Information Security
ICT systems must be protected against rapidly evolving threats that have the potential to impact the confidentiality, integrity, availability, intended use, and value of information and services.
To defend against these threats, a strategy is required that adapts to changing environmental conditions to ensure the continuous delivery of services. This means that organizations must implement minimum security measures, continuously monitor service delivery levels, track and analyze reported vulnerabilities, and prepare an effective incident response to guarantee the continuity of services provided.
COS is firmly committed to information security, which is an integral part of every stage of our service lifecycle, from conception to retirement, including development or acquisition decisions and operational activities.
Information security is a fundamental pillar of COS’s overall strategy and the delivery of our services. Therefore, since 2011, we have had an Information Security Management System (ISMS), compliant with the international standard ISO 27001, which has been reviewed and approved by an external entity, issuing the corresponding certificate of validity. The ISMS is a tool to guarantee maximum confidentiality, integrity, and availability of the information managed by an organization.
In 2021, COS adapted its ISMS to the requirements of the National Security Framework, achieving intermediate-level certification in June of that year.
The fundamental pillars of COS’s information security strategy are the following:
• The Security Organization. COS has appointed an Information Security Committee to monitor, coordinate, and support initiatives related to information security. This committee is composed of the following roles: Security Officer, Service Manager, Information Officer, and System Manager.
• A mandatory regulatory framework for all COS employees and suppliers. This includes: Organic Law 3/2018, of December 5, on Data Protection and Guarantee of Digital Rights; Royal Decree 3/2010, of January 8, which regulates the National Security Framework in the field of Electronic Administration; Law 34/2002, of June 11, on Information Society Services and Electronic Commerce; the Industrial Property Law; and UNE-EN ISO 27001:2013.
• The Security Policy. Based on the applicable regulatory framework, COS develops, approves, communicates, and periodically reviews a mandatory Information Security Policy for employees and third parties. This policy is complemented by Security Regulations and Security Procedures.
• Information Security training and awareness programs for all employees and third parties with access to information systems. Training and awareness programs are aimed at all system users and seek to promote best practices in security, as well as inform users of their responsibilities regarding information protection.
• Use of Technical Protection Measures. COS advocates for the use of technology to help protect information, as well as prevent and detect information security incidents.
• Audits and Monitoring. To verify compliance with security policies, procedures, and regulations, as well as the effectiveness of implemented technical measures, COS conducts regular internal and external audits.
You can consult our Information Security Policy here:
– Information Security Policy
– Third-Party Information Security Policy