/h2>\n<p>Dbus sets out the following fundamental principles, which will form the basis for all activities related to its information security:<\/p>\n<style>\n  ol.alfa {\n    list-style-type: none;\n    counter-reset: item;\n  }\n  ol.alfa li {\n    counter-increment: item;\n    margin-bottom: 1em;\n  }\n  ol.alfa li::before {\n    content: counter(item, lower-alpha) \") \";\n    font-weight: bold;\n  }\n<\/style>\n<ol class=\"alfa\">\n<li><strong>Security as a holistic process<\/strong> formed by all human, material, technical, legal, and organisational elements related to information assets. Maximum attention will also be given to raising awareness among all personnel involved in the security process in order to prevent exposure to information security risks.<\/li>\n<li><strong>Security by default and by design:<\/strong> security aspects will be considered in all phases of the information systems lifecycle, ensuring security by default. Security must be regarded as part of routine operations and must therefore be present and initially applied from the design stage of information systems.<\/li>\n<li><strong>Proportionality:<\/strong> the establishment of measures will proportionally reflect their economic and operational costs relative to the potential risks, criticality, and the value of the information and its services.<\/li>\n<li><strong>Compliance with legal and contractual requirements<\/strong> applicable to Dbus\u2019s information and information systems.<\/li>\n<li><strong>Risk-based security management<\/strong> as an ongoing and iterative activity. This management will reduce risks to acceptable levels by implementing security controls that are balanced and proportionate to the criticality of the information assets and their exposure to risks.<\/li>\n<li><strong>Prevention, detection, response, and recovery:<\/strong> measures will be established to reduce the likelihood of threats to information assets materialising into negative impacts and, if they do occur, to manage them promptly and adequately in order to avoid seriously affecting their confidential nature, integrity, availability, authenticity, and traceability.<\/li>\n<li><strong>Existence of lines of defence:<\/strong> composed of multiple security layers to ensure that compromising one layer does not compromise the entire information system or minimises the final impact. The lines of defence include organisational, physical, and logical measures.<\/li>\n<li><strong>Continuous monitoring and periodic reevaluation:<\/strong> in order to detect abnormal activities or behaviours and respond to them in a timely manner, along with ongoing assessments of security status and periodic updating of all measures applied.<\/li>\n<li><strong>Differentiation of responsibilities:<\/strong> in information systems, distinguishing between the asset owner, the Head of Information Security, and the System Manager. This includes separating responsibility for information system security from responsibility for operational management.<\/li>\n<li><strong>Principle of awareness and training:<\/strong> every user and administrator of the systems must be aware of and trained in the correct use of systems and information.<\/li>\n<li><strong>Professional secrecy:<\/strong> anyone processing personal data or accessing information not officially classified as public must keep such data or information confidential, even after their activities related to the organisation have ended.<\/li>\n<\/ol>\n<h2><span style=\"color: #72bf44;\">6. Minimum information security requirements<\/span><\/h2>\n<p>For the effective application of this ISP and its implementing regulations, Dbus will provide the necessary resources to ensure correct implementation and maintenance, including the controls or security measures established in each area. Likewise, Dbus commits to meeting the following minimum information security requirements.<\/p>\n<p><strong>a) Organisation and implementation of the security process:<\/strong><\/p>\n<style>\n  ol.romanos {\n    list-style-type: lower-roman;\n  }\n  ol.romanos li {\n    margin-bottom: 1em;\n  }\n  ol.romanos-sub li {\n    margin-bottom: 0.8em;\n  }\n<\/style>\n<ol type=\"i\" class=\"romanos\">\n<li>Information system security must involve all individuals within the organisation (both internal and external) who participate in activities within the scope of the ISP.<\/li>\n<li>The roles of Head of Information, Head of Service, Chief Information Security Officer (CISO), and System Manager will be unequivocally identified, with clear assignment of responsibilities, segregation of duties and hierarchical organisation, in accordance with the provisions of the NSF.<\/li>\n<li>Appointments will be communicated to all individuals who are part of the organisation.<\/li>\n<li>External organisations providing services to Dbus will designate points of contact for information security. This responsibility must be taken on by the CISO of the external organisation or an associated figure.<\/li>\n<li>Certification of Security Officer roles is mandatory whenever required by law.<\/li>\n<\/ol>\n<p><strong>b) Asset control:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Information assets will be inventoried and categorised according to their characteristics and required security level.<\/li>\n<li>All security measures applied to assets will consider their categorisation.<\/li>\n<\/ol>\n<p><strong>c) Analysis and risk management:<\/strong><\/p>\n<ol class=\"romanos\">\n<li>All information systems within the scope of this ISP must undergo a risk management process that follows an internationally recognised and appropriate methodology for each area.