At XOne (COMPUTER GLOBAL SOFTWARE, S.L.) information security is a business requirement, not an add-on. The information system supporting our mobile application development and publishing service is certified against the Spanish National Security Framework (ENS) and against ISO/IEC 27001:2022, both by an accredited certification body.
On this page
- Certificate of Conformity with the Spanish National Security Framework (ENS) – Royal Decree 311/2022
- ISO/IEC 27001:2022 certification – Information Security
- Information Security Policy
Certificate of Conformity with the Spanish National Security Framework (ENS)
COMPUTER GLOBAL SOFTWARE, S.L. holds the Certificate of Conformity with the Spanish National Security Framework (ENS) at MEDIUM category, having been audited and found compliant with the requirements of Royal Decree 311/2022 of 3 May, which regulates the National Security Framework.
- Certificate number: ENS_2.026.126
- Security category: MEDIUM — MEDIUM level across all five security dimensions (Availability, Integrity, Confidentiality, Authenticity and Traceability), with 64 security measures implemented.
- Scope: information system supporting the mobile application development and publishing service.
- Location: Extremadura Science and Technology Park building (PCTEX), Avenida de Elvas, University Campus, Badajoz (Spain) — with its own data centre.
- Statement of applicability: version 1.1, dated 11/02/2026.
- Certification body: ACCM — Agencia para la Certificación de la Calidad y el Medio Ambiente, S.L., accredited by ENAC.
- Date of award: 9 August 2026 · Valid until: 9 August 2028
→ View the ENS certificate (PDF)
Conformity mark published in accordance with Article 38 of Royal Decree 311/2022.
ISO/IEC 27001:2022 certification
COMPUTER GLOBAL SOFTWARE, S.L. operates an Information Security, Cybersecurity and Privacy Protection Management System certified against ISO/IEC 27001:2022.
- Registration code: SI-623926
- Standard: ISO/IEC 27001:2022
- Scope: Information Security Management System supporting the mobile application development and publishing services.
- Location: Avda. de Elvas, s/n — 06006 Badajoz (Spain).
- Certification body: ACCM — Agencia para la Certificación de la Calidad y el Medio Ambiente.
- First issue: 10/04/2026 · Current issue: 10/04/2026 · Valid until: 09/04/2029
→ View the ISO/IEC 27001 certificate (PDF)

Information Security Policy
COMPUTER GLOBAL SOFTWARE, S.L. — Document Org.1. Edition 01, dated 11/02/2026. Approved by Management.
1. OBJECTIVE AND DEVELOPMENT
COMPUTER GLOBAL SOFTWARE, S.L., as a company whose information systems support its MOBILE APPLICATION DEVELOPMENT AND PUBLISHING SERVICE, aims to offer all of its stakeholders the strongest possible guarantees regarding the security of the information it handles. Accordingly, Management establishes the following information security objectives:
- Provide a framework that increases our resilience and our capacity to respond effectively.
- Ensure the rapid and efficient recovery of services in the event of any physical disaster or contingency that could jeopardise the continuity of operations.
- Prevent information security incidents as far as this is technically and economically viable, and mitigate the information security risks generated by our activities.
- Guarantee the confidentiality, integrity, availability, authenticity and traceability of information.
To achieve these objectives we must:
- Continuously improve our information security management system.
- Comply with applicable legal requirements and any other requirements we subscribe to, as well as with the commitments made to our customers, keeping them continuously up to date. The legal and regulatory framework for our activities includes: Regulation (EU) 2016/679 (GDPR); Spanish Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights; Royal Legislative Decree 1/1996 (Intellectual Property Act); Royal Decree-Law 2/2018 amending the Intellectual Property Act; Royal Decree 3/2010 developing the National Security Framework, as amended by Royal Decree 951/2015; standard UNE-EN ISO/IEC 27001 for information security; Law 34/2002 on Information Society Services and Electronic Commerce (LSSI); and Royal Decree 311/2022 of 3 May regulating the National Security Framework.
- Identify potential threats and the impact on business operations should they materialise.
- Protect the interests of our main stakeholders (customers, shareholders, employees and suppliers), our reputation, our brand and our value-creating activities.
- Work jointly with our suppliers and subcontractors to improve IT service delivery, service continuity and information security.
- Assess and guarantee the technical competence of our staff and ensure they are properly motivated to take part in the continuous improvement of our processes, providing the training and internal communication needed for them to apply the good practices defined in the system.
- Guarantee that facilities and equipment are appropriate and consistent with the company’s activity, objectives and targets.
- Guarantee the continuous analysis of all relevant processes, introducing the relevant improvements in each case based on the results obtained and the objectives set.
- Structure our management system so that it is easy to understand.
Management of our system is entrusted to the IT Systems Manager, and the system is available in a repository within our information system, accessible according to the access profiles granted under our access management procedure in force.
2. ENS BASIC PRINCIPLES
The security policy of COMPUTER GLOBAL SOFTWARE, S.L. is established in accordance with the basic principles set out in Chapter II of the National Security Framework and is developed by applying the following minimum requirements:
- Organisation and implementation of the security process.
