Martínez Caballero Abogados Information Security Policy
Law Firm: MC Abogados (Apna Advocats SLP)
Version: 1.0
Date of Approval: June 26, 2025
Approved by: Diana Caballero Aguirre, CEO and Chief Information Security Officer
Confidentiality Level: Internal
1. Introduction
Information and the systems that manage it are critical assets for MC Abogados. The growing reliance on digital technologies, the handling of sensitive data, and the need to maintain client trust require the establishment of a formal security policy. This policy defines the principles, roles, responsibilities, and controls necessary to protect information from internal and external threats.
2. Mission and Objectives
The purpose of this policy is to ensure the confidentiality, integrity, availability, authenticity, and traceability of the information handled by the firm. Its main objectives are:
- Comply with current regulations (GDPR, LOPDGDD, LSSI).
- Minimize the risk of data breaches or data loss.
- Ensure business continuity.
- Raise the team’s awareness of their role in protecting information.
3. Scope
It applies to all systems, individuals, devices, and processes involved in the processing of information at MC Abogados. It includes both digital and paper-based information, regardless of format or medium.
4. Regulatory Framework
This policy is based on:
- Regulation (EU) 2016/679 (GDPR).
- Organic Law 3/2018 on Data Protection and the Guarantee of Digital Rights.
- Law 34/2002 (LSSI).
- Principles of the ISO/IEC 27001 standard.
5. Classification of Information
Office information will be classified into three levels:
- Confidential: records, health information, minors, criminal proceedings.
- Internal use: internal communications, human resources, working documents.
- Public: content published on the web and social media.
6. Security Organization
- Security Officer: Diana Caballero Aguirre (CEO).
- Data Protection Officer: Equal Data Protection (external).
- Digital Channels Manager: Digital Marketing Manager.
- IT Support: external provider, on an as-needed basis.
All staff members are responsible for complying with this policy and reporting incidents or vulnerabilities.
7. Risk Management
Although no formal audit has been conducted, the firm commits to:
- Review the risks at least once a year.
- Respond to incidents that affect security.
- Assess technological or regulatory changes.
8. Technical Controls and Access
- Strong passwords and two-step authentication.
- Encrypted storage on Google Drive and OneDrive.
- Website Protection with Wordfence and Limit Login Attempts.
- Controlled remote access and responsible use of personal devices.
9. Incident Management
Incidents must be reported immediately to the Security Officer. Their impact will be assessed, and the AEPD will be notified if appropriate. All cases will be documented to prevent future occurrences.
10. Relationships with Third Parties
Third parties who access the firm’s data must sign confidentiality agreements and comply with this policy. Upon termination of the relationship, they must delete all information in accordance with auditable safeguards.
11. Training and Awareness
The entire team will receive annual basic training in cybersecurity, best practices, and data protection. A culture of active security will be promoted.
12. Updates and Continuous Improvement
This policy will be reviewed annually or whenever significant changes occur. All modifications will be approved by management and communicated to staff.
13. Supplementary Documentation
This policy will be implemented through:
- Internal Safety Policies.
- Safe Work Procedures.
- Best Practice Guides for Employees.
Approved by:
Diana Caballero Aguirre
CEO and Chief Information Security Officer