<\/li>\n<li>The information security risk management process must be conducted continuously in accordance with NSF provisions.<\/li>\n<li>\n    In line with the above, this analysis will be repeated in full or in part:<\/p>\n<ol type=\"i\" style=\"list-style-type: lower-roman !important;\">\n<li>Regularly, at least once a year.<\/li>\n<li>Whenever the information handled or the services in question change.<\/li>\n<li>Whenever a serious security incident occurs and\/or serious vulnerabilities are reported.<\/li>\n<\/ol>\n<\/li>\n<li>Measures applied as a result of analyses must be justified and proportionate to the risks. Risk treatment plans must be approved as appropriate by the System Manager and the Head of Security.<\/li>\n<\/ol>\n<p><strong>d) Personnel management:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>All personnel, both internal and external, who use the information systems supporting Dbus services or participate in personal data processing must receive training and be informed of their duties, obligations, and responsibilities regarding information security.<\/li>\n<li>Obligations and responsibilities in these areas will be established in internal regulations approved by the Information Security Committee. Compliance with the regulations will be supervised.<\/li>\n<li>Activities will be developed with a view to ensuring training and awareness among personnel in the areas covered by this ISP.<\/li>\n<\/ol>\n<p><strong>e) Professionalism:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>System security will be implemented, maintained, reviewed, and audited by qualified and trained personnel, who will participate in all phases of the system lifecycle.<\/li>\n<\/ol>\n<p><strong>f) Authorisation and access control:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Access to the information assets within the scope of the ISP must be restricted to duly authorised users, processes, devices, or other information systems, and limited exclusively to authorised functions.<\/li>\n<li>Access to customer information will be segregated and restricted to authorised personnel, ensuring that the information is not disclosed without the required authorisation and appropriate controls.<\/li>\n<\/ol>\n<p><strong>g) Protection of facilities:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Information assets must remain in areas with a level of control and access mechanisms that are appropriate and proportional to the identified risks.<\/li>\n<\/ol>\n<p><strong>h) Acquisition of security products and contracting of security services:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Products and services will be selected based on the level of risk associated with the assets to be protected and the required security level, ensuring they have certified security features relevant to their intended use or, if not, that they meet the established quality standards.<\/li>\n<\/ol>\n<p><strong>i) Minimum privilege:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Systems will be designed and configured to provide only the essential functionalities necessary to achieve their objectives, with access to administration and monitoring functions and resources being particularly restricted.<\/li>\n<\/ol>\n<p><strong>j) Integrity and updating of information systems:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>The development and maintenance of information systems will be accompanied by security specifications.<\/li>\n<li>Change management, configuration, and system update processes will be implemented following an authorisation procedure to ensure system integrity and address any vulnerabilities.<\/li>\n<\/ol>\n<p><strong>k) Protection of stored and in-transit information:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Measures will be implemented to maintain the required security level for information that is stored or in transit on devices such as laptops, mobile devices, peripherals, and storage media, including communications across public networks.<\/li>\n<li>The stipulated security level will also be maintained for physical documentation derived from catalogued digital information.<\/li>\n<\/ol>\n<p><strong>l) Prevention concerning other interconnected information systems:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Interconnections with systems outside Dbus\u2019s control will be analysed, especially if connected through public networks, and risks will be mitigated by applying appropriate measures according to applicable regulations and best practices.<\/li>\n<\/ol>\n<p><strong>m) Activity logging and malicious code detection:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>User activity will be logged, retaining only that information strictly necessary to monitor, analyse, investigate, and manage illicit or risk situations affecting information asset security and the rights of affected individuals. To ensure this task is carried out correctly, single-user access will be established wherever possible.<\/li>\n<\/ol>\n<p><strong>n) Security incidents and personal data security breaches:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Comprehensive procedures will be implemented to manage information security and personal data incidents, incorporating classification criteria, stakeholder notification and communication protocols, defined activities for each incident management phase, application of detection, containment, response, and recovery measures, as well as maintenance of incident records to support ongoing process improvement.