Protecting information and information assets is crucial for the strategic success and sustainability of the business of Redes Energéticas Nacionais, SGPS, S.A. (“REN SGPS”) and of companies in which it holds, directly or indirectly, a majority stake in the share capital, more than half of the voting rights or the possibility of appointing at least half of the members of the management or supervisory body, irrespective of whether its registered office is located in Portugal or abroad (hereinafter shorty and jointly referred to as “REN”).
With this purpose, REN operates an Information Security Management System (hereinafter referred to as “ISMS”) that provides all the necessary tools for the secure management of information and systems. Through a risk-based approach and continuous improvement, it ensures the confidentiality, integrity, and availability of data. Safeguarding these three pillars of information security serves as a guarantee for the organisation's image, reputation, and credibility, as well as for its production processes, with both partners and clients.
This Policy applies to all REN employees and members of its governing bodies, irrespective of their contractual relationship or role, as well as, where applicable, to attorneys, authorised representatives, service providers, contractors and suppliers who are authorised in any way to act for and/or on behalf of REN, or who access, process, store, transmit or manage REN information or information assets.
Its scope encompasses all information for which REN is responsible, irrespective of its format or medium, as well as the information systems, applications, technological infrastructure, networks, equipment, services and processes supporting the business, including corporate, operational, industrial and support environments, whether owned by REN or provided by third parties.
REN establishes that information security management is underpinned by a governance model with clearly defined responsibilities, appropriate controls and a commitment to continuous improvement, in accordance with applicable legal, regulatory and standards-based requirements.
REN adheres to the principles outlined in the ISO/IEC 27001 information security framework, and commits to:
a) Upholding the principles set out in this Policy and ensuring its approval, publication and communication to all intended recipients;
b) Providing all the necessary resources for the implementation of information security management processes and activities, namely concerning the awareness and education of both internal and external employees regarding the subject and their roles in the effectiveness of the ISMS;
c) Ensuring the definition, implementation, and review of the information security management strategy, and guaranteeing its proper alignment with REN's business objectives;
d) Ensuring that the ISMS achieves the intended results;
e) Promoting continuous improvement in a structured and systematic manner.
REN sets forth the following information security objectives:
i. Ensure compliance with the legal and regulatory requirements applicable to the business, as stipulated in national and EU legislation;
ii. Ensure the integration of information security requirements and objectives into business functions and processes, as well as operations;
iii. Ensure the availability, integrity, and confidentiality of information, services, and infrastructure, both under normal operating conditions and in exceptional circumstances;
iv. Ensure that the security measures of the ISMS are understandable, effective, and have an appropriate cost-benefit ratio;
v. Establish monitoring and measurement processes that ensure the proper implementation and performance of information security controls.
REN's ISMS identifies, establishes, operationalises, monitors, and ensures the continuous improvement of information security requirements, among others, in the following domains:
a) Information security organisation
provide guidance and support for information security in accordance with relevant business requirements, laws, and regulations.
b) Mobile devices and remote access
ensure security in remote access, telecommuting, and the use of mobile devices.
c) Information security in human resources management
provide all necessary information to ensure that employees and service providers understand their responsibilities in the context of Information Security.
d) Information asset management
identify information assets and assign appropriate protection responsibilities, ensuring that information receives the appropriate level of protection based on its importance to the Organisation and preventing the unauthorised disclosure, modification, removal or deletion of stored information.
e) Access control
restrict access to information and information processing resources, ensuring that authorised users have access, while preventing unauthorised access to systems and services.
f) Cryptography
ensure the appropriate and effective use of cryptography to protect the confidentiality, authenticity, and/or integrity of information.
g) Physical and environmental security
prevent unauthorised physical access, damage, and interference with the Organisation's information and information processing resources.
h) Technical Vulnerability Management
ensure that vulnerability scans and penetration tests are conducted regularly, and that mandatory deadlines are established for applying patches based on criticality.
i) Information Backups
ensure that backups are performed comprehensively and that restoration tests are conducted monthly;
j) Event Logging
ensure the centralisation and correlation of security logs and the definition of rules governing their generation and management.
k) Anti-malware/Antivirus
ensure that workstations and servers are protected against malware, with automatic signature updates and full weekly scans.
l) Communications security
ensure the protection of information in networks and their information processing resources, maintaining the security of information transferred within the Organisation and to any external entities.
m) Acquisition, development, and maintenance of systems
ensure that information security is an integral part of information systems throughout their entire lifecycle. Information security is designed and implemented within the scope of the systems and information development lifecycle.
n) Information security in supplier relationships
ensure the protection of the Organisation's assets that are accessible to suppliers, maintaining the agreed-upon level of information security and service availability, in alignment with supplier agreements.
o) Information security incident management
ensure a consistent and effective approach to the management of information security incidents, including the reporting of security events and vulnerabilities.
p) Information security aspects of business continuity management
incorporate information security continuity into REN’s business continuity management systems, ensuring the availability of information processing resources.
q) Compliance
prevent breaches of legal, statutory, regulatory or contractual obligations relating to information security, as well as of any security requirements.
REN has an annual Audit Plan, approved by the Information Security Management System (ISMS) Management Committee, which includes internal and external audits of both the IT infrastructure and the ISMS.
The Information Security Management System policies are approved by REN’s Board of Directors or Executive Committee. The Information Security Manager is responsible for overseeing and assessing the implementation of the ISMS, reporting on its performance to top management and ensuring that the system complies with the requirements of the ISO/IEC 27001 standard and applicable legislation.
In addition, the following responsibilities are assigned to the Board of Directors, the Executive Committee, the ISMS Management Committee and the Audit Committee:
At operational and governance level, the Executive Committee ensures the commitment and the financial, technical and human resources required for the effective operation of the ISMS. It is responsible for appointing individuals to designated roles, delegating the appropriate authority and monitoring the system’s performance through performance indicators. In this way, it ensures not only regulatory compliance but also the continual improvement and resilience of the organisation’s information infrastructure.
As part of its monitoring and continual improvement responsibilities, the Committee periodically reviews the ISMS, validates audit programmes and analyses performance and risk indicators. It also serves as an essential communication link by reporting its activities to the Risk Management Committee and promoting security awareness across the business units. By contributing to the identification of vulnerabilities and approving process improvements, the ISMS Management Committee ensures the continual development and effectiveness of information protection within the organisation.
REN maintains an incident response process aligned with recognised best practices.
Information about the cybersecurity incident response service of Redes Energéticas Nacionais, SGPS, S.A (REN) can be found at: