Information Security Policy

Approval and Entry into Force

This Information Security Policy is effective from the date of signature until it is replaced by a new Policy.

Organization’s Mission

DyCare’s mission is to improve people’s lives through the use of new technologies with a scientific basis. Its objective is to become the world leader in digital rehabilitation.

To achieve this, DyCare focuses on developing innovative digital solutions, such as its ReHub platform, which enables the creation of personalized exercises, patient monitoring, and the generation of comprehensive therapy reports in a simple way. These solutions are designed to facilitate and improve the rehabilitation process for patients with musculoskeletal conditions, combining new technologies with medical science to address patients’ individual needs and improve their quality of life.

The core values that guide DyCare in its mission include scientific evidence, positive social impact, continuous innovation, and a passion for improving healthcare.

In summary, DyCare is dedicated to transforming digital rehabilitation through the development of technological solutions based on scientific evidence, with the aim of improving people’s quality of life and becoming a global benchmark in the field of digital rehabilitation.

Scope

This policy applies to all ICT systems of the entity and to all members of the organization involved in Services and Projects intended for the public sector that require the application of the ENS (National Security Framework), without exception.

Objectives

In view of the foregoing, Management establishes the following information security objectives:

  • To provide a framework for increasing resistance or resilience capacity in order to provide an effective response.
  • To ensure the rapid and efficient recovery of services in the face of any physical disaster or contingency that could occur and that could jeopardize the continuity of operations.
  • To prevent information security incidents to the extent technically and economically feasible, and to mitigate the information security risks generated by our activities.
  • To guarantee the confidentiality, integrity, availability, authenticity, and traceability of information.

Regulatory Framework

One of the objectives must be to comply with applicable legal requirements and any other requirements we subscribe to, as well as commitments made to clients, together with their continuous updating. To this end, the legal and regulatory framework within which we carry out our activities is:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
  • Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights).
  • Real Decreto Legislativo 1/1996, de 12 de abril, Ley de Propiedad Intelectual (Spanish Royal Legislative Decree 1/1996, of 12 April, approving the consolidated text of the Intellectual Property Law).
  • Ley 2/2019, de 1 de marzo (Spanish Law 2/2019, of 1 March), amending the consolidated text of the Intellectual Property Law approved by Royal Legislative Decree 1/1996, of 12 April, and incorporating into Spanish law Directive 2014/26/EU of the European Parliament and of the Council of 26 February 2014, and Directive (EU) 2017/1564 of the European Parliament and of the Council of 13 September 2017.
  • Real Decreto 311/2022, de 3 de mayo (Spanish Royal Decree 311/2022, of 3 May), regulating the National Security Framework (Esquema Nacional de Seguridad).
  • Ley 34/2002, de 11 de julio (Spanish Law 34/2002, of 11 July), on Information Society Services and Electronic Commerce (LSSI).
  • Ley 39/2015, de 1 de octubre (Spanish Law 39/2015, of 1 October), on the Common Administrative Procedure of Public Administrations.
  • Ley 40/2015, de 1 de octubre (Spanish Law 40/2015, of 1 October), on the Legal Regime of the Public Sector.

Development

To achieve these objectives, it is necessary to:

  • Continuously improve our information security system.
  • Identify potential threats, as well as the impact on business operations that such threats, should they materialize, could cause.
  • Preserve the interests of its main stakeholders (clients, shareholders, employees, and suppliers), reputation, brand, and value-creation activities.
  • Work together with our suppliers and subcontractors in order to improve the provision of IT services, the continuity of services, and information security, contributing to greater efficiency in our activity.
  • Evaluate and ensure the technical competence of staff, as well as ensure their adequate motivation to participate in the continuous improvement of our processes, providing the training and internal communication needed for them to develop the good practices defined in the system.
  • Ensure the proper condition of facilities and adequate equipment, so that they correspond to the company’s activity, objectives, and goals.
  • Ensure a continuous analysis of all relevant processes, establishing appropriate improvements in each case, based on the results obtained and the objectives set.
  • Structure our management system so that it is easy to understand.

Management of our system is entrusted to the Head of IT Systems, and the system will be available on our information system in a repository, which can be accessed according to the access profiles granted under our current access management procedure.

The documentation relating to system security is structured in folders within the company’s Google Drive, divided into subfolders named according to the points of the standard and operating frameworks, which contain the various procedures, records, and evidence, with restricted access for company personnel; unauthorized external personnel may not access it.

Security documentation is structured as follows:

  • Security regulations: documents describing the use of equipment, services, and facilities. They describe what is considered misuse, staff responsibility with regard to compliance with or violation of the regulations, rights, duties, and disciplinary measures in accordance with applicable law.
  • Specific documents: security documentation developed in accordance with the applicable CCN-STIC guides.
  • Security procedures: documents detailing how to operate the system’s elements.

This policy is complemented by the rest of the policies, procedures, and documents in force for the development of our management system.

Security Organization

Essential responsibility lies with the organization’s General Management, since it is responsible for organizing functions and responsibilities and for providing adequate resources to achieve the objectives of the ENS. Managers are also responsible for setting a good example by following the established security standards.

