<rdf:RDF
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:env="https://www.caib.es/eboibfront/rdf/schema/enviament/1.0/"
    xmlns:eli="https://www.caib.es/eboibfront/rdf/schema/eli/1.0/"
    xmlns:rann="https://www.caib.es/eboibfront/rdf/schema/relAnnexe/1.0/" > 
  <rdf:Description rdf:about="https://intranet.caib.es/eboibfront/ca/2025/12044/695850/acord-del-consell-rector-de-l-institut-d-estadisti/xml">
    <env:contingut rdf:parseType="Literal">![CDATA[&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;D&amp;apos;acord amb l&amp;apos;article 30.32 de l&amp;apos;Estatut d&amp;apos;autonomia de les Illes Balears, la Comunitat Autònoma té competència exclusiva en les &lt;/span&gt;estadístiques d&amp;apos;interès per a la comunitat autònoma i en l&amp;apos;organització i gestió d&amp;apos;un sistema estadístic propi.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;La Llei 3/2002, de 17 de maig, d&amp;apos;estadística de les Illes