- Risk analysis and management.
- Personnel management.
- Professionalism.
- Authorisation and access control.
- Protection of facilities.
- Acquisition of security products and contracting of security services.
- Least privilege.
- System integrity and updating.
- Protection of stored and in-transit information.
- Prevention regarding other interconnected information systems.
- Activity logging and malicious code detection.
- Security incidents.
- Business continuity.
- Continuous improvement of the security process.
3. SECURITY ORGANISATION
Ultimate responsibility rests with the General Management of the organisation, which is responsible for organising roles and responsibilities and for providing adequate resources to meet the objectives of the ENS and ISO 27001. Managers are also responsible for setting a good example by following the established security rules.
These principles are adopted by Management, which provides the necessary means and equips employees with sufficient resources to comply with them, setting them out and making them publicly known through this Policy.
The defined security roles are: Information Owner (RINF), Service Owner (RSER), Security Officer (RSEG), Systems Manager (RSIS), Management (DIR) and Management System Officer (RSG). This definition is completed in the job profiles and in the system documentation. Appointment and renewal take place through ratification by the security committee.
The committee for security management and coordination is the body with the greatest responsibility within the information security management system, so that all the most important security-related decisions are agreed by this committee. Its members are the Information Security Management System officers and Company Management (partners/administrators). Its duties and responsibilities are defined in the “Deed of constitution of the security committee”. Members are ratified or replaced annually at the committee’s own meeting. The security committee is an autonomous, executive body with authority to take decisions and does not subordinate its activity to any other part of the company.
4. RISK MANAGEMENT
All systems subject to this Policy must undergo a risk analysis, assessing the threats and risks to which they are exposed. This analysis is reviewed regularly: at least once a year; when the information handled changes; when the services provided change; when a serious security incident occurs; and when serious vulnerabilities are reported.
To harmonise risk analyses, the Security Committee establishes a reference valuation for the different types of information handled and the different services provided. The Security Committee facilitates the availability of resources to meet the security needs of the different systems, promoting horizontal investments. Risk analysis is carried out using the methodology set out in procedure Op.pl.1 Risk Analysis.
5. PERSONNEL MANAGEMENT
All members of COMPUTER GLOBAL SOFTWARE, S.L. are obliged to know and comply with this Information Security Policy and the Security Regulations; it is the responsibility of the Security Committee to provide the means necessary for this information to reach those affected.
All members attend a security awareness session at least once a year. A continuous awareness programme is established for all members, particularly new joiners. People with responsibility for the use, operation or administration of systems receive training in the secure handling of those systems to the extent required by their work. Training is mandatory before assuming a responsibility, whether it is a first assignment or a change of role or responsibilities.
6. PROFESSIONALISM AND HUMAN RESOURCES SECURITY
The objectives of personnel security control are to reduce the risks of human error, irregularities, misuse of facilities and resources and unauthorised handling of information; to explain security responsibilities at the recruitment stage, include them in the agreements to be signed and verify compliance during the performance of duties; to ensure users are aware of information security threats and concerns and are able to support the organisation’s Information Security Policy in the course of their normal work; to establish confidentiality commitments with all staff and users outside the information processing facilities; and to provide the tools and mechanisms needed to report existing security weaknesses and incidents so as to minimise their effects and prevent recurrence.
Regarding professionalism: the competence required of staff to carry out work affecting information security is determined; competence is ensured on the basis of appropriate education, training or experience; and staff competence in information security is demonstrated through the necessary documented information.
This Policy applies to all staff of COMPUTER GLOBAL SOFTWARE, S.L. and to external personnel performing tasks within the company. HR includes information security duties in job descriptions, informs all staff it hires of their obligations regarding compliance with the Information Security Policy, manages Confidentiality Commitments with staff and coordinates user training in relation to this Policy.
The Information Security Management System Officer (RSEG) is responsible for monitoring, documenting and analysing reported security incidents and for communicating them to the Information Security Committee and to information owners. The Committee is responsible for implementing the means and channels needed for the RSEG to handle incident and anomaly reports, and it oversees investigation and promotes the resolution of information security incidents. The RSEG takes part in preparing the Confidentiality Commitment signed by employees and third parties, in advising on the penalties applicable for breaches of this Policy, and in handling information security incidents. All staff are responsible for promptly reporting the information security weaknesses and incidents they detect.
7. AUTHORISATION AND ACCESS CONTROL TO INFORMATION SYSTEMS
The objectives of access control to information systems are to prevent unauthorised access to information systems, databases and information services; to implement security in user access through authentication and authorisation techniques; to control the security of connections between the company network and other public or private networks; to review critical events and the activities carried out by users on the systems; to raise awareness of users’ responsibility for the use of passwords and equipment; and to guarantee information security when laptops and personal computers are used for remote work.