These principles are embraced by Management, which provides the necessary means and equips its employees with sufficient resources for compliance, making them public through this Integrated Management Systems Policy.

This definition of duties and responsibilities is completed in the job profiles and in the system documents Register of Officers, Roles, and Responsibilities.

Conflict Resolution

Any differences of criteria that could lead to a conflict will be dealt with within the Security Committee, and in all cases the criteria of General Management shall prevail.

Security Committee

The procedure for its appointment and renewal will be ratification by the Security Committee.

The committee for the management and coordination of security is the body with the greatest responsibility within the information security management system, such that all the most important decisions related to security are agreed upon by this committee.

The members of the information security committee are:

  • Security Officer: Silvia Raga
  • System Officer: Xavier Robert
  • Service Officer: Ricardo Jauregui
  • Information Officer: Ricardo Jauregui

These members are appointed by the committee, the only body that can appoint, renew, and remove them.

The Security Committee is an autonomous, executive body with autonomy for decision-making and is not required to subordinate its activity to any other element of our company.

The organization of Information Security is developed in the document complementary to this Policy, the Security Organization Policy.

This policy is complemented by the rest of the policies, procedures, and documents in force for the development of our management system.

Risk Management

All systems subject to this Policy must undergo a risk analysis, assessing the threats and risks to which they are exposed. This analysis is reviewed regularly:

  • At least once a year;
  • When the information handled changes;
  • When the services provided change;
  • When a serious security incident occurs;
  • When serious vulnerabilities are reported.

To harmonize risk analyses, the ICT Security Committee will establish a reference assessment for the different types of information handled and the different services provided. The ICT Security Committee will drive the availability of resources to meet the security needs of the different systems, promoting horizontal investments.

The risk analysis will take into account the risk analysis methodology developed in the Risk Analysis procedure.

Personnel Management

All members of DYCARE have an obligation to know and comply with this Information Security Policy and the Security Regulations, it being the responsibility of the ICT Security Committee to provide the necessary means for the information to reach those affected.

All members of DYCARE will attend an ICT security awareness session at least once a year. A continuous awareness program will be established to reach all members of DYCARE, particularly new hires.

Persons with responsibility for the use, operation, or administration of ICT systems will receive training for the safe handling of systems to the extent they need it to carry out their work. Training will be mandatory before assuming a responsibility, whether it is their first assignment or a change of position or responsibilities within it.

Professionalism and Security of Human Resources

This Policy applies to all DYCARE staff and external personnel performing tasks within the company. HR will include information security functions in job descriptions, will inform all newly hired staff of their obligations regarding compliance with the Information Security Policy, will manage Confidentiality Agreements with staff, and will coordinate user training tasks with regard to this Policy.

The Security Management Officer (RGS) is responsible for monitoring, documenting, and analyzing reported security incidents, as well as communicating with the Information Security Committee and information owners.

The Information Security Committee will be responsible for implementing the means and channels necessary for the Security Management Officer (RGS) to handle incident and system anomaly reports. The Committee will also stay informed, oversee investigations, oversee the evolution of information, and promote the resolution of information security incidents.

The Security Management Officer (RGS) will participate in the preparation of the Confidentiality Agreement to be signed by employees and third parties performing functions at DYCARE, in advising on the sanctions to be applied for non-compliance with this Policy, and in the handling of information security incidents.

All DYCARE staff are responsible for reporting weaknesses and information security incidents detected in a timely manner.

Professionalism of human resources:

  • Determine the competence required of staff to carry out work affecting Information Security.
  • It must be ensured that individuals are competent on the basis of appropriate education, training, or experience.
  • Demonstrate, through the necessary documented information, staff competence in Information Security matters.

The objectives of controlling personnel security are:

  • To reduce the risks of human error, the initiation of irregularities, misuse of facilities and resources, and unauthorized handling of information.
  • To explain security responsibilities at the staff recruitment stage and include them in agreements to be signed, and to verify their compliance during the performance of the employee’s duties.
  • To ensure that users are aware of information security threats and concerns and are trained to support the organization’s Information Security Policy in the course of their normal duties.
  • To establish confidentiality commitments with all staff and users outside the information processing facilities.
  • To establish the tools and mechanisms necessary to promote the reporting of existing security weaknesses, as well as incidents, in order to minimize their effects and prevent recurrence.

Authorization and Access Control to Information Systems

The objective of access control to information systems is to:

  • Prevent unauthorized access to information systems, databases, and information services.
  • Implement security in user access through authentication and authorization techniques.
  • Control security in the connection between the DYCARE network and other public or private networks.
  • Review critical events and activities carried out by users on the systems.
  • Raise awareness of user responsibility for the use of passwords and equipment.
  • Ensure information security when laptops and personal computers are used for remote work.

Protection of Facilities

The objectives of this policy regarding the protection of facilities are:

  • To prevent unauthorized access, damage, and interference to DYCARE’s premises, facilities, and information.
  • To protect DYCARE’s critical information processing equipment by placing it in protected areas and protecting it with a defined security perimeter, with appropriate security measures and access controls. This also includes protecting such equipment during transport and while it remains outside protected areas for maintenance or other reasons.
  • To control environmental factors that could impair the proper functioning of the computer equipment housing DYCARE’s information.
  • To implement measures to protect information handled by staff in offices, within the normal framework of their regular duties.
  • To provide protection proportional to the identified risks.