<\/li>\n<li>These procedures will be defined, without limitation, in accordance with all applicable provisions of the NSF, the NSF Technical Security Instruction for Notification of Incidents, the National Cyber Incident Management and Notification Guide, and the CCN-STIC 817 Cyber Incident Management Guide. Additionally, the internal security breach management procedure defined and implemented by Dbus in compliance with the GDPR will be taken into account.<\/li>\n<li>The process will involve incident management through single-window solutions, the participation of key security bodies and roles, and, where appropriate (based on incident classification), notification to Computer Security Incident Response Teams (hereinafter, <strong>CSIRT<\/strong>), competent supervisory authorities, and affected users.<\/li>\n<\/ol>\n<p><strong>o) Continuity of activity:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Recovery measures will be implemented, and plans defined to ensure operational continuity in the event of disruptive incidents.<\/li>\n<\/ol>\n<p><strong>p) Audit and continuous improvement of processes:<\/strong><\/p>\n<ol type=\"i\" class=\"romanos\">\n<li>Security management processes will be continuously updated and improved, incorporating regulatory changes and industry best practices.<\/li>\n<li>Information systems will undergo regular audits, at least annually, to verify compliance with this ISP and applicable regulatory requirements.<\/li>\n<li>Extraordinary audits will be conducted whenever substantial changes occur in the services provided or in the scope of personal data processing, or a serious security incident or non-compliance arises.<\/li>\n<li>Audits will be supervised by the CISO.<\/li>\n<\/ol>\n<h2><span style=\"color: #72bf44;\">7. Personal data<\/span><\/h2>\n<p>Dbus requires personal data in order to carry out its functions. It collects such data only when they are adequate, relevant, and not excessive, and when they are related to the scope and purposes for which they were obtained.<\/p>\n<p>Dbus also adopts the necessary technical and organisational measures to comply with the applicable data protection regulations in each case.<\/p>\n<p>The data controllers will be responsible for documenting and maintaining the record of personal data processing activities up to date, in accordance with Article 30 of the GDPR.<\/p>\n<h2><span style=\"color: #72bf44;\">8. Organisation of information security<\/span><\/h2>\n<p>Information security is organised at Dbus in accordance with the committee and role structure detailed below.<\/p>\n<h3><span style=\"color: #72bf44;\">8.1 Committee structure for the management and coordination of security<\/span><\/h3>\n<table style=\"border-collapse:collapse;margin:8px 0;\">\n<tr style=\"background-color:#72bf44; color:#fff;\">\n<td style=\"border:1px solid #444;padding:6px;\">Committee<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Description<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Management Committee<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      The Management Committee serves as Dbus\u2019s primary body for strategic and governance decision-making and assumes specific responsibilities in information security, a critical business function.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Information Security Committee (ISC)<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      The ISC coordinates information security within the organisation, ensuring the protection of information assets and services, and facilitating the integration and coordination of all related measures.\n    <\/td>\n<\/tr>\n<\/table>\n<p>The functions and composition of these committees are defined in the document <strong>RN5-02 Roles and Responsibilities of the IS.<\/strong><\/p>\n<h3><span style=\"color: #72bf44;\">8.2 Roles and security functions<\/span><\/h3>\n<table style=\"border-collapse:collapse;margin:8px 0;\">\n<tr style=\"background-color:#72bf44; color:#fff;\">\n<td style=\"border:1px solid #444;padding:6px;\">Role<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Description<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Managing Director<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Ultimately responsible for the organisation, and, therefore, for maintaining the organisation\u2019s information security. Commits to providing the necessary resources for the development of information security functions and compliance with this policy.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Head of Service<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Functional business managers with sufficient authority to make decisions regarding the services provided under their responsibility, and to determine the applicable security requirements.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Head of Information<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Functional business managers with sufficient authority to make decisions regarding the processing of their information and to determine the applicable security requirements.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Chief Information Security Officer (CISO)<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Responsible for defining and overseeing Dbus\u2019s information security strategy in order to fulfil the security requirements set by the Heads of Service and Information, based on this information security policy. Is also assigned with responsibility for leading the Information Security Management System.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>ICT Security Office (ICTSO)<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Team reporting to the CISO, responsible for the operational management of the Security Implementation Plan; operation and maintenance; analysis and discussion of issues related to the security of information systems within its scope of competence; and the drafting and submitting of proposals to the ISC.