Our Services

Deoban offers services in the field of Innovative Commercial Solutions in Toll Collection Systems (TCS), Intelligent Transport System (ITS), Intelligent Surveillance and Electronic Services and Information Technology (IT) products.

The company has grown as a multidimensional firm in the field of information management systems and has added many other disciplines such as access control solution, technical assistance and consulting.

Follow us
 

Security Policy

Security Policy

DEOBAN, as a company dedicated to the management of innovative business solutions, Toll Collection Systems (TCS), Intelligent Transport Systems (ITS), intelligent surveillance, electronic services products and information technology (IT), is committed to information security and to its proper management, with the aim of providing all its stakeholders with the highest guarantees regarding the security of the information used.

In view of the above, Management establishes the following information security objectives:

  • Provide a framework to increase resilience and ensure an effective response.
  • Ensure the rapid and efficient recovery of services in the event of any physical disaster or contingency that could jeopardise business continuity.
  • Prevent information security incidents insofar as technically and economically feasible, and mitigate the information security risks generated by our activities.
  • Guarantee the confidentiality, integrity, availability, authenticity and traceability of information.

In order to achieve these objectives, it is necessary to:

  • Continuously improve our information security system.
  • Comply with applicable legal requirements and any other requirements to which we subscribe, in addition to commitments made to customers, and ensure that these are continuously updated. The legal and regulatory framework governing our activities includes:
  • REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
  • Organic Law 3/2018, of 5 December, on Personal Data Protection and guarantee of digital rights.
  • Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI).
  • Regulation (EU) No 910/2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS).
  • Royal Legislative Decree 1/1996, of 12 April, Intellectual Property Law.
  • Royal Decree-Law 2/2018, of 13 April, amending the consolidated text of the Intellectual Property Law.
  • Royal Decree 311/2022, of 3 May, implementing the National Security Framework (ENS), as amended by Royal Decree 951/2015, of 23 October.
  • ISO/IEC 27001:2022.
  • Identify potential threats and the impact that such threats, should they materialise, could have on business operations.
  • Preserve the interests of our main stakeholders (customers, shareholders, employees and suppliers), as well as our reputation, brand and value-creating activities.
  • Work jointly with our suppliers and subcontractors to improve the provision of IT services, service continuity and information security, thereby increasing the efficiency of our activities.
  • Assess and ensure the technical competence of personnel and ensure that they are appropriately motivated to participate in the continuous improvement of our processes, providing appropriate training and internal communication so that they apply the good practices defined in the system.
  • Ensure that facilities are maintained in proper condition and that suitable equipment is available in accordance with the company’s activities, objectives and targets.
  • Ensure the continuous analysis of all relevant processes and establish the appropriate improvements in each case, based on the results obtained and the objectives established.

Our management system has the following structure:

The management of our system is entrusted to the Management Officer, and the system is available within our information system in a repository that can be accessed according to the access profiles granted under our current access management procedure.

These principles are endorsed by Management, which provides the necessary means and resources to employees to ensure compliance, and they are made publicly available through this Integrated Management Systems Policy.

Security Organisation

Ultimate responsibility lies with the organisation’s General Management, which is responsible for organising functions and responsibilities and providing adequate resources to achieve the objectives of the National Security Framework (ENS). Managers are also responsible for setting a good example by complying with the established security rules.

These principles are endorsed by Management, which provides the necessary means and resources to employees to ensure compliance, and they are reflected and made publicly available through this Integrated Management Systems Policy.

The defined security roles or functions are:

Information Manager

  • Make decisions relating to the information processed.

Service and System Manager

  • Coordinate the implementation of the system.
  • Continuously improve the system.

Security Manager

  • Determine the suitability of technical measures.
  • Provide the best technology for the service.

Management

  • Provide the resources required for the system.
  • Lead the system.

This definition is supplemented by the job profiles and system documentation.

The procedure for their appointment and renewal shall be ratification by the Security Committee.

The committee responsible for security management and coordination is the body with the highest level of responsibility within the information security management system. All major security-related decisions are agreed by this committee. The members of the Information Security Committee are:

  • Information Manager.
  • Service Manager.
  • Security Manager.
  • System Manager.
  • Company Management (partners-administrators).

