Information Security Policy
1. Statement of principles
MULTIPLE STUDIO SL (hereinafter MULTIPLE STUDIO SL) is a company dedicated to providing specialised graphic design services, founded in January 2018. It is an independent design and creative direction studio founded and run by designers with more than 20 years of experience. Our business structure is based on four partners who are leaders in Branding, Audiovisual, Photography, Editorial and Digital design, bringing together talent from different fields to create interdisciplinary solutions that we identify as emerging needs in the sector. To this end, we embrace values that we consider essential to achieving our objectives, including the preservation of information and personal data, both our own and those of other interested parties, as well as the professional and personal development of all members of our team.
Due to the nature of our activity, at MULTIPLE STUDIO SL we are aware that information is an asset of great value to our organisation and therefore requires appropriate protection and management in order to ensure business continuity and minimise any possible damage caused by failures affecting the integrity, availability and confidentiality of information. Likewise, both the legislation in force regarding personal data protection (GDPR and LOPDGDD) and MULTIPLE STUDIO SL’s commitment to our clients make us particularly sensitive to the processing of personal data to which we have access in the course of our activity.
To this end, MULTIPLE STUDIO SL establishes a set of management activities aimed at preserving the principles of Confidentiality, Integrity, Availability, Authenticity, Traceability and Regulatory Compliance of information. These principles are defined as follows:
- Confidentiality: the property that ensures that access to information may only be exercised by persons authorised to do so.
- Integrity: the property of safeguarding the accuracy and completeness of information assets.
- Availability: the quality that ensures that authorised persons can access information and process it whenever necessary.
- Authenticity: the property or characteristic whereby an entity is who it claims to be, or which guarantees the source from which the data originate.
- Traceability: the property or characteristic whereby the actions of an entity can be attributed exclusively to that entity.
- Regulatory Compliance: the property that ensures that information is managed in accordance with the ethical, professional and legal principles established by the regulations applicable in each context.
Systems must be protected against rapidly evolving threats that have the potential to affect information and services. To defend against these threats, a strategy is required that adapts to changes in environmental conditions in order to guarantee the continuous provision of services.
This means that the different departments must apply the minimum security measures required by the National Security Scheme (ENS), continuously monitor service delivery levels, track and analyse reported vulnerabilities, and prepare an effective response to incidents in order to guarantee the continuity of the services provided.
The different departments of the organisation must ensure that security is an integral part of every stage of the system life cycle, from its conception to its withdrawal from service, including development or acquisition decisions and operational activities. Security requirements and funding needs must be identified and included in planning, requests for proposals and tender specifications for ICT projects.
Departments must be prepared to prevent, detect, react to and recover from incidents, in accordance with Article 8 of the ENS.
Privacy protection is embedded within the framework described above. Our systems process sensitive personal data and therefore privacy protection is a fundamental pillar within the ISMS framework and constitutes a social need that companies must respect and protect, as well as being subject to specific legislation and/or regulation worldwide.
1.1. General objectives
The Security Policy provides the basis for defining and delimiting the objectives and responsibilities for the various technical, legal and organisational actions required to guarantee information security and privacy, in compliance with the applicable legal framework, the company’s global and specific policies, and the defined procedures.
From a security and privacy perspective, these actions are selected and implemented on the basis of risk analysis and the balance between acceptable risk and the cost of the measures.
The objective of the Security Policy is to establish the necessary framework for protecting information resources and data against internal or external, deliberate or accidental threats.
Information and data may exist in a variety of formats, on electronic media, paper or other media, and may sometimes include critical data concerning the operations, strategies or activities of MULTIPLE STUDIO SL and its clients and, where applicable, sensitive data as defined by personal data protection regulations. The loss, corruption or theft of information or of the systems that manage it has a significant impact on our Company.
MULTIPLE STUDIO SL is convinced that effective Information Security and Privacy management is an enabling factor that allows the organisation to fully understand and appropriately address the risks to which information is exposed, as well as to respond and adapt efficiently to the growing requirements of regulatory bodies, legislation and, of course, its clients.