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Security Operations Centre (SOC)<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Team reporting to the CISO, responsible for monitoring and overseeing the organisation\u2019s information security during normal system operation.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Head of Systems<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Develops, operates, and maintains information systems, defines their architecture and management, adheres to security measures determined by the CISO, and helps develop security procedures and plans.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Data Protection Officer<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Ensures appropriate application of data protection regulations by providing advice, continuously monitoring compliance, and cooperating with the relevant supervisory authority.\n    <\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Systems Administrator<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">\n      Member of the organisational structure, appointed by and working under the supervision of the Head of Systems.\n    <\/td>\n<\/tr>\n<\/table>\n<p>The functions of these roles are defined in the document <strong>RN5-02 Roles and Responsibilities of the IS.<\/strong><\/p>\n<h3><span style=\"color: #72bf44;\">8.3 Appointment and renewal procedure<\/span><\/h3>\n<p>The formation of the Information Security Committee, the appointment of its members, and the designation of the key responsible individuals identified in this ISP have been approved by the Managing Director and communicated to all relevant stakeholders.<\/p>\n<p>This same body may review the appointments of Information Security Committee members and other roles considered by the ISP when deemed appropriate or upon vacancy.<\/p>\n<h3><span style=\"color: #72bf44;\">8.4 Conflict resolution<\/span><\/h3>\n<p>The Information Security Committee will resolve any conflicts and\/or differences of opinion arising among the roles considered by the ISP.<\/p>\n<h2><span style=\"color: #72bf44;\">9. Regulatory framework<\/span><\/h2>\n<p>Dbus designs, maintains, and promotes a regulatory framework applicable to the field of information security, as well as to executive and management bodies, employees, and external suppliers. The regulatory framework is structured across five levels, each with distinct scopes, degrees of technical detail and binding nature, with each element based on or aligned with higher-level standards:<\/p>\n<ul style=\"list-style-type: disc; padding-left: 20px; margin: 0;\">\n<li style=\"margin-bottom: 12px;\"><strong>Normative level one:<\/strong> the Information Security Policy.<\/li>\n<li style=\"margin-bottom: 12px;\"><strong>Normative level two:<\/strong> information security standards and specific policies. These are mandatory throughout Dbus. Establishes the obligations and rules to follow regarding the security process covered by each standard.<\/li>\n<li style=\"margin-bottom: 12px;\"><strong>Normative level three:<\/strong> procedures related to specific security processes and applicable across the whole organisation. Assigns responsibilities relevant to the process and describes the actions required to comply with the security measures established in the higher normative level.<\/li>\n<li style=\"margin-bottom: 12px;\"><strong>Normative level four:<\/strong> specific guidelines and instructions. Describes the actions required to comply with a specific security procedure, assign responsibility to an organisational unit or within a workplace, and relate these actions to a specific asset.<\/li>\n<li><strong>Normative level five:<\/strong> reports, records, electronic evidence, and templates. Reports are technical documents that record the results and conclusions of a study or evaluation. Security activity logs and alerts are technical records that document threats and vulnerabilities to information systems, falling under the responsibility of the security team. Electronic evidence is generated throughout the lifecycle of information systems and may cover one or more systems depending on the aspect addressed.<\/li>\n<\/ul>\n<p>The Information Security Committee will establish the necessary mechanisms to share documentation derived from regulatory development, standardising it as far as possible throughout the scope of this policy.<\/p>\n<p>The following table summarises the regulatory framework and responsibility for its proposal, review, and approval.<\/p>\n<table style=\"border-collapse:collapse;margin:8px 0;\">\n<tr style=\"background-color:#72bf44; color:#fff;\">\n<td style=\"border:1px solid #444;padding:6px;\">Normative level<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Document<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Proposed by<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Reviewed by<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Approved by<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>One<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Information Security Policy<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">CISO<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Information Security Committee<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Management Committee<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\"><strong>Two<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Security standards and specific policies<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">CISO<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Head of Systems (at Dbus), Service or