These members are appointed by the committee, which is the only body authorised to appoint, renew and dismiss them.

The Security Committee is an autonomous executive body with decision-making authority and is not required to subordinate its activities to any other element of the company. The organisation of information security is developed in the corresponding supplementary document. Among its functions, particular emphasis is placed on ensuring compliance with the ENS. One of its main tasks is conflict resolution, since any differences of opinion that could lead to a conflict shall be addressed within the Security Committee, with the criterion of General Management prevailing in all cases.

This definition of duties and responsibilities is supplemented by the job profiles and the system documents relating to the register of managers, roles and responsibilities.

Risk Management

All systems subject to this Policy shall undergo a risk analysis, assessing the threats and risks to which they are exposed. This analysis shall be reviewed regularly:

  • At least once a year.
  • When the information being handled changes.
  • When the services provided change.
  • When a serious security incident occurs.
  • When serious vulnerabilities are reported.

To harmonise risk analyses, the ICT Security Committee shall establish a reference assessment for the different types of information handled and the different services provided. The ICT Security Committee shall facilitate the availability of resources to meet the security needs of the different systems, promoting horizontal investments.

The risk analysis shall be carried out taking into account the risk analysis methodology established in the Risk Analysis procedure.

Personnel Management

All members of our organisation are required to know and comply with this Information Security Policy and the Security Regulations. The ICT Security Committee is responsible for providing the necessary means to ensure that this information reaches all affected parties.

All members of our organisation shall attend an ICT security awareness session at least once a year. A continuous awareness programme shall be established for all members of the organisation, particularly new employees.

Persons responsible for the use, operation or administration of ICT systems shall receive training in the secure use of systems to the extent required to perform their duties. Such training shall be mandatory before assuming a responsibility, whether it is their first assignment or a change of position or responsibilities.

Professionalism and Human Resources Security

This Policy applies to all personnel within the organisation and to external personnel performing tasks within the company.

The Human Resources department shall include information security functions in employee job descriptions, inform all personnel hired of their obligations regarding compliance with the Information Security Policy, manage confidentiality commitments with personnel, and coordinate user training activities relating to this Policy.

The Security Management Officer (RGS) [CISO] is responsible for monitoring, documenting and analysing reported security incidents and communicating them to the Information Security Committee and information owners.

The Information Security Committee shall be responsible for implementing the necessary means and channels for the Security Management Officer (RGS) [CISO] to manage reports of incidents and system anomalies. The Committee shall also remain informed, supervise investigations, monitor the evolution of information and promote the resolution of information security incidents.

The Security Management Officer (RGS) [CISO] shall participate in preparing the Confidentiality Commitment to be signed by employees and third parties performing functions within the organisation, advising on sanctions applicable for non-compliance with this Policy and handling information security incidents.

All personnel within the organisation are responsible for promptly reporting any information security weaknesses and incidents detected.

The objectives relating to human resources security are:

  • Determine the competence required of personnel carrying out work that affects Information Security.
  • Ensure that individuals are competent on the basis of appropriate education, training or experience.
  • Demonstrate, through the necessary documented information, the competence of personnel in Information Security.
  • Reduce the risks of human error, irregular practices, misuse of facilities and resources, and unauthorised handling of information.
  • Explain security responsibilities during the recruitment stage, include them in agreements to be signed, and verify compliance during the performance of employees’ duties.
  • Ensure that users are aware of information security threats and concerns and are trained to support the organisation’s Information Security Policy in the course of their normal duties.
  • Establish confidentiality commitments with all personnel and users outside information processing facilities.
  • Establish the necessary tools and mechanisms to encourage the reporting of existing security weaknesses and incidents in order to minimise their effects and prevent recurrence.

Authorisation and Access Control to Information Systems

Access control to information systems aims to:

  • Prevent unauthorised access to information systems, databases and information services.
  • Implement secure user access through authentication and authorisation techniques.
  • Control the security of connections between the organisation’s network and other public or private networks.
  • Review critical events and activities performed by users on systems.
  • Raise awareness of users’ responsibility for the use of passwords and equipment.
  • Ensure information security when laptops and personal computers are used for remote work.