1.2. Senior Management commitment
The purpose of the Information Security Management System is to ensure that information security and privacy risks are known, accepted, managed or minimised in a documented, systematic, structured, repeatable, affordable manner that can adapt to changes in risks, the environment and technologies.
To this end, Management declares MULTIPLE STUDIO SL’s commitment to:
- Establish as a primary objective the provision of overseas travel services with absolute respect for quality standards, preserving information, with special attention to the sensitivity of the personal data processed, using all necessary measures available.
- Apply the principle of continuous improvement to all the organisation’s processes, with the additional objective of achieving the highest level of customer satisfaction.
- Ensure compliance with the applicable legal and regulatory requirements (in particular those relating to personal data protection), as well as those voluntarily assumed by the organisation.
- Encourage participation, communication, information and training among the professional team so that they feel involved in the work of the organisation as a whole.
- Promote a commitment to responsibility among team members in accordance with quality requirements, as well as the privacy and information security requirements agreed both internally and with clients, through appropriate and regular training and awareness-raising activities.
- Ensure business continuity by developing continuity plans in accordance with recognised methodologies.
- Carry out and periodically review risk analyses based on recognised methods that enable us to establish the level of both personal data privacy and information security in general, as well as for ongoing projects and services, and to minimise risks through the development of specific policies, technical solutions and contractual agreements with specialised organisations.
- Commit to providing information to interested parties.
- Select suppliers and subcontractors on the basis of criteria related to privacy and information security.
With specific regard to the protection of personal data, MULTIPLE STUDIO SL undertakes to comply with the principles set out in the applicable legislation. These are:
- Principle of “lawfulness, transparency and fairness”. Data must be processed lawfully, fairly and transparently in relation to the data subject.
- Principle of “purpose limitation”. Data must be processed for one or more specified, explicit and legitimate purposes and, furthermore, data collected for specified, explicit and legitimate purposes may not subsequently be processed in a manner incompatible with those purposes.
- Principle of “data minimisation”. Apply technical and organisational measures to ensure that only data that are necessary for each specific processing purpose are processed, reducing the scope of processing and limiting the retention period and accessibility to what is necessary.
- Principle of “accuracy”. Implement reasonable measures to keep data up to date and to erase or amend them without delay when they are inaccurate in relation to the purposes for which they are processed.
- Principle of “storage limitation”. Data retention must be limited in time to achieving the purposes pursued by the processing.
- Principle of “security”. Carry out a risk analysis aimed at determining the technical and organisational measures necessary to guarantee the integrity, availability and confidentiality of the personal data processed.
- Principle of “accountability”. Maintain due diligence on an ongoing basis to protect and guarantee the rights and freedoms of natural persons whose data are processed, based on an analysis of the risks that the processing represents for those rights and freedoms, so that we can guarantee and demonstrate that the processing complies with the provisions of the GDPR and the LOPDGDD.
- Direct, support and supervise the information security management system, as established in Royal Decree 311/2022 and subsequent amendments, and seek to achieve its objectives.
The Management of MULTIPLE STUDIO SL undertakes to support and promote the principles set out in this Policy and therefore asks company personnel to accept and comply with the provisions of the documented management system for the ENS.
1.3. Development of the Security Policy
This Security Policy complements MULTIPLE STUDIO SL’s security policies in different areas and will be developed through security regulations addressing specific aspects. The security regulations will be made available to all members of the organisation who need to be aware of them, particularly those who use, operate or administer information and communications systems.
Information Security documentation will be classified into three levels, with each document at one level being based on those at the higher level:
- First level: Security Policy.
- Second level: Security standards and procedures.
- Third level: Reports, records and electronic evidence.
2. Policy
2.1. Prevention
Departments must avoid, or at least prevent as far as possible, information or services from being adversely affected by security incidents. To this end, departments must implement the minimum security measures established by the ENS, as well as any additional controls identified through a threat and risk assessment. These controls, and the security roles and responsibilities of all personnel, must be clearly defined and documented.