8. PROTECTION OF FACILITIES
The objectives of this policy are to prevent unauthorised access, damage and interference to the company’s premises, facilities and information; to protect critical information-processing equipment by placing it in protected areas within a defined security perimeter, with appropriate security measures and access controls, including protection while it is being moved or kept outside protected areas for maintenance or other reasons; to control environmental factors that could impair the correct operation of the computing equipment hosting company information; to implement measures to protect the information handled by staff in the offices as part of their normal duties; and to provide protection proportionate to the risks identified.
This Policy applies to all physical resources related to the company’s information systems: facilities, equipment, cabling, files, storage media, etc. The RSEG, together with the Information Owners where appropriate, defines the physical and environmental security measures for the protection of critical assets on the basis of a risk analysis, oversees their application and verifies compliance. Department managers define the physical access levels of staff to the restricted areas under their responsibility. Information Owners formally authorise off-site work involving business information where they consider it appropriate. All staff are responsible for complying with the clear desk and clear screen policy.
9. PRODUCT ACQUISITION
The different departments must ensure that ICT security is an integral part of every stage of the system life cycle, from conception to withdrawal from service, including development or acquisition decisions and operational activities. Security requirements and funding needs must be identified and included in planning, in requests for tenders and in tender specifications for ICT projects. Information security is also taken into account in the acquisition and maintenance of information systems, limiting and managing change. The policy on the development and acquisition of information systems is set out in document Op.pl.3.1 Acquisition of new components.
10. SECURITY BY DEFAULT
COMPUTER GLOBAL SOFTWARE, S.L. considers it strategic that its processes integrate information security as part of their life cycle. Information systems and services must include security by default from creation to withdrawal, with security considered in development and/or acquisition decisions and in all operational activities, establishing security as an integral, cross-cutting process.
11. SYSTEM INTEGRITY AND UPDATING
COMPUTER GLOBAL SOFTWARE, S.L. undertakes to guarantee system integrity through a change management process that controls the updating of physical or logical elements by requiring prior authorisation before installation on the system. This assessment is carried out mainly by ICT systems management, which evaluates the impact on system security before changes are made and keeps documented control of those changes assessed as significant or with security implications. Periodic security reviews assess the security status of systems in relation to manufacturers’ specifications, vulnerabilities and applicable updates, reacting diligently to manage risk in the light of that status.
12. PROTECTION OF STORED AND IN-TRANSIT INFORMATION
COMPUTER GLOBAL SOFTWARE, S.L. establishes protection measures for the security of information stored in or in transit through insecure environments. Insecure environments include laptops, tablets, mobile phones, peripheral devices, storage media and communications over open networks or networks with weak encryption.
13. PREVENTION REGARDING INTERCONNECTED INFORMATION SYSTEMS
COMPUTER GLOBAL SOFTWARE, S.L. establishes information security protection measures, particularly to protect the perimeter, especially where it connects to public networks. In all cases, the risks arising from the interconnection of the system with other systems through networks are analysed and the point of connection is controlled.
14. ACTIVITY LOGGING
COMPUTER GLOBAL SOFTWARE, S.L. logs user activity, retaining the information needed to monitor, analyse, investigate and document improper or unauthorised activity, making it possible to identify the person acting at any given time.
The main objectives of incident management are to establish a system for detecting and responding to malicious code; to have procedures in place for managing security incidents and weaknesses detected in information system components, covering detection mechanisms, classification criteria, analysis and resolution procedures, channels for communicating with interested parties and the recording of actions taken (this record is used for the continuous improvement of system security); to ensure IT services return to optimal performance; to reduce the potential risks and impacts an incident may cause; to safeguard system integrity in the event of a security incident; to communicate the impact of an incident as soon as it is detected in order to raise the alarm and put an appropriate corporate communication plan into practice; and to promote business efficiency.
15. BUSINESS CONTINUITY
In order to guarantee the continuity of its activities, COMPUTER GLOBAL SOFTWARE, S.L. establishes measures to ensure that systems have backups, and puts in place the mechanisms needed to guarantee the continuity of operations in the event of the loss of the usual working facilities.
16. CONTINUOUS IMPROVEMENT OF THE SECURITY PROCESS
COMPUTER GLOBAL SOFTWARE, S.L. establishes a process of continuous improvement of information security, applying the criteria and methodology set out in international standards such as ISO 27001.
17. DOCUMENTED INFORMATION AND INFORMATION CLASSIFICATION
The specific guidelines for documentation management, including the structure of system security documentation, its management and access, and the information classification policy, are defined in document Mp.info.2 Documented information.
18. MANAGEMENT OF PERSONAL DATA RISKS (GDPR)
COMPUTER GLOBAL SOFTWARE, S.L. is firmly committed to regulatory compliance, integrating the management of personal data risks as a fundamental pillar of its security policy. In line with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation, GDPR), and with Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), the company implements proactive measures to identify, assess and mitigate risks that may affect both its employees and its operations, guaranteeing a safe and protected working environment. This strategy not only safeguards the physical and emotional integrity of its staff but also strengthens the resilience and sustainability of its business processes.