This Policy applies to all physical resources related to DYCARE’s information systems: facilities, equipment, cabling, files, storage media, etc.

The Security Management Officer (RGS), together with the Information Owners, as appropriate, will define the physical and environmental security measures for the protection of critical assets, based on a risk analysis, and will oversee their implementation. They will also verify compliance with physical and environmental security provisions.

The heads of the various departments will define the levels of physical access for DYCARE staff to the restricted areas under their responsibility. Information Owners will formally authorize off-site work involving their business information for DYCARE employees when they deem it appropriate.

All DYCARE staff are responsible for complying with the clear screen and clear desk policy, for the protection of information related to daily work in the offices.

Product Acquisition

The various departments must ensure that ICT security is an integral part of every stage of the system’s life cycle, from its conception to its decommissioning, including development or acquisition decisions and operational activities. Security requirements and funding needs must be identified and included in planning, in requests for proposals, and in tender specifications for ICT projects.

Furthermore, information security will be taken into account in the acquisition and maintenance of information systems, limiting and managing change.

The policy on the development and acquisition of information systems is set out in the document: Systems Acquisition, Development and Maintenance Policy.

Security by Default

DYCARE considers it strategic for the entity that processes integrate information security as part of their life cycle. Information systems and services must include security by default from their creation to their decommissioning, including security in development and/or acquisition decisions and in all operational activities, establishing security as an integral, cross-cutting process.

System Integrity and Updating

DYCARE undertakes to guarantee the integrity of the system through a change management process that enables control over the updating of physical or logical elements through prior authorization before their installation in the system. This assessment will be carried out primarily by the systems department, which will assess the impact on system security before making changes and will document and control those changes assessed as significant or having security implications for the systems.

Through periodic security reviews, the security status of the systems will be assessed in relation to manufacturers’ specifications, vulnerabilities, and updates affecting them, reacting diligently to manage risk in view of their security status.

Protection of Stored and In-Transit Information

DYCARE establishes protection measures for Information Security for information stored or in transit through insecure environments. Laptops, personal digital assistants (PDAs), peripheral devices, information storage media, and communications over open networks or with weak encryption shall be considered insecure environments.

Personal Data

This concerns personal data, to which only authorized persons shall have access; it covers the affected files and the corresponding data controllers. All information systems shall be adjusted to the security levels required by regulations according to the nature and purpose of the personal data collected, as set out in the aforementioned Security Document.

Third Parties

When providing services to other organizations or handling information belonging to other organizations, they will be made aware of this Information Security Policy; channels will be established for reporting and coordination with the respective ICT Security Committees, and action procedures will be established for responding to security incidents. When third-party services are used or information is transferred to third parties, they will be made aware of this Security Policy and the Security Regulations applicable to such services or information. Such third party shall be subject to the obligations established in said regulations, and may develop its own operational procedures to comply with them. Specific procedures for reporting and resolving incidents will be established. It will be ensured that third-party personnel are adequately aware of security matters, at least to the same level as established in this Policy. Where any aspect of the Policy cannot be met by a third party as required in the preceding paragraphs, a report from the Security Officer will be required specifying the risks incurred and how they will be addressed. Approval of this report by the persons responsible for the information and the services affected will be required before proceeding.

Prevention of Interconnected Information Systems

DYCARE establishes protection measures for Information Security, especially to protect the perimeter, in particular if connected to public networks, especially if used wholly or mainly for the provision of electronic communications services available to the public.

In all cases, the risks arising from the interconnection of the system, through networks, with other systems will be analyzed, and its point of connection will be controlled.

Activity Logs

DYCARE will log user activities, retaining the information necessary to monitor, analyze, investigate, and document improper or unauthorized activities, making it possible to identify at all times the person carrying out the action.

The main objectives of Incident Management are:

  • To establish a system for detecting and reacting to malicious code.
  • To have procedures in place for managing security incidents and weaknesses detected in information system elements. These procedures will cover detection mechanisms, classification criteria, analysis and resolution procedures, as well as channels of communication to interested parties and the recording of actions taken. This record is used for the continuous improvement of system security.
  • To ensure that IT services return to optimal performance.
  • To reduce the possible risks and impacts that an incident may cause.
  • To safeguard the integrity of systems in the event of a security incident.
  • To communicate the impact of an incident as soon as it is detected in order to raise the alarm, and to implement an appropriate business communication plan.
  • To promote business efficiency.

Business Continuity

DYCARE, with the aim of ensuring business continuity, establishes measures for systems to have backup copies and establishes the mechanisms necessary to ensure the continuity of operations in the event of loss of usual working resources.

Continuous Improvement of the Security Process

DYCARE establishes a process of continuous improvement of information security by applying the criteria and methodology established in international standards such as ISO 27001.


This document is publicly available and may be shared freely. It does not contain sensitive or confidential information.

Scroll to Top