To ensure compliance with the policy, departments must:
- Authorise systems before they enter operation.
- Regularly assess security, including assessments of configuration changes made routinely.
- Request periodic reviews by third parties in order to obtain an independent assessment.
2.2. Detection
Since services can deteriorate rapidly as a result of incidents, ranging from a simple slowdown to a complete stoppage, service operations must be continuously monitored in order to detect anomalies in service delivery levels and act accordingly, as established in Article 9 of the ENS.
Monitoring is particularly relevant when lines of defence are established in accordance with Article 8 of the ENS. Detection, analysis and reporting mechanisms will be established so that responsible parties are informed regularly and whenever a significant deviation from the parameters previously established as normal occurs.
2.3. Response
Departments must:
- Establish mechanisms to respond effectively to security incidents.
- Designate a point of contact for communications regarding incidents detected in other departments or other organisations.
- Establish protocols for the exchange of information relating to the incident. This includes two-way communications with Computer Emergency Response Teams (CERTs).
2.4. Recovery
To guarantee the availability of critical services, departments must develop system continuity plans as part of their overall business continuity plan and recovery activities.
2.5. Security organisation
This policy applies to all MULTIPLE STUDIO SL systems and to all members of the organisation, without exception.
MULTIPLE STUDIO SL undertakes to provide its services in a managed manner and in compliance with the requirements established in its Integrated Management System, so as to guarantee uninterrupted service in accordance with client requirements for availability, security and quality.
Due to the nature of our activity, at MULTIPLE STUDIO SL we know that information is an asset of great value to our organisation, and especially our clients’ information, and therefore requires appropriate protection and management in order to ensure business continuity and minimise any possible damage caused by failures in Information Security.
To this end, the organisation:
- Will adequately protect the confidentiality, availability, integrity, authenticity and traceability of its information assets by introducing a series of controls to manage relevant security risks.
- Will prioritise the protection and safeguarding of its clients and client data as a business priority.
- Will establish, implement, monitor, maintain and continuously improve its information security management as part of its broader business management approach, and will maintain Accredited Certification to the appropriate standards.
- Will manage any information security breach in a timely and responsible manner and invest in appropriate detection, response and remediation strategies.
- At planned intervals, will test its information security controls and its responses to scenarios that could pose a threat to its operations.
- Will provide the organisation with adequate resources to establish, maintain and improve the security environment as appropriate to the changing risk landscape.
- Will invest in staff competencies to carry out their duties and provide personnel with appropriate training and awareness relevant to their role and the information to which they have access.
- Will ensure that our suppliers and partner organisations do the same, and that they establish and enforce security standards for those to whom we transmit any information.
2.5.1. Security Committee
The members of the Security Committee will be appointed in a founding record, which will identify the appointed person and the position they must hold.
The secretary of the Security Committee will be the SECURITY MANAGER and will have the following functions:
- Convene meetings of the Security Committee.
- Prepare the matters to be discussed at Committee meetings, providing timely information for decision-making.
- Prepare the minutes of meetings.
- Be responsible for the direct or delegated implementation of Committee decisions.
- The Security Committee will report to the Managing Director.
The Security Committee will have the following functions:
- Address the concerns of Senior Management and the different departments.
- Regularly report on the status of information security to Senior Management.
- Promote continuous improvement of the information security management system.
- Develop the Organisation’s strategy for the evolution of information security.
- Coordinate the efforts of the different areas in matters of information security, ensuring that efforts are consistent, aligned with the strategy established in this area, and avoiding duplication.
- Prepare (and regularly review) the Security Policy for approval by Management.
- Approve information security regulations.
- Coordinate all security functions within the organisation.
- Ensure compliance with applicable legal and sector-specific regulations.
- Ensure that security activities are aligned with the organisation’s objectives.
- Coordinate the Continuity Plans of the different areas in order to ensure seamless action should they need to be activated.
- Coordinate and, where appropriate, approve project proposals received from the different security areas, managing the regular monitoring and reporting of project progress and notification of any deviations.
