nIformation security policy

Approval and entry into force

This information security policy is effective from the date of signing and until it is replaced by a new policy.

Organization mission

The DyCare company’s mission is to improve people’s lives by using new science-based technologies. Its goal is to become the world leader in digital rehabilitation.

To achieve this, DyCare focuses on developing innovative digital solutions, such as its Rehub platform, which allows the creation of personalized exercises, patient monitoring and the generation of complete reports of the therapy in a simple way. These solutions are designed to facilitate and improve the rehabilitation process of patients with musculoskeletal problems, combining new technologies with medical science to treat the individual needs of patients and improve their quality of life.

The core values that guide DyCare in its mission include scientific evidence, positive social impact, continuous innovation, and the passion for improving healthcare.

In summary, DyCare is dedicated to transforming digital rehabilitation through the development of technological solutions based on scientific evidence, with the aim of improving the quality of life of people and becoming a world reference in the field of digital rehabilitation.

Scope

This policy applies to all ICT systems of the entity and to all members of the organization, involved in services and projects intended for the public sector, which require the application of ENS, without exceptions.

Objectives

For all the above, the Directorate establishes the following information security objectives:

Provide a framework to increase resistance or resilience capacity to give an effective response.

Ensure the fast and efficient recovery of services, against any physical disaster or contingency that could occur and that would put the continuity of operations at risk.

Prevent information security incidents to the extent that it is technically and economically viable, as well as mitigate the security risks of the information generated by our activities.

Ensure confidentiality, integrity, availability, authenticity and traceability of information.

Regulatory framework

One of the objectives must be to comply with applicable legal requirements and with any other requirements that we subscribe, in addition to the commitments acquired with customers, as well as their continuous updating. For this, the legal and regulatory framework in which we carry out our activities is:

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and the free flow of these data.

Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights.

Royal Legislative Decree 1/1996, of April 12, Intellectual Property Law.

Law 2/2019, of March 1, which modifies the consolidated text of the Intellectual Property Law, approved by Royal Legislative Decree 1/1996, of April 12, and by which the Directive is incorporated into the Spanish legal system 2014/26/EU of the European Parliament and of the Council, of February 26, 2014, and Directive (EU) 2017/1564 of the European Parliament and of the Council, of September 13, 2017.

Royal Decree 311/2022, of May 3, which regulates the national security scheme.

Law 34/2002 of July 11 on Services of the Information Society and Electronic Commerce (LSSI).

Law 39/2015, of October 1, of the Common Administrative Procedure of Public Administrations.

Law 40/2015, of October 1, on the Legal Regime of the Public Sector.

Development

In order to achieve these objectives, it is necessary:

Continuously improve our information security system.

Identify potential threats, as well as the impact on business operations that such threats, if they materialize, can cause.

Preserve the interests of its main stakeholders (customers, shareholders, employees and suppliers), reputation, brand and value creation activities.

Work together with our suppliers and subcontractors in order to improve the provision of IT services, the continuity of services and the security of information, which have an impact on a greater efficiency of our activity.

Evaluate and guarantee the technical competence of the personnel, as well as ensure the adequate motivation of the latter for their participation in the continuous improvement of our processes, providing adequate internal training and communication so that they develop good practices defined in the system.

Guarantee the correct condition of the facilities and the appropriate equipment, in such a way that they are in correspondence with the activity, objectives and goals of the company.

Guarantee a continuous analysis of all the relevant processes, establishing the relevant improvements in each case, based on the results obtained and the established objectives.

Structure our management system so that it is easy to understand. Our management system has the following structure:

The management of our system is entrusted to the Head of Computer Systems and the system will be available in our information system in a repository, which can be accessed according to the access profiles granted according to our current access management procedure.

The documentation related to the security of the system is structured in folders within the company’s Google Drive, divided into sub-folders named by standard points and operating frameworks, which collect the different procedures, records and evidence, with restricted access for the company’s personnel, no being able to access unauthorized external personnel.

The security documentation is structured in:

Security policy.

Safety regulations: Documents that describe the use of equipment, services and facilities. They describe what is considered improper use, the responsibility of the staff with respect to compliance or violation of the regulations, rights, duties and disciplinary measures in accordance with current legislation.

Specific documents: Security documentation developed according to the CCN-STIC guides that are applicable.

Security Procedures: Documents detailing how to operate the elements of the system.

This policy is complemented by the rest of the policies, procedures and documents in place to develop our management system.

Security organization

The essential responsibility falls on the general direction of the organization, since it is responsible for organizing the functions and responsibilities and for providing adequate resources to achieve the objectives of the ENS. Managers are also responsible for setting a good example by following the established safety regulations.

These principles are assumed by the Directorate, who has the necessary means and provides their employees with sufficient resources for their compliance, plasming and putting them public knowledge through this integrated management system policy.

