Bizneo HR is a company specialised in the development and provision of technological software solutions for human resources management (HR Tech), whose mission is to facilitate the digitalisation and optimisation of people management processes for organisations, improving operational efficiency and employee experience through secure, scalable and compliance-oriented SaaS platforms. The strategic objectives of Bizneo in terms of information security are to guarantee the availability, integrity, confidentiality, authenticity and traceability of information managed on behalf of its clients, ensure the continuity of services provided and maintain the trust of its clients and stakeholders.
Bizneo depends on information systems. These systems are administered with diligence, taking appropriate measures to protect them against accidental or deliberate damage that could affect the availability, integrity, confidentiality, authenticity or traceability of the information processed and the services provided.
Aware of the importance of information security, and in line with the path defined by our own identity, Bizneo has driven the establishment of an information security management system (hereinafter, ISMS) under the ISO 27001 framework and in accordance with the requirements of Royal Decree 311/2022, of 3 May, which regulates the National Security Framework in the field of Electronic Administration (hereinafter, ENS), in order to identify, assess and minimise the risks to which its information and that of its clients is exposed, as well as to guarantee compliance with the established objectives.
The objective of this Security Policy is to guarantee the quality of information and the continuous provision of services, acting preventively and supervising daily activity, as well as providing a reference framework for the establishment of security objectives that allow Bizneo to develop a company culture, a way of working and making decisions, aligned with information security and in which respect for personal data is a constant.
Information systems are protected against rapidly evolving threats, whose potential damage affects the confidentiality, integrity, availability, intended use (traceability) and value of information (authenticity) of services. To defend against these threats, a strategy has been defined that adapts to changes in environmental conditions to guarantee the continuous provision of our services.
The different departments of Bizneo ensure that security is an integral part of every stage of the system lifecycle, from conception to decommissioning, including development or acquisition decisions and operational activities.
Bizneo is prepared to prevent, detect, react to and recover from incidents, in accordance with Article 12 of the ENS, and has therefore taken action to strengthen different aspects of information security:
Bizneo will carry out its activities in accordance with the applicable legal and regulatory framework. It commits to complying with all relevant laws and regulations related to information security, including, but not limited to, those indicated in the document "Applicable ISMS Legislation".
Bizneo integrates the ENS and ISO 27001 into the organisation's security policy to provide a more complete and robust structure for addressing specific aspects of information security, both at national and international level. Furthermore, the adoption of these standards improves the company's credibility, demonstrating its commitment to best security practices.
This security policy has been established in accordance with the basic principles set out in Chapter II of Royal Decree 311/2022 and has been developed applying the following minimum requirements:
In accordance with the National Security Framework (ENS), our organisation adopts the following basic principles to guarantee information security:
Bizneo has identified and defined the security roles and functions necessary to guarantee the protection of information. Each role has clearly defined responsibilities (ENS Authority, Responsibility and Competence).
Bizneo has appointed a Security Committee that will oversee the monitoring and compliance of the ISMS. The Security Committee is made up of corporate and management positions within the organisation. The list of constituent members of the Security Committee is defined in the procedure created for this purpose (PS00 - ISMS Manual). Said Security Committee will have the following functions and responsibilities:
Likewise, the functions and responsibilities of the Security Manager, the Information Manager, the Services Manager, the Artificial Intelligence Manager and the Systems Manager have been defined, as well as their relationship with the Security Committee.
In order to describe the process and hierarchy for resolving authority conflicts that may arise during ENS management between critical profiles with security responsibilities, Bizneo has defined the functions for conflict resolution between responsible parties, applicable to all specific ENS management profiles (see ENS Authority, Responsibility and Competence).
The Information Security Manager, the Service Manager, the Information Manager, the Artificial Intelligence Manager and the Systems Manager will be appointed by Management at the proposal of the Security Committee. These appointments will be reviewed every 2 years or when a position becomes vacant.
Positions with functions or responsibilities related to information security, as well as the escalation structure in the absence of any of these responsible parties, are defined in the security organisational chart and in the roles, responsibilities, authority and competence matrix of the ISMS, which are internal documents of a confidential nature. Escalation is carried out following the hierarchical lines established in those documents.
All systems subject to this Policy have been assessed through a risk analysis, evaluating the threats and risks to which they are exposed. This analysis will be repeated:
Bizneo, through the drafting of the corresponding procedure (PS00 - ISMS Manual), has defined the criteria for determining the level of security required in each dimension. To this end, the essential elements — information and services — are analysed, with the criteria that the person responsible for each type of information and each service may use revolving around them, considering that the authority to determine the category of the system lies with the person responsible for it.
The National Security Framework establishes in its Annex II security measures conditioned on the assessment of the security level in each dimension and on the security category (Article 40) of the respective information system. In turn, the security category of the system is calculated based on the highest security level of the assessed dimensions.
All members of Bizneo are obliged to know and comply with this Information Security Policy and the Security Regulations, with the Security Committee being responsible for applying the necessary measures to ensure that the information reaches those affected.
All employees will receive a security awareness session at least once a year. Likewise, a continuous awareness programme will be established to raise awareness among all members of Bizneo, particularly new starters, which is aligned with other implemented standards.
Personnel dedicated to security tasks are appropriately qualified, given the sensitivity and complexity of some of those tasks. This applies to all phases of the security process lifecycle (installation, maintenance, incident management and decommissioning). To this end, staff receive the specific training necessary to guarantee the security of information technologies applicable to systems and services subject to the ENS.