- Receive information security concerns from the organisation’s Management and forward them to the relevant departmental managers, obtaining the corresponding responses and solutions which, once coordinated, must be communicated to Management.
- Obtain regular reports from departmental security managers on the state of the organisation’s security and any possible incidents. These reports are consolidated and summarised for communication to the organisation’s Management.
- Coordinate and respond to concerns conveyed through departmental security managers.
- Define, within the Corporate Security Policy, the assignment of roles and the criteria for achieving the relevant guarantees regarding segregation of duties.
- Prepare and approve training and qualification requirements for administrators, operators and users from an information security perspective.
- Monitor the main residual risks accepted by the Organisation and recommend possible actions in relation to them.
- Monitor the performance of security incident management processes and recommend possible actions in relation to them. In particular, ensure coordination between the different security areas in the management of information security incidents.
- Promote periodic audits to verify compliance with the organisation’s security obligations.
- Approve plans to improve the Organisation’s information security. In particular, ensure coordination between the different plans that may be carried out in different areas.
- Prioritise security actions when resources are limited.
- Ensure that information security is taken into account in all projects from their initial specification through to implementation. In particular, ensure the creation and use of shared services that reduce duplication and support the homogeneous operation of all ICT systems.
- Resolve conflicts of responsibility that may arise between the different responsible parties and/or between different areas of the Organisation.
2.5.2. Roles: Functions and responsibilities
The functions of the organisation’s responsible roles are detailed below:
Information Manager
- Ultimate responsibility for the use made of certain information and, therefore, for its protection.
- Ultimate responsibility for any error or negligence resulting in a confidentiality or integrity incident (in relation to data protection) or an availability incident (in relation to information security).
- Establish information security requirements.
- Determine and approve information security levels.
- Approve the categorisation of the system with regard to information.
- Any other functions indicated in documents within the scope of the ENS.
Service Manager
- Establish service security requirements.
- Determine the security levels of services.
- Approve the categorisation of the system with regard to services.
- Any other functions indicated in documents within the scope of the ENS.
Security Manager
Their functions will be as follows:
- Maintain the security of the information handled and the services provided by information systems within their area of responsibility, in accordance with the organisation’s Information Security Policy.
- Promote information security training and awareness within their area of responsibility.
- Approve the Statement of Applicability.
- Channel and supervise both compliance with the security requirements of the service provided or solution supplied, and communications relating to information security and incident management within the scope of that service (POC).
- Any other functions indicated in documents within the scope of the ENS.
The Security Manager will be the secretary of the Security Committee, with the functions indicated in section 3.5.1 of this policy.
System Manager
Their functions will be as follows:
- Develop, operate and maintain the information system throughout its entire life cycle, including its specifications, installation and verification of correct operation.
- Define the topology and management of the information system, establishing usage criteria and the services available within it.
- Ensure that security measures are properly integrated into the overall security framework.
- Have the authority to propose suspension of the processing of certain information or the provision of a particular service if serious security deficiencies are identified that could affect compliance with the established requirements.
- Any other functions indicated in documents within the scope of the ENS.
Data Protection Manager
Their functions will be as follows:
- Coordinate all aspects relating to the compliance of MULTIPLE STUDIO SL’s activities in the field of personal data protection.
- Coordinate, together with the Security Manager, compliance with the ENS in relation to personal data protection.
2.5.3. Appointment procedures
The Security Manager will be appointed by the Security Committee. The appointment will be reviewed every 2 years or whenever the position becomes vacant.
Likewise, the remaining roles indicated in the previous section will be appointed by the Security Committee by means of meeting minutes.
2.5.4. Review of the Security Policy
The Security Committee will be responsible for the annual review of this Security Policy and for proposing its revision or continued validity. The Policy will be approved by Senior Management and disseminated so that all affected parties are aware of it.
2.5.5 Information management
This Security Policy complements MULTIPLE STUDIO SL’s security policies in different areas and will be developed through security regulations addressing specific aspects. The security regulations will be available to all members of the organisation who need to be aware of them, particularly those who use, operate or administer information and communications systems.