The defined security roles or functions are:

This definition of duties and responsibilities is completed in the job profiles and in the documents of the Registry of Responsible, Roles and Responsibilities System.

Conflict resolution

The differences of criteria that could lead to a conflict will be treated within the Security Committee and the criteria of the General Directorate will prevail in any case.

Security Committee

The procedure for its designation and renewal will be ratification in the Security Committee.

The Security Management and Coordination Committee is the body with the greatest responsibility within the Information Security Management System, so that all the most important security-related decisions are agreed by this Committee.

The members of the Information Security Committee are:
Security Manager: Silvia Raga
System Manager: Xavier Robert
Responsible for the service: Ricardo Jauregui
Information Manager: Ricardo Jauregui

These members are appointed by the Committee, the only body that can appoint, renew and dismiss them.

The Security Committee is an autonomous, executive body with autonomy for decision-making and that does not have to subordinate its activity to any other element of our company.

The information security organization is developed in the complementary document to this security organization policy

This policy is complemented by the rest of the policies, procedures and documents in place to develop our management system.

RISK MANAGEMENT

All systems subject to this policy must carry out a risk analysis, evaluating the threats and the risks to which they are exposed. This analysis is regularly reviewed: at least once a year; when the information handled changes; when the services provided change; When a serious security incident occurs; When serious vulnerabilities are reported.

For the harmonization of risk analysis, the ICT Security Committee will establish a benchmark assessment for the different types of information handled and the different services provided. The ICT Security Committee will energize the availability of resources to meet the security needs of the different systems, promoting investments of a horizontal nature.

To carry out the risk analysis, the risk analysis methodology developed in the Risk Analysis procedure will be taken into account.

PERSONAL MANAGEMENT

All DyCare members are required to know and comply with this information security policy and security regulations, and the ICT Security Committee is the responsibility of the ICT Security Committee to provide the necessary means for the information to reach those affected.

All DyCare members will attend an ICT security awareness session at least once a year. A continuous awareness program will be established to serve all DyCare members, in particular those of new incorporation.

People with responsibility for the use, operation or administration of ICT systems will receive training for the safe management of systems to the extent that they need it to carry out their work. The training will be mandatory before assuming a responsibility, whether it is your first assignment or if it is a change of job or responsibilities in it.

Professionalism and security of human resources 

This policy applies to all DyCare personnel and external staff performing tasks within the company. HR will include information security functions in the job descriptions of employees, will inform all personnel who hire their obligations with respect to compliance with the information security policy, will manage the confidentiality commitments with the personnel and coordinate the training tasks of the users regarding this policy.

The Responsible for Security Management (RGS), is responsible for monitoring, documenting and analyzing reported security incidents, as well as communicating to the Information Security Committee and the owners of information.

The Information Security Committee will be responsible for implementing the necessary means and channels for the Security Management Manager (RGS) to manage incident and system anomalies reports. The committee will also be aware, supervise the investigation, monitor the evolution of the information and promote the resolution of information security incidents.

The Security Management Manager (RGS) will participate in the preparation of the confidentiality commitment that will be signed by employees and third parties who perform functions in DyCare, in the advice on the sanctions that will be applied for non-compliance with this policy and in the treatment of incidents information security.

All DyCare staff are responsible for reporting on information security weaknesses and incidents that are detected in a timely manner.

Human Resources Professionalism:

Determine the necessary competence of the personnel to carry out the work that affects the security of the information.

Ensure that people are competent on the basis of appropriate education, training or experience.

Demonstrate through the documented information that the competence of the personnel in terms of information security is necessary.

The objectives of controlling the safety of personnel are:

Reduce the risks of human error, implementation of irregularities, misuse of facilities and resources, and unauthorized handling of information. 

Explain the safety responsibilities at the staff recruitment stage and include them in the agreements to be signed and verify their compliance during the performance of the employee’s tasks.

Ensure users are aware of information security threats and concerns and are trained to support the organization’s information security policy in the course of their normal tasks.

Establish confidentiality commitments with all personnel and users outside the information processing facilities.

Establish the necessary tools and mechanisms to promote the communication of existing security weaknesses, as well as incidents, in order to minimize their effects and prevent their recidivism.

Authorization and control of access to information systems

The control of access to information systems aims to:

Avoid unauthorized access to information systems, databases and information services.

Implement security in user access through authentication and authorization techniques.

Control the security of the connection between the DyCare network and other public or private networks.

Review critical events and activities carried out by users in the systems.

Raise awareness about your responsibility for the use of passwords and equipment.

Ensure information security when using laptops and personal computers for remote work.

FACILITIES PROTECTION

The objectives of this policy on the protection of facilities are:

Prevent unauthorized access, damage and interference to DyCare headquarters, installations and information.

Protect DyCare’s critical information processing equipment by placing it in protected areas and protected by a defined security perimeter, with appropriate security measures and access controls. Likewise, contemplate its protection in its transfer and remain outside the protected areas, for maintenance or other reasons.

