{"id":1288,"date":"2026-05-05T09:31:23","date_gmt":"2026-05-05T07:31:23","guid":{"rendered":"https:\/\/macguffin.es\/?page_id=1288"},"modified":"2026-05-05T09:43:05","modified_gmt":"2026-05-05T07:43:05","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/macguffin.es\/en\/security-policy\/","title":{"rendered":"Pol\u00edtica de seguridad"},"content":{"rendered":"<h2 class=\"Textbody\" style=\"text-align: center;\">Security policy<\/h2>\n<hr \/>\n<p><strong>MAC GUFFIN SL<\/strong>, as a company dedicated <strong>to event production<\/strong>, is committed to information security and to the proper management of such information, in order to provide all its stakeholders with the highest level of assurance regarding the security of the information used. For all of the above reasons, Management establishes the following information security objectives:<\/p>\n<ul>\n<li>To provide a framework to increase resilience in order to respond effectively to critical security situations.<\/li>\n<li>To ensure the rapid and efficient recovery of services in the event of any physical disaster or contingency that could occur and jeopardize the continuity of operations.<\/li>\n<li>Prevent information security incidents to the extent that is technically and economically feasible, as well as mitigate the information security risks generated by our activities.<\/li>\n<li>To guarantee the confidentiality, integrity, availability, authenticity, and traceability of information<\/li>\n<\/ul>\n<p>To achieve these objectives, it is necessary to:<\/p>\n<ul>\n<li><strong>Continuously improve <\/strong>our information security system.<\/li>\n<li>Comply with applicable legal requirements and any other requirements we undertake, in addition to the commitments made to our clients, as well as continuously updating them.<\/li>\n<\/ul>\n<p>The legal and regulatory framework within which we conduct our activities is:<\/p>\n<ul>\n<li><em>REGULATION (EU) 2016\/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016 <\/em><em style=\"color: #555555;\">on the protection of natural persons with regard to the processing of personal data and on the free movement of such data<\/em><\/li>\n<li><em>Organic Law 3\/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights.<\/em><\/li>\n<li><em>Royal Legislative Decree 1\/1996, of April 12, Intellectual Property Law<\/em><\/li>\n<li><em>Royal Decree-Law 2\/2018, of April 13, amending the consolidated text of the Intellectual Property Law<\/em><\/li>\n<li><em>REGULATION (EU) 910\/2014 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of July 23, <\/em><em style=\"color: #555555;\">2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation).<\/em><\/li>\n<li><em>Occupational Risk Prevention: Law 31\/1995 of November 8 and Royal Decree 39\/1997 of January 17, approving the Regulation on Prevention Services.<\/em><\/li>\n<li><em>Law 34\/2002 of July 11 on Information Society Services and Electronic Commerce (LSSI-CE).<\/em><\/li>\n<li><em>Royal Decree-Law 13\/2012 of March 30, the Cookies Law.<\/em><\/li>\n<li><em>Royal Legislative Decree 1\/1996, of April 12, approving the consolidated text of the Intellectual Property Law, regularizing, clarifying, and harmonizing the legal provisions in force on the matter.<\/em><\/li>\n<li><em>Resolution of October 7, 2016, of the Secretary of State for Public Administration, approving the Technical Security Instruction for the State of Security Report.<\/em><\/li>\n<li><em>Resolution of October 13, 2016, of the Secretary of State for Public Administration, approving the Technical Security Instruction in accordance with the National Security Framework.<\/em><\/li>\n<li><em>Resolution of March 27, 2018, of the Secretary of State for Public Service, approving the Technical Security Instruction on Information Systems Security Audits.<\/em><\/li>\n<li><em>Resolution of April 13, 2018, of the Secretary of State for Public Service, approving the Technical Security Instruction on the Reporting of Security Incidents.<\/em><\/li>\n<li><em>Royal Decree 311\/2022, of May 3, regulating the National Security Framework<\/em><em style=\"color: #555555;\">\u00a0<\/em>\n<ul>\n<li>Identify potential threats, as well as the impact on business operations that such threats, should they materialize, may cause.<\/li>\n<li>Protect the interests of its key stakeholders (customers, shareholders, employees, and suppliers), its reputation, brand, and value-creating activities.<\/li>\n<li>Work collaboratively with our suppliers and subcontractors to improve the delivery of IT services, service continuity, and information security, thereby enhancing the efficiency of our operations.<\/li>\n<li>To assess and ensure the <strong>technical competence of staff<\/strong>, as well as to ensure their adequate motivation to participate in the continuous improvement of our processes, providing appropriate training and internal communication so that they can implement the best practices defined in the system.<\/li>\n<li>Ensure <strong>that facilities are in good condition and that equipment <\/strong>is adequate, so that they align with the company\u2019s activities, objectives, and goals.