
Deoban offers services in the field of Innovative Commercial Solutions in Toll Collection Systems (TCS), Intelligent Transport System (ITS), Intelligent Surveillance and Electronic Services and Information Technology (IT) products.
The company has grown as a multidimensional firm in the field of information management systems and has added many other disciplines such as access control solution, technical assistance and consulting.
DEOBAN, as a company dedicated to the management of innovative business solutions, Toll Collection Systems (TCS), Intelligent Transport Systems (ITS), intelligent surveillance, electronic services products and information technology (IT), is committed to information security and to its proper management, with the aim of providing all its stakeholders with the highest guarantees regarding the security of the information used.
In view of the above, Management establishes the following information security objectives:
In order to achieve these objectives, it is necessary to:
Our management system has the following structure:
The management of our system is entrusted to the Management Officer, and the system is available within our information system in a repository that can be accessed according to the access profiles granted under our current access management procedure.
These principles are endorsed by Management, which provides the necessary means and resources to employees to ensure compliance, and they are made publicly available through this Integrated Management Systems Policy.
Ultimate responsibility lies with the organisation’s General Management, which is responsible for organising functions and responsibilities and providing adequate resources to achieve the objectives of the National Security Framework (ENS). Managers are also responsible for setting a good example by complying with the established security rules.
These principles are endorsed by Management, which provides the necessary means and resources to employees to ensure compliance, and they are reflected and made publicly available through this Integrated Management Systems Policy.
The defined security roles or functions are:
This definition is supplemented by the job profiles and system documentation.
The procedure for their appointment and renewal shall be ratification by the Security Committee.
The committee responsible for security management and coordination is the body with the highest level of responsibility within the information security management system. All major security-related decisions are agreed by this committee. The members of the Information Security Committee are:
These members are appointed by the committee, which is the only body authorised to appoint, renew and dismiss them.
The Security Committee is an autonomous executive body with decision-making authority and is not required to subordinate its activities to any other element of the company. The organisation of information security is developed in the corresponding supplementary document. Among its functions, particular emphasis is placed on ensuring compliance with the ENS. One of its main tasks is conflict resolution, since any differences of opinion that could lead to a conflict shall be addressed within the Security Committee, with the criterion of General Management prevailing in all cases.
This definition of duties and responsibilities is supplemented by the job profiles and the system documents relating to the register of managers, roles and responsibilities.
All systems subject to this Policy shall undergo a risk analysis, assessing the threats and risks to which they are exposed. This analysis shall be reviewed regularly:
To harmonise risk analyses, the ICT Security Committee shall establish a reference assessment for the different types of information handled and the different services provided. The ICT Security Committee shall facilitate the availability of resources to meet the security needs of the different systems, promoting horizontal investments.
The risk analysis shall be carried out taking into account the risk analysis methodology established in the Risk Analysis procedure.
All members of our organisation are required to know and comply with this Information Security Policy and the Security Regulations. The ICT Security Committee is responsible for providing the necessary means to ensure that this information reaches all affected parties.
All members of our organisation shall attend an ICT security awareness session at least once a year. A continuous awareness programme shall be established for all members of the organisation, particularly new employees.
Persons responsible for the use, operation or administration of ICT systems shall receive training in the secure use of systems to the extent required to perform their duties. Such training shall be mandatory before assuming a responsibility, whether it is their first assignment or a change of position or responsibilities.
This Policy applies to all personnel within the organisation and to external personnel performing tasks within the company.
The Human Resources department shall include information security functions in employee job descriptions, inform all personnel hired of their obligations regarding compliance with the Information Security Policy, manage confidentiality commitments with personnel, and coordinate user training activities relating to this Policy.
The Security Management Officer (RGS) [CISO] is responsible for monitoring, documenting and analysing reported security incidents and communicating them to the Information Security Committee and information owners.
The Information Security Committee shall be responsible for implementing the necessary means and channels for the Security Management Officer (RGS) [CISO] to manage reports of incidents and system anomalies. The Committee shall also remain informed, supervise investigations, monitor the evolution of information and promote the resolution of information security incidents.
The Security Management Officer (RGS) [CISO] shall participate in preparing the Confidentiality Commitment to be signed by employees and third parties performing functions within the organisation, advising on sanctions applicable for non-compliance with this Policy and handling information security incidents.
All personnel within the organisation are responsible for promptly reporting any information security weaknesses and incidents detected.
The objectives relating to human resources security are:
Access control to information systems aims to:
The objectives of this policy regarding the protection of facilities are:
This Policy applies to all physical resources related to the organisation’s information systems: facilities, equipment, cabling, records, storage media, etc.
The Security Management Officer (RGS), together with the Information Owners where appropriate, shall define the physical and environmental security measures required to protect critical assets based on a risk analysis and shall supervise their implementation. Compliance with physical and environmental security provisions shall also be verified.
The managers of the different departments shall define the physical access levels of the organisation’s personnel to restricted areas under their responsibility. Information Owners shall formally authorise off-site work involving business information when deemed appropriate.
All personnel within the organisation are responsible for complying with the clean screen and clean desk policy in order to protect information related to daily work in the offices.
The different departments shall ensure that ICT security is an integral part of every stage of the system life cycle, from conception to withdrawal from service, including development or acquisition decisions and operational activities. Security requirements and funding needs shall be identified and included in planning, requests for proposals and tender specifications for ICT projects.
Information security shall also be taken into account in the acquisition and maintenance of information systems, with changes being limited and managed appropriately.
The information systems development and acquisition policy is detailed in the document: INFORMATION SYSTEMS ACQUISITION, DEVELOPMENT AND MAINTENANCE POLICY.
The organisation considers it strategically important that processes integrate information security as part of their life cycle. Information systems and services must include security by default from their creation until their withdrawal, incorporating security into development and/or acquisition decisions and all operational activities, with security established as an integral and cross-cutting process.
Our organisation is committed to ensuring system integrity through a change management process that controls the updating of physical or logical components by requiring prior authorisation before their installation in the system. This assessment shall primarily be carried out by Systems Management, which shall evaluate the impact on system security before changes are made and shall document changes considered significant or having security implications.
Periodic security reviews shall assess the security status of systems in relation to manufacturers’ specifications, vulnerabilities and applicable updates, responding diligently to manage risks in light of their security status.
The organisation establishes protection measures for Information Security when information is stored or transmitted through insecure environments. Laptops, personal digital assistants (PDAs), peripheral devices, information media and communications over open or weakly encrypted networks shall be considered insecure environments.
The organisation establishes Information Security protection measures, particularly to protect the perimeter when systems are connected to public networks, especially where such networks are used wholly or mainly to provide publicly available electronic communications services.
In all cases, risks arising from the interconnection of the system with other systems through networks shall be analysed and the interconnection point shall be controlled.
The organisation shall record user activities, retaining the information necessary to monitor, analyse, investigate and document improper or unauthorised activities, enabling the person performing an action to be identified at all times.
The main objectives of incident management are:
In order to guarantee business continuity, the organisation establishes measures to ensure that systems have backup copies and the necessary mechanisms to guarantee continuity of operations in the event of the loss of the usual working resources.
The organisation establishes a process for the continuous improvement of information security by applying the criteria and methodology established in the applicable standard.
6 October 2026