Control the environmental factors that could impair the proper functioning of the computer equipment that houses DyCare information

Implement measures to protect the information handled by staff in the offices, within the normal framework of their usual tasks.

Provide proportional protection to the identified risks.

This policy applies to all physical resources related to DyCare information systems: installations, equipment, wiring, files, storage media, etc.

The Head of Security Management (RGS), together with the information holders, as appropriate, will define the physical and environmental security measures for the protection of critical assets, based on a risk analysis, and will monitor its application. It will also verify compliance with the physical and environmental security provisions.

Those responsible for the different departments will define the levels of physical access of DyCare personnel to the restricted areas under their responsibility. Information owners will formally authorize off-site work with information about their business to DyCare employees when they deem it appropriate.

All DyCare staff are responsible for compliance with the clean screen and desktop policy, for the protection of information related to daily work in the offices.

Purchase of products

The different departments must ensure that ICT security is an integral part of each stage of the system’s life cycle, from its conception to its withdrawal from service, through development or acquisition decisions and exploitation activities. Security requirements and financing needs must be identified and included in the planning, request for offers, and in tender specifications for ICT projects.

On the other hand, the security of information will be taken into account in the acquisition and maintenance of information systems, limiting and managing the change.

The information systems development and acquisition policy is developed in the document: Acquisition, Development and Maintenance Policy of Systems.

Default security

DyCare considers it strategic for the entity that the processes integrate information security as part of its life cycle. Information systems and services must include security by default from its creation to its withdrawal, including security in development and/or acquisition decisions and in all operating activities, establishing security as an integral and transversal process.

System integrity and update

DyCare is committed to guaranteeing the integrity of the system through a change management process that allows the control of the update of the physical or logical elements through authorization prior to its installation on the system. Said evaluation will be carried out mainly by the Systems Management that will evaluate the impact on the security of the system before making the changes and will control in a documented way those changes that are evaluated as important or with implications for the safety of the systems.

Through periodic security checks, the security status of the systems will be evaluated, in relation to the specifications of the manufacturers, the vulnerabilities and the updates that affect them, reacting with diligence to manage the risk in view of their security status.

Protection of information stored and in transit

DyCare establishes protection measures for the security of information stored or in transit through unsafe environments. Laptops, personal assistants (PDAs), peripheral devices, information supports and communications on open networks or with weak encryption will be considered unsafe environments.

Personal data

This is personal data. The one, to which only authorized persons will have access, collects the affected files and those responsible. All information systems will be adjusted to the levels of security required by the regulations for the nature and purpose of the personal data collected in the aforementioned security document.

Third parties

When you provide services to other agencies or manage information from other agencies, they will be made part of this information security policy, channels will be established for reporting and coordination of the respective ICT Security Committees and action procedures will be established for the reaction to security incidents. When you use third party services or assign information to third parties, you will be made part of this security policy and the security regulations that concern said services or information. Said third party will be subject to the obligations established in said regulations, being able to develop its own operating procedures to satisfy it. Specific incident reporting and resolution procedures will be established. It will be ensured that third party personnel are adequately aware of security, at least at the same level as that established in this policy. When any aspect of the policy cannot be satisfied by a third party as required in the previous paragraphs, a report from the security officer who specifies the risks incurred and how to treat them will be required. Approval of this report will be required by those responsible for the affected information and services before moving on.

Prevention of interconnected information systems

DyCare, establishes protection measures for the security of information, especially to protect the perimeter, in particular, if it is connected to public networks, especially if they are used in whole or mainly, for the provision of electronic communications services available to the public.

In any case, the risks arising from the interconnection of the system will be analyzed, through networks, with other systems, and its point of union will be controlled. electronic connections available to the public.

Activity records

DyCare, will record the activities of the users, retaining the information necessary to monitor, analyze, investigate and document improper or unauthorized activities, allowing the person to act to identify at all times.

The main objectives of incident management are:

Establish a detection and reaction system against harmful code.

Have procedures for managing security incidents and weaknesses detected in the elements of the information system.

These procedures will cover the detection mechanisms, the classification criteria, the analysis and resolution procedures, as well as the communication channels to the interested parties and the registration of the actions.

This record is used for continuous improvement of system security.

Ensure that IT services return to optimal performance.

Reduce the potential risks and impacts that the incident may cause.

Ensure the integrity of the systems in the event of a security incident.

Communicate the impact of an incident as soon as it is detected to activate the alarm; and implement an appropriate business communication plan.

Promote business efficiency.

continuity of activity

DyCare, with the aim of guaranteeing the continuity of activities, establishes measures so that the systems have backup copies and establishes necessary mechanisms to guarantee the continuity of operations, in case of loss of the usual means of work.

Continuous improvement of the security process

DyCare establishes a process of continuous improvement of information security by applying the criteria and methodology established in international standards such as ISO 27001

Scroll to Top