Public Policy on Information Security

Information Security Management System

Public Policy on Information Security

Protecting information and information assets is crucial for the strategic success and sustainability of the business of Redes Energéticas Nacionais, SGPS, S.A. (“REN SGPS”) and of companies in which it holds, directly or indirectly, a majority stake in the share capital, more than half of the voting rights or the possibility of appointing at least half of the members of the management or supervisory body, irrespective of whether its registered office is located in Portugal or abroad (hereinafter shorty and jointly referred to as “REN”).

With this purpose, REN operates an Information Security Management System (hereinafter referred to as “ISMS”) that provides all the necessary tools for the secure management of information and systems. Through a risk-based approach and continuous improvement, it ensures the confidentiality, integrity, and availability of data. Safeguarding these three pillars of information security serves as a guarantee for the organisation's image, reputation, and credibility, as well as for its production processes, with both partners and clients.

This Policy applies to all REN employees and members of its governing bodies, irrespective of their contractual relationship or role, as well as, where applicable, to attorneys, authorised representatives, service providers, contractors and suppliers who are authorised in any way to act for and/or on behalf of REN, or who access, process, store, transmit or manage REN information or information assets.

Its scope encompasses all information for which REN is responsible, irrespective of its format or medium, as well as the information systems, applications, technological infrastructure, networks, equipment, services and processes supporting the business, including corporate, operational, industrial and support environments, whether owned by REN or provided by third parties.

REN establishes that information security management is underpinned by a governance model with clearly defined responsibilities, appropriate controls and a commitment to continuous improvement, in accordance with applicable legal, regulatory and standards-based requirements.

Information Security Principles

REN adheres to the principles outlined in the ISO/IEC 27001 information security framework, and commits to:

a)    Upholding the principles set out in this Policy and ensuring its approval, publication and communication to all intended recipients;

b)    Providing all the necessary resources for the implementation of information security management processes and activities, namely concerning the awareness and education of both internal and external employees regarding the subject and their roles in the effectiveness of the ISMS;

c)     Ensuring the definition, implementation, and review of the information security management strategy, and guaranteeing its proper alignment with REN's business objectives;

d)    Ensuring that the ISMS achieves the intended results;

e)    Promoting continuous improvement in a structured and systematic manner.

Information Security Objectives

REN sets forth the following information security objectives:

     i.        Ensure compliance with the legal and regulatory requirements applicable to the business, as stipulated in national and EU legislation;

    ii.        Ensure the integration of information security requirements and objectives into business functions and processes, as well as operations;

   iii.        Ensure the availability, integrity, and confidentiality of information, services, and infrastructure, both under normal operating conditions and in exceptional circumstances;

   iv.        Ensure that the security measures of the ISMS are understandable, effective, and have an appropriate cost-benefit ratio;

     v.       Establish monitoring and measurement processes that ensure the proper implementation and performance of information security controls.

Information Security Domains

REN's ISMS identifies, establishes, operationalises, monitors, and ensures the continuous improvement of information security requirements, among others, in the following domains:

a)    Information security organisation

provide guidance and support for information security in accordance with relevant business requirements, laws, and regulations.

b)    Mobile devices and remote access

ensure security in remote access, telecommuting, and the use of mobile devices.

c)     Information security in human resources management

provide all necessary information to ensure that employees and service providers understand their responsibilities in the context of Information Security.

d)    Information asset management

identify information assets and assign appropriate protection responsibilities, ensuring that information receives the appropriate level of protection based on its importance to the Organisation and preventing the unauthorised disclosure, modification, removal or deletion of stored information.

e)    Access control

restrict access to information and information processing resources, ensuring that authorised users have access, while preventing unauthorised access to systems and services.

f)     Cryptography

ensure the appropriate and effective use of cryptography to protect the confidentiality, authenticity, and/or integrity of information.

g)    Physical and environmental security

prevent unauthorised physical access, damage, and interference with the Organisation's information and information processing resources.

h)    Technical Vulnerability Management

ensure that vulnerability scans and penetration tests are conducted regularly, and that mandatory deadlines are established for applying patches based on criticality.