Logically, the same requirements demanded internally must be required of any supplier providing security-related services. To this end, Bizneo has driven a procedure for evaluating suppliers so as to ensure a level of security similar to that required by the organisation.
The first step in ensuring that information and systems are protected is to limit access to them. Therefore, it has been defined who, and to what extent, will have access to resources, so that each person has the access necessary to carry out their tasks, but not to equipment or data that should not be within their reach.
Likewise, the information systems of Bizneo have authorisation mechanisms to allow, deny and revoke access when necessary.
The facilities are protected against damage that could affect the systems they house and against access by unauthorised persons. Access to our facilities is secured and regulated by the procedure established for this purpose.
Bizneo establishes the business and information security requirements for its information systems, whether new or existing and being expanded or improved.
Thus, any new acquisition of security products and services that could affect the ISMS must be assessed beforehand, from a functional and security requirements perspective. Following validation, formal testing of the product will proceed, indicating whether it meets the requirements.
Any contracted service must be assessed before going into production in order to ensure that it meets the minimum security requirements defined in this Information Security Policy and the applicable Security Regulations.
The Information Security System implemented at Bizneo follows the Principle of Least Privilege, whereby users of the system are granted the minimum access levels (or permissions) necessary to perform their functions, with the objective of restricting access to information and resources solely to what is strictly necessary to fulfil a specific task.
This principle of least privilege ensures that each party (whether a process, a user or a programme) can only access what is essential for its legitimate purpose, without granting unnecessary privileges. However, this principle is not limited solely to human user access — it also applies to applications, systems or connected devices that require privileges to carry out necessary tasks.
By limiting privileges, exposure to cyberattacks is reduced and "privilege accumulation" is avoided.
To guarantee the integrity of information systems at all times, any physical or logical change is made only after formal approval and through a formal procedure.
To this end, systems are updated in a controlled manner and in accordance with the security status required at each moment. Changes in manufacturer specifications, the emergence of new vulnerabilities, and the issuing of updates and patches affecting systems are analysed in order to take the necessary measures to prevent systems and their security level from degrading, while also managing the risks introduced by the changes to be made.
A significant part of the information lifecycle corresponds to its storage and transport. Information must be protected at all times. To this end, appropriate procedures have been developed, covering both information in electronic and paper format, as well as policies for the handling and processing of information.
Prevention against other interconnected information systems is a crucial aspect for Bizneo. To this end, measures have been established to guarantee security when information systems connect with each other, taking into account aspects such as perimeter protection, access control and the proper activity logging needed to detect possible anomalies or unusual behaviour in the interconnection.
Any connection to or from interconnected services will be carried out following the guidelines defined in the CCN-STIC guides published for this purpose.
The company monitors its information and processing systems, recording them as security incidents and reviewing the operation and fault logs of its systems to identify problems. Thus, the activities of monitoring the use of Bizneo's systems comply with legal privacy requirements and are used to verify the effectiveness of the implemented security controls and compliance with the access control policy.
Likewise, corporate devices, through the use of next-generation antivirus software with centralised management, have tools for the protection, detection, recovery and elimination of malicious code.
The management of Bizneo has established a formal notification procedure whereby all personnel must notify security-related incidents through the established channel immediately and without delay. This allows for a rapid and effective response to security incidents and weaknesses.
The company has established a procedure to act against interruptions to business activity and protect critical processes from the effects of major failures in information systems and ensure their immediate restoration. To this end, a business continuity plan has been implemented (see PROSI-11 Business Continuity Plan) to reduce the impact on Bizneo's infrastructure, and consequently on the company, and the recovery of information assets (whether due to accidents, equipment failure, deliberate acts, etc.) so that departmental processes reach an acceptable level of continuity through corrective and preventive recovery measures.
Management particularly values and establishes as its main criterion for risk estimation the assessment of the confidentiality, integrity and availability of the critical information of the company and its clients, as well as ensuring the traceability and authenticity thereof.
It therefore commits to continuously developing, implementing, maintaining and improving this Security Policy and its Management System with the objective of continuous improvement in the way services are provided and information is handled.
Bizneo processes personal data. In this regard, and in compliance with applicable data protection legislation, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as risks of varying probability and severity to the rights and freedoms of natural persons, Bizneo has applied appropriate technical and organisational measures to guarantee a level of security appropriate to the risk, including, where applicable, among others:
The security documentation of the system will follow the guidelines established by Bizneo. Measures will be implemented to structure, manage and control access to security documentation, guaranteeing its integrity and confidentiality. Access will be restricted to authorised personnel and will be carried out in accordance with the defined access policies. The necessary permissions will be assigned to persons who may have access to this documentation. Documentation will be organised into folders and the internal folder structure will follow, where deemed appropriate to facilitate classification, the sections of the respective standards and regulations.
The documentation generated for the Information Security Management System of Bizneo will follow the identification structure defined in the Manual created for this purpose (PS00 - ISMS Manual).
This Information Security Policy will be available as documented information and will be communicated within the organisation. Furthermore, it will be shared with relevant interested parties, such as authorities, operators and public transport users, as appropriate.
This policy will be reviewed annually or sooner if there are significant changes in the operational or technological environment of Bizneo. Senior management commits to keeping this policy aligned with the company's objectives and applicable information security requirements.
This Information Security Policy will always be aligned with the general policies of the company and with those that serve as a framework for other internal management systems, such as quality policies.
In Madrid, 26 June 2026
Santiago Salas
CEO Bizneo HR