Process<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Information Security Committee<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" style=\"border:1px solid #444;padding:6px;\"><strong>Three<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">General information security procedures<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">ICT Security Office<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Head of Systems (at Dbus)<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">CISO<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\">General procedures<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Operational personnel and specialists<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">CISO<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Head of Systems (at Dbus), Service or Process<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" style=\"border:1px solid #444;padding:6px;\"><strong>Four<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Information security guidelines and technical instructions<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">ICT Security Office<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Head of Systems (at Dbus), Service or Process<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">CISO<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\">General technical guidelines and instructions<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Operational personnel and specialists<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">CISO<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Head of Systems (at Dbus), Service or Process<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" style=\"border:1px solid #444;padding:6px;\"><strong>Five<\/strong><\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Reports, records, evidence, and templates for information security processes<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Security providers, ICT Security Office<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">ICT\/CISO Security Office<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">&#8211;<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #444;padding:6px;\">Reports, records, evidence, and templates for IT processes<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">IT suppliers, Operational personnel and specialists<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">Head of Systems (at Dbus), Service or Process<\/td>\n<td style=\"border:1px solid #444;padding:6px;\">&#8211;<\/td>\n<\/tr>\n<\/table>\n<h2><span style=\"color: #72bf44;\">10. Management of exceptions<\/span><\/h2>\n<p>If a user is unable to comply with the obligations set out in this ISP or the associated regulations, they should immediately write to <span style=\"cursor: pointer; color: #72bf44;\" onclick=\"location.href='mailto:' + ['ciso','dbus.eus'].join('@')\">ciso<span>@<\/span>dbus.eus<\/span> in order to manage their application. Otherwise, they must stop using Dbus&#8217;s ICT services and information.<\/p>\n<h2><span style=\"color: #72bf44;\">11. Control and supervision activities<\/span><\/h2>\n<p>Within the scope of its powers, Dbus has the authority to self-organise, direct, and control information security, as well as to regulate and oversee the use of company-owned IT devices; it also reserves the corporate power to monitor and ensure compliance with obligations related to the use of these devices, always while fully respecting fundamental rights, the right to data protection where personal data is processed, and the principles of necessity and proportionality.<\/p>\n<p>Firstly, the principle of necessity requires that any restriction be specifically justified, obliging the party seeking to implement it to demonstrate that the legitimate objective cannot be achieved by any reasonable means that reconcile the employee\u2019s interests with those of the organisation.<\/p>\n<p>Secondly, the principle of proportionality requires that the restrictive measure of fundamental rights must pass the \u201ctriple test\u201d, i.e. assessing whether the control measure:<\/p>\n<ul style=\"list-style-type: disc; padding-left: 20px; margin: 0;\">\n<li style=\"margin-bottom: 12px;\">Is capable of achieving the proposed objective (suitability test).<\/li>\n<li style=\"margin-bottom: 12px;\">Is necessary, in the sense that no other, more moderate measure exists to achieve that purpose with equal effectiveness (necessity test).<\/li>\n<li>Is balanced or proportionate, as it brings greater benefits or advantages for the public interest than the harm caused to other conflicting goods or values (strict proportionality test).<\/li>\n<\/ul>\n<p>Dbus will inform employees of the criteria governing the use of digital devices, always respecting the minimum standards for protecting their privacy in accordance with social practices and constitutionally and legally recognised rights.<\/p>\n<h2><span style=\"color: #72bf44;\">12. Breaches<\/span><\/h2>\n<p>Users must not comply with any requests, instructions, or orders that go against Dbus&#8217;s information security regulations, nor use them as a justification for any breach. Breaches of the provisions set forth herein are permitted only under exceptional and duly justified circumstances, such as requirements from administrative, inspection, or judicial authorities.<\/p>\n<p>Any incident or action related to this policy must be reported by email to <span style=\"cursor: pointer; color: #72bf44;\" onclick=\"location.href='mailto:' + ['ciso','dbus.eus'].join('@')\">ciso<span>@<\/span>dbus.eus<\/span><\/p>\n<p>Breaches of this policy and the associated information security regulations may result in suspension of access to the organisation\u2019s information and ICT systems. They may also lead to disciplinary measures under applicable labour regulations, usage rules, and other internal regulations such as Dbus\u2019s Code of Conduct, without prejudice to any other liabilities incurred by the person in breach.