i)      Information Backups

ensure that backups are performed comprehensively and that restoration tests are conducted monthly;

j)      Event Logging

ensure the centralisation and correlation of security logs and the definition of rules governing their generation and management.

k)     Anti-malware/Antivirus

ensure that workstations and servers are protected against malware, with automatic signature updates and full weekly scans.

l)     Communications security

ensure the protection of information in networks and their information processing resources, maintaining the security of information transferred within the Organisation and to any external entities.

m)     Acquisition, development, and maintenance of systems

ensure that information security is an integral part of information systems throughout their entire lifecycle. Information security is designed and implemented within the scope of the systems and information development lifecycle.

n)    Information security in supplier relationships

ensure the protection of the Organisation's assets that are accessible to suppliers, maintaining the agreed-upon level of information security and service availability, in alignment with supplier agreements.

o)     Information security incident management

ensure a consistent and effective approach to the management of information security incidents, including the reporting of security events and vulnerabilities.

p)   Information security aspects of business continuity management

incorporate information security continuity into REN’s business continuity management systems, ensuring the availability of information processing resources.

q)    Compliance

prevent breaches of legal, statutory, regulatory or contractual obligations relating to information security, as well as of any security requirements.

Audits

REN has an annual Audit Plan, approved by the Information Security Management System (ISMS) Management Committee, which includes internal and external audits of both the IT infrastructure and the ISMS.

Responsibility and Authority

The Information Security Management System policies are approved by REN’s Board of Directors or Executive Committee. The Information Security Manager is responsible for overseeing and assessing the implementation of the ISMS, reporting on its performance to top management and ensuring that the system complies with the requirements of the ISO/IEC 27001 standard and applicable legislation.

In addition, the following responsibilities are assigned to the Board of Directors, the Executive Committee, the ISMS Management Committee and the Audit Committee:

  • Board of Directors and Executive Committee (EC): Within the scope of the powers delegated to them, the Board of Directors and the EC hold strategic responsibility for cybersecurity and are responsible for approving and overseeing risk management measures in accordance with applicable legislation. These bodies define the organisation’s vision by aligning its business objectives with its security strategy, approving the fundamental ISMS policies and actively promoting a security culture through ongoing awareness-raising and training initiatives for all employees.

    At operational and governance level, the Executive Committee ensures the commitment and the financial, technical and human resources required for the effective operation of the ISMS. It is responsible for appointing individuals to designated roles, delegating the appropriate authority and monitoring the system’s performance through performance indicators. In this way, it ensures not only regulatory compliance but also the continual improvement and resilience of the organisation’s information infrastructure.

  • Information Security Management System Management Committee (ISMS Management Committee): The ISMS Management Committee acts as the technical and operational oversight body, ensuring that the security strategy is aligned with the REN Group’s mission and the applicable regulatory framework. The Committee is responsible for supporting the definition of risk management measures for submission to the Executive Committee, approving internal standards and procedures, and managing exceptions to security policies. It also has the authority to appoint individuals to specific management roles and to subdelegate responsibilities, thereby ensuring the effective governance of the system.

    As part of its monitoring and continual improvement responsibilities, the Committee periodically reviews the ISMS, validates audit programmes and analyses performance and risk indicators. It also serves as an essential communication link by reporting its activities to the Risk Management Committee and promoting security awareness across the business units. By contributing to the identification of vulnerabilities and approving process improvements, the ISMS Management Committee ensures the continual development and effectiveness of information protection within the organisation.

  • Audit Committee: The Audit Committee is responsible for overseeing the effectiveness of the risk management system, which includes information security, and the internal control system. In performing this role, it monitors and assesses these systems, issues opinions and submits proposals to improve their operation, thereby ensuring that the risks effectively assumed by REN are consistent with the objectives established by the Board of Directors and the Executive Committee.

Incident Response

REN maintains an incident response process aligned with recognised best practices.

Information about the cybersecurity incident response service of Redes Energéticas Nacionais, SGPS, S.A (REN) can be found at:

https://www.ren.pt/en-gb/csirt/rfc-2350

Newsletter

Receive all the details of the operation,
trends and news we share
with all the energy.

Frequency *
0:00
/
0:00