November 30, International Computer Security Day: this is how Fraternidad-Muprespa protects it

General
Autor
Fraternidad-Muprespa

Every November 30th the  International Information Security Day, a date that has been commemorated since 1998 and that focuses on raising awareness about cyberattacks and computer crimes, as well as the importance of protecting personal data and sensitive information.

Throughout this year 2024, Fraternidad-Muprespa has successfully passed two external audits within the framework of the international standard ISO 27001 and the National Security Scheme (ENS) according to Royal Decree 311/2022. These milestones reaffirm the entity's commitment to the rigorous management of information security and the protection of digital assets, which are aligned with the highest international and national standards.

The password management policy associated with the staff's corporate credentials has also been reinforced. This update includes the implementation of more robust requirements for the creation, storage and renewal of passwords, as well as the use of advanced technologies to ensure their protection. These measures seek to minimize the risks associated with unauthorized access and further strengthen the security of systems and data.

As explained Luis Martínez del Pino, director of the Information Systems Security Department at

This is an additional layer of protection that combines the use of traditional credentials with a second verification factor, ensuring that only authorized users can access systems. The deployment of this technology reinforces the Mutua's ability to prevent unauthorized access and safeguard our organization's critical information.”.

Additionally, we have launched a new comprehensive process for the management and control of phishing attempts, thus reinforcing protection against this type of cyber threats.

In addition, Digital Certificates continue to be issued to employees, which enables them to sign documents electronically, as well as carry out different operations and personal procedures through the Internet.

Other recurring initiatives have been carried out successfully, as del Pino recalls, citing, among other examples, “ audits of access to sensitive data, ethical hacking processes, cybersecurity training to raise employee awareness, improvement of management policies and control of access to Internet sites, or the maintenance and continuous improvement of the Comprehensive Management System”.

All the initiatives described above", concludes ,

They allow us to strengthen the pillars that support our operational efficiency, information security and quality at all levels..

What did you think of the content?