<\/p>\n<h2><span style=\"color: #72bf44;\">13. Review and continuous improvement procedure<\/span><\/h2>\n<p>The Information Security Committee&#8217;s mission will be to review this ISP annually, propose any necessary revisions or updates, and promote continuous improvement by regularly reassessing and updating Dbus\u2019s ISMS to ensure its effectiveness.<\/p>\n<p>If appropriate, the person responsible for Information Security will prepare and submit any modifications or updates to Senior Management, after which the Committee will distribute them to all relevant parties in order to keep everyone informed.<\/p>\n<h2><span style=\"color: #72bf44;\">14. Approval and entry into force<\/span><\/h2>\n<p>Text approved on 14 May 2025 by the Information Security Committee.<\/p>\n<p>This Information Security Policy is effective from the stated date and will remain so until replaced by a new one.<\/p>\n<p>The entry into force of this policy repeals any previous policy within the organisation.<\/p>\n<h2><span style=\"color: #72bf44;\">15. Annex 1: Glossary of terms<\/span><\/h2>\n<p><strong>Asset:<\/strong> any component or function of an information system susceptible to intentional or accidental threats that may impact the organisation. It includes: information, data, services, applications (software), equipment (hardware), communications, administrative resources, physical resources, and human resources.<\/p>\n<p><strong>Authenticity:<\/strong> the property or characteristic confirming that an entity is who it claims to be or that guarantees the origin of the data.<\/p>\n<p><strong>System security category:<\/strong> a classification level, within the Basic-Medium-High scale, used to qualify an information system in order to select the necessary security measures. The system&#8217;s security category encompasses a holistic view of all assets as a unified entity focused on service delivery.<\/p>\n<p><strong>Confidentiality:<\/strong> property or characteristic whereby information is not made available or disclosed to unauthorised individuals, entities, or processes.<\/p>\n<p><strong>Availability:<\/strong> property or characteristic of assets whereby authorised entities or processes have access to them when required.<\/p>\n<p><strong>Security incident (incident or cyber incident):<\/strong> unexpected or unwanted event having an adverse impact on the security of networks and information systems.<\/p>\n<p><strong>Integrity:<\/strong> property or characteristic whereby the information asset has not been altered in an unauthorised manner.<\/p>\n<p><strong>Nature of the information:<\/strong> set of qualities of information that determine its degree of criticality for the organisation.<\/p>\n<p><strong>Basic security principles:<\/strong> fundamentals that must govern all actions undertaken to secure information and services.<\/p>\n<p><strong>Security process:<\/strong> method followed to achieve the organisation&#8217;s security objectives. The process is designed to identify, assess, manage, and control the security risks faced by the system.<\/p>\n<p><strong>Information security:<\/strong> preservation of confidentiality, integrity, availability, authenticity, and traceability of the information and the systems on which it depends.<\/p>\n<p><strong>Service:<\/strong> organisation, processes, information systems, and personnel intended to meet the needs of the beneficiary entity.<\/p>\n<p><strong>Information system:<\/strong> any of the following elements:<\/p>\n<p> &#8211;&nbsp;&nbsp;The electronic communications networks used by the organisation over which it has management capacity.<\/p>\n<p> &#8211;&nbsp;&nbsp;Any device or group of interconnected or related devices in which one or more perform automatic digital data processing through a program.<\/p>\n<p> &#8211;&nbsp;&nbsp;Digital data stored, processed, retrieved, or transmitted by the elements mentioned above, including those necessary for the functioning, use, protection, and maintenance of such elements.<\/p>\n<p><strong>Traceability:<\/strong> property or characteristic whereby the actions of an entity (person or process) can be indisputably traced back to that entity.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction San Sebasti\u00e1n Tram Company (hereinafter, CTSS or Dbus) recognises the importance of information security for the effective performance of its operations. For this reason, it has developed this Information Security Policy (hereinafter, ISP), which establishes and integrates the basic security principles with the operational requirements of confidentiality, integrity, availability, authenticity, and traceability of [&hellip;]<\/p>\n","protected":false},"author":529,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"acf":[],"_links":{"self":[{"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/pages\/83321"}],"collection":[{"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/users\/529"}],"replies":[{"embeddable":true,"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/comments?post=83321"}],"version-history":[{"count":3,"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/pages\/83321\/revisions"}],"predecessor-version":[{"id":84063,"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/pages\/83321\/revisions\/84063"}],"wp:attachment":[{"href":"https:\/\/dbus.eus\/en\/wp-json\/wp\/v2\/media?parent=83321"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}