<\/li>\n<li>Ensure continuous <strong>analysis <\/strong>of all <strong>relevant processes<\/strong>, establishing the appropriate improvements in each case based on the results obtained and the established objectives.<\/li>\n<li>Structure our management system so that it is easy to understand. Our management system has the following structure:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1291 size-full\" src=\"https:\/\/macguffin.es\/wp-content\/uploads\/2026\/05\/88c29c90-5863-4023-a232-e33a7b2bc642.jpg\" alt=\"\" width=\"886\" height=\"288\" srcset=\"https:\/\/macguffin.es\/wp-content\/uploads\/2026\/05\/88c29c90-5863-4023-a232-e33a7b2bc642.jpg 886w, https:\/\/macguffin.es\/wp-content\/uploads\/2026\/05\/88c29c90-5863-4023-a232-e33a7b2bc642-300x98.jpg 300w, https:\/\/macguffin.es\/wp-content\/uploads\/2026\/05\/88c29c90-5863-4023-a232-e33a7b2bc642-768x250.jpg 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/><\/p>\n<p>Management of our system is entrusted to the Management Officer, and the system will be available in our information system within a repository, which can be accessed according to the access profiles granted in accordance with our current access management procedure.<\/p>\n<p>These principles are adopted by Management, which provides the necessary means and equips its employees with sufficient resources for their implementation, setting them forth and making them publicly available through this Integrated Management Systems Policy.<\/p>\n<p>The security roles or functions defined in ESRI are<\/p>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"225\"><strong>Role<\/strong><\/td>\n<td width=\"444\"><strong>Duties and Responsibilities<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"225\">Information Manager<\/td>\n<td width=\"444\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0 Make decisions regarding the information processed<\/td>\n<\/tr>\n<tr>\n<td width=\"225\">Service Manager<\/td>\n<td width=\"444\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Coordinate the implementation of the system<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Continuously improve the system<\/td>\n<\/tr>\n<tr>\n<td width=\"225\">Safety Officer<\/td>\n<td width=\"444\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Determine the suitability of technical measures<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Provide the best technology for the service<\/td>\n<\/tr>\n<tr>\n<td width=\"225\">System manager<\/td>\n<td width=\"444\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Coordinate the implementation of the system<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Continuously improve the system<\/td>\n<\/tr>\n<tr>\n<td width=\"225\">Management<\/td>\n<td width=\"444\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Provide the necessary resources for the system<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Lead the system<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>This definition is further detailed in the job descriptions and system documents.<\/p>\n<p>The procedure for appointment and renewal shall be ratification by the security committee<\/p>\n<p>The committee for security management and coordination is the body with the greatest responsibility within the information security management system, such that all major decisions related to security are agreed upon by this committee. The members of the information security committee are:<\/p>\n<ul>\n<li>Information Officer.<\/li>\n<li>Head of Services.<\/li>\n<li>Security Officer.<\/li>\n<li>System Manager.<\/li>\n<li>Company Management (partners-managers).<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>These members are appointed by the committee, which is the sole body authorized to appoint, reappoint, and remove them.<\/p>\n<p>The safety committee is an autonomous, executive body with decision-making autonomy and is not required to subordinate its activities to any other part of our company.<\/p>\n<p>This policy is complemented by the other policies, procedures, and documents in effect to implement our management system.<\/p>\n<p>&nbsp;<\/p>\n<p>Madrid, March 11, 2016<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security policy MAC GUFFIN SL, as a company dedicated to event production, is committed to information security and to the proper management of such information, in order to provide all its stakeholders with the highest level of assurance regarding the security of the information used. For all of the above reasons, Management establishes the following [&#8230;]\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1288","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/pages\/1288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/comments?post=1288"}],"version-history":[{"count":3,"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/pages\/1288\/revisions"}],"predecessor-version":[{"id":1294,"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/pages\/1288\/revisions\/1294"}],"wp:attachment":[{"href":"https:\/\/macguffin.es\/en\/wp-json\/wp\/v2\/media?parent=1288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}