Information Security Policy
Edition 01 · Approved by Management on 30 September 2026
QUABU SOLUTIONS S.L. publishes its Information Security Policy, aligned with the Spanish National Security Framework (ENS) and ISO/IEC 27001.
1. Approval and entry into force
This Information Security Policy is effective from its approval by Management until it is replaced by a new Policy.
2. Mission of the organization
QUABU provides advisory, consulting and audit services in information technology, data protection, security and regulatory compliance, offering tailored solutions that help companies and public bodies operate successfully and securely in the digital environment in accordance with the ENS.
To achieve its goals, QUABU is committed to information security and its proper management, in order to offer all stakeholders the highest guarantees regarding the information used.
Systems must be managed diligently, taking appropriate measures to protect them against accidental or deliberate damage that could affect the availability, integrity or confidentiality of the information processed or the services provided.
The goal of information security is to ensure information quality and continuous service delivery by acting preventively, monitoring daily activity and reacting promptly to incidents.
ICT systems must be protected against rapidly evolving threats. We therefore apply the minimum security measures required by the ENS, continuously monitor service levels, analyse reported vulnerabilities and prepare an effective incident response.
ICT security is an integral part of every stage of the system lifecycle, from design to decommissioning. Departments must be ready to prevent, detect, respond to and recover from incidents, in line with Article 8 of the ENS.
3. Scope
This policy applies to all ICT systems of the entity and to all members of the organization involved in the information systems supporting Atlassian solution implementation and configuration services, Atlassian product maintenance and support, and associated software and technology development, according to the current Statement of Applicability, without exception.
4. Objectives
Management sets the following information security objectives:
- Provide a framework to increase resilience and deliver an effective response.
- Ensure fast and efficient recovery of services in the face of any disaster or contingency that threatens business continuity.
- Prevent security incidents as far as technically and economically feasible, and mitigate the risks arising from our activities.
- Ensure the confidentiality, integrity, availability, authenticity and traceability of information.
5. Regulatory framework
We are committed to complying with applicable legal requirements and commitments made to clients, keeping them continuously up to date. The legal framework includes:
- Regulation (EU) 2016/679 (GDPR) on the protection of natural persons with regard to the processing of personal data.
- Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights.
- Royal Decree 311/2022 regulating the National Security Framework (ENS).
6. Implementation
To achieve these objectives it is necessary to:
- Continuously improve our information security system.
- Identify potential threats and the impact they could have on business operations.
- Protect the interests of clients, shareholders, employees and suppliers, as well as our reputation and brand.
- Work together with suppliers and subcontractors to improve services, their continuity and information security.
- Assess and ensure staff technical competence and motivation, with appropriate training and internal communication.
- Ensure facilities and equipment are in proper condition.
- Continuously analyse relevant processes and implement improvements.
- Structure the management system clearly in three levels: policies, procedures and records.
Security documentation is organized into: Security Policy, security regulations, specific documents developed according to the applicable CCN-STIC guides, and security procedures. It is stored in restricted-access repositories based on authorized profiles.
7. Security organization
Ultimate responsibility lies with General Management, which organizes roles and responsibilities and provides adequate resources to meet the ENS objectives. Managers must lead by example by following the established security rules.
The defined security roles are:
- Information Owner: makes decisions about the information processed.
- Service Owner: coordinates system implementation and continuous improvement.
- Security Officer / ISMS Manager (CISO): determines the suitability of technical measures.
- System Owner: coordinates the technical implementation and improvement of the system.
- Management: provides the necessary resources and leads the system.
Disagreements will be addressed within the Security Committee; General Management's decision shall prevail in all cases.
8. Security Committee
The Security Committee is the body with the highest responsibility within the information security management system; the most important security decisions are agreed within it.
It is formed by the Security Officer, the System Owner, the Service Owner and the Information Owner. Its members are appointed, renewed and removed by the Committee itself, which acts as an autonomous executive body.
9. Risk management
All systems subject to this Policy shall undergo a risk analysis, reviewed:
- at least once a year;
- when the information handled changes;
- when the services provided change;
- when a serious security incident occurs;
- when serious vulnerabilities are reported.
The Security Committee will set a reference valuation for the different types of information and services, and promote the resources needed to meet security requirements.
10. Personnel management
All members of QUABU must know and comply with this Policy and the security regulations.
All staff will attend at least one security awareness session per year, with an ongoing programme especially aimed at new hires. Those who operate or administer ICT systems will receive the necessary training before taking on that responsibility.
11. Professionalism and human resources security
This Policy applies to all QUABU staff and to external staff performing tasks within the company. Security duties are included in job descriptions and confidentiality agreements are managed.
- The Security Officer monitors, documents and analyses reported incidents and reports to the Committee.
- All staff must promptly report any security weaknesses and incidents detected.
- The required security competence of staff is determined and documented.
- Risks of human error, misuse of resources and unauthorized handling of information are reduced.
- Tools are established to report weaknesses and incidents and prevent recurrence.
12. Access authorization and control
- Prevent unauthorized access to information systems, databases and services.
- Implement authentication and authorization techniques.
- Control the security of connections between QUABU's network and other networks.
- Review critical events and user activities.
- Raise awareness of responsible use of passwords and equipment.
- Ensure security when using laptops and working remotely.
13. Protection of facilities
- Prevent unauthorized access, damage and interference to facilities and information.
- Protect critical equipment in areas with a defined security perimeter and appropriate access controls.
- Control environmental factors that could affect equipment.
- Provide protection proportional to the identified risks.
All staff are responsible for complying with the clear screen and clear desk policy.
14. Product acquisition
Security is integrated into the development, acquisition and maintenance of information systems. Security requirements are identified and included in the planning and tendering of ICT projects, limiting and managing change.
15. Security by default
Systems and services include security by default from creation to decommissioning, as a comprehensive, cross-cutting process.
16. System integrity and updates
QUABU ensures system integrity through a change management process with prior authorization, assessing its security impact. Periodic reviews evaluate the security status against vendor specifications, vulnerabilities and updates.
17. Protection of stored and in-transit information
Protection measures are in place for information stored or in transit through insecure environments, such as laptops, peripheral devices, storage media and communications over open or weakly encrypted networks.
18. Personal data
QUABU processes personal data in accordance with applicable law. Only authorized persons have access, and systems meet the security levels required by the nature and purpose of the data.
19. Third parties
When QUABU provides services to other organizations or uses third-party services, they will be made aware of this Policy and the applicable regulations, with coordination channels and incident response procedures established. Third-party staff must have security awareness at least at the level of this Policy. If any aspect cannot be met, the risks will be analysed and formally approved before proceeding.
20. Interconnected information systems
The perimeter and connections to public networks are especially protected, analysing the risks arising from interconnection with other systems and controlling their connection points.
21. Activity logs and incident management
QUABU logs user activity with the information needed to monitor, analyse and investigate improper or unauthorized actions. Incident management objectives are:
- Maintain a system for detecting and responding to malicious code.
- Maintain procedures for managing incidents and weaknesses, covering detection, classification, analysis, resolution, communication and recording.
- Restore optimal service performance and reduce incident impact.
- Safeguard system integrity and communicate impact as soon as possible.
- Use records for the continuous improvement of security.
22. Business continuity
QUABU maintains backups and the mechanisms needed to ensure business continuity in the event of loss of usual working resources.
23. Continuous improvement
QUABU applies a continuous improvement process for information security following the criteria and methodology of international standards such as ISO/IEC 27001.