Security Policy
MAGMACULTURA Information Security Policy
PUBLIC SUMMARY
MAGMACULTURA considers information and the systems that process it to be essential assets for carrying out its activities and providing its cultural, educational and tourism services. The organisation therefore undertakes to protect them appropriately against threats that could affect their confidentiality, integrity, availability, authenticity and traceability.
This statement summarises the principles and commitments established in the MAGMACULTURA Information Security Policy, approved by Management and mandatory for all members of the organisation, as well as for collaborators, suppliers and third parties who access information or systems within its scope.
MAGMACULTURA has an Information Security Management System designed to ensure the protection of information, continuity of services and appropriate management of security risks. This system is aligned with ISO/IEC 27001 and, where applicable, with Spain’s National Security Framework, regulated by Royal Decree 311/2022.
The scope of information security covers the systems, processes, services, applications, technological infrastructure, networks, devices, facilities and suppliers that support MAGMACULTURA’s activities. In particular, it includes services related to the management of cultural venues, the development of cultural projects, the management of retail shops and customer acquisition through contact centre services.
MAGMACULTURA’s main information security commitments are:
- Protect information and systems against unauthorised access, improper alteration, loss, unavailability or unauthorised use.
- Manage security risks on an ongoing basis, applying measures proportionate to the value of the information, the level of risk and the potential impact on services.
- Implement prevention, detection, response and recovery controls for security incidents.
- Ensure continuity of services and minimise the impact of potential disruptions.
- Comply with applicable legislation, regulations, contractual obligations and requirements relating to information security and data protection.
- Promote staff training and awareness regarding the secure use of information and systems.
- Integrate security throughout the design, acquisition, implementation, operation, maintenance and decommissioning of systems and services.
- Regularly monitor and review the effectiveness of the security measures implemented.
- Maintain a clear structure of responsibilities for information security.
- Continuously improve the Information Security Management System.
Security management is supported by a defined organisational structure that includes governance, oversight and control functions. The Information Security Committee coordinates the security strategy, promotes continuous improvement and ensures the suitability of applicable policies, standards and procedures.
MAGMACULTURA applies a risk-based approach. To this end, it identifies, analyses, assesses and treats risks that may affect information, technological assets and the services provided. Security measures are selected taking into account the results of this analysis, ISMS requirements, international best practices and, where appropriate, the measures established by Spain’s National Security Framework.
Information security is the responsibility of everyone involved in the use, management or administration of MAGMACULTURA systems. For this reason, the organisation promotes awareness, training and compliance with internal security rules, as well as active collaboration in the prevention and reporting of incidents.
Suppliers and third parties that provide services to MAGMACULTURA or access its information must comply with applicable security requirements, maintain appropriate levels of protection and cooperate in the management of incidents, risks and contractual obligations related to information security.
The Information Security Policy will be reviewed periodically, at least once a year, or whenever significant changes occur in the organisation, services, systems, risks or applicable legal and regulatory framework. The purpose of this review is to ensure that the policy remains appropriate, effective and aligned with MAGMACULTURA’s objectives.
Last updated: [15/05/2026]
Approved by: MAGMACULTURA Management