The Security Policy defines the assignment of responsibilities for each information asset managed by the system. This relationship is formalised in record FR01_PRSI21 Asset Inventory, where the Information Manager is identified based on the categorisation and sensitivity of the data for the services included within the scope of the system.
Information Security documentation will be classified into three levels, with each document at one level being based on those at the higher level:
- First level: Security Policy.
- Second level: Security standards and procedures.
- Third level: Reports, records and electronic evidence.
Personnel will have access to the relevant information in a repository.
2.6. Personal data
MULTIPLE STUDIO SL, in providing its services, processes particularly sensitive personal data.
The relevant documentation, to which only authorised persons will have access, contains the records of processing activities involving the affected data and the corresponding responsible persons. All MULTIPLE STUDIO SL information systems will comply with the security levels required by the regulations according to the nature and purpose of the personal data.
2.7. Risk management
All systems subject to this Policy must carry out a risk analysis, assessing the threats and risks to which they are exposed. This analysis will be repeated:
- Regularly, at least once a year.
- When the information handled changes.
- When the services provided change.
- When a serious security incident occurs.
- When serious vulnerabilities are reported.
For the harmonisation of risk analyses, the Security Committee will establish a reference assessment for the different types of information handled and the different services provided. The Security Committee will facilitate the availability of resources to meet the security needs of the different systems, promoting cross-cutting investments.
2.8. Personnel obligations
All members of MULTIPLE STUDIO SL are required to know and comply with this Security Policy and the Security Regulations, and the Security Committee is responsible for providing the necessary means to ensure that the information reaches those concerned.
All members of MULTIPLE STUDIO SL will attend an information security awareness session at least once a year. An ongoing awareness programme will be established for all members of MULTIPLE STUDIO SL, particularly new employees.
Persons responsible for the use, operation or administration of systems will receive training in the secure handling of systems to the extent necessary to perform their work. Training will be mandatory before assuming a responsibility, whether it is their first assignment or a change of position or responsibilities within the same role.
2.9. Third parties
When MULTIPLE STUDIO SL provides services to other public or private organisations or handles information belonging to other public or private organisations, those organisations will be made aware of this Security Policy, channels will be established for reporting and coordination between the respective Security Committees, and action procedures will be established for responding to security incidents.
When MULTIPLE STUDIO SL uses third-party services or transfers information to third parties, those third parties will be made aware of this Security Policy and the Security Regulations applicable to those services or information. The third party will be subject to the obligations established in those regulations and may develop its own operating procedures to comply with them. Specific incident reporting and resolution procedures will be established. It will be ensured that third-party personnel are appropriately aware of security issues, at least to the same level as established in this Policy.
When any aspect of the Policy cannot be fulfilled by a third party as required in the preceding paragraphs, a report from the Security Manager will be required specifying the risks incurred and how they are to be treated. Approval of this report by the managers responsible for the affected information and services will be required before proceeding.
3. Applicable legislation
The laws considered applicable to the ISMS are detailed below, together with a definition of the area responsible for assessing their impact on the organisation.
| Law / Regulation | Responsibility |
| Law 39/2015, of 1 October, on the Common Administrative Procedure of Public Administrations | Legal Department |
| Law 40/2015, of 1 October, establishes and regulates the foundations of the legal regime of Public Administrations, the principles of the liability system of Public Administrations and sanctioning powers, as well as the organisation and operation of the General State Administration and its institutional public sector for the performance of their activities | Legal Department |
| Royal Decree 311/2022, of 3 May, regulating the National Security Scheme. | Legal Department |
| Organic Law 1/2015, of 30 March, amending Organic Law 10/1995, of 23 November, on the Criminal Code | Legal Department |
| Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data | Legal Department |
| Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights | Legal Department |
| Law 34/2002 on Information Society Services (LSSI) | Legal Department |
| Law 17/2001 on Trademarks | Legal Department |
| REGULATION (EU) No 910/2014 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC | Legal Department
|
| Law 6/2020, of 11 November, regulating certain aspects of electronic trust services. | Legal Department |