Protection of Facilities

The objectives of this policy regarding the protection of facilities are:

  • Prevent unauthorised access, damage and interference affecting our organisation’s premises, facilities and information.
  • Protect the organisation’s critical information processing equipment by locating it in protected areas within a defined security perimeter and applying appropriate security measures and access controls. Protection shall also be considered when equipment is moved or remains outside protected areas for maintenance or other reasons.
  • Control environmental factors that could adversely affect the proper operation of computing equipment containing the organisation’s information.
  • Implement measures to protect information handled by personnel in offices during their normal duties.
  • Provide protection proportionate to the identified risks.

This Policy applies to all physical resources related to the organisation’s information systems: facilities, equipment, cabling, records, storage media, etc.

The Security Management Officer (RGS), together with the Information Owners where appropriate, shall define the physical and environmental security measures required to protect critical assets based on a risk analysis and shall supervise their implementation. Compliance with physical and environmental security provisions shall also be verified.

The managers of the different departments shall define the physical access levels of the organisation’s personnel to restricted areas under their responsibility. Information Owners shall formally authorise off-site work involving business information when deemed appropriate.

All personnel within the organisation are responsible for complying with the clean screen and clean desk policy in order to protect information related to daily work in the offices.

Product Acquisition

The different departments shall ensure that ICT security is an integral part of every stage of the system life cycle, from conception to withdrawal from service, including development or acquisition decisions and operational activities. Security requirements and funding needs shall be identified and included in planning, requests for proposals and tender specifications for ICT projects.

Information security shall also be taken into account in the acquisition and maintenance of information systems, with changes being limited and managed appropriately.

The information systems development and acquisition policy is detailed in the document: INFORMATION SYSTEMS ACQUISITION, DEVELOPMENT AND MAINTENANCE POLICY.

Security by Default

The organisation considers it strategically important that processes integrate information security as part of their life cycle. Information systems and services must include security by default from their creation until their withdrawal, incorporating security into development and/or acquisition decisions and all operational activities, with security established as an integral and cross-cutting process.

System Integrity and Updating

Our organisation is committed to ensuring system integrity through a change management process that controls the updating of physical or logical components by requiring prior authorisation before their installation in the system. This assessment shall primarily be carried out by Systems Management, which shall evaluate the impact on system security before changes are made and shall document changes considered significant or having security implications.

Periodic security reviews shall assess the security status of systems in relation to manufacturers’ specifications, vulnerabilities and applicable updates, responding diligently to manage risks in light of their security status.

Protection of Information Stored and in Transit

The organisation establishes protection measures for Information Security when information is stored or transmitted through insecure environments. Laptops, personal digital assistants (PDAs), peripheral devices, information media and communications over open or weakly encrypted networks shall be considered insecure environments.

Protection of Interconnected Information Systems

The organisation establishes Information Security protection measures, particularly to protect the perimeter when systems are connected to public networks, especially where such networks are used wholly or mainly to provide publicly available electronic communications services.

In all cases, risks arising from the interconnection of the system with other systems through networks shall be analysed and the interconnection point shall be controlled.

Activity Logs

The organisation shall record user activities, retaining the information necessary to monitor, analyse, investigate and document improper or unauthorised activities, enabling the person performing an action to be identified at all times.

The main objectives of incident management are:

  • Establish a system for detecting and responding to malicious code.
  • Maintain procedures for managing security incidents and weaknesses detected in information system components.
  • Ensure that these procedures cover detection mechanisms, classification criteria, analysis and resolution procedures, communication channels to interested parties and the recording of actions taken.
  • Use these records for the continuous improvement of system security.
  • Ensure that IT services return to optimal performance.
  • Reduce the potential risks and impacts caused by an incident.
  • Safeguard system integrity in the event of a security incident.
  • Communicate the impact of an incident as soon as it is detected in order to raise the alarm and implement an appropriate business communication plan.
  • Promote business efficiency.

Business Continuity

In order to guarantee business continuity, the organisation establishes measures to ensure that systems have backup copies and the necessary mechanisms to guarantee continuity of operations in the event of the loss of the usual working resources.

Continuous Improvement of the Security Process

The organisation establishes a process for the continuous improvement of information security by applying the criteria and methodology established in the applicable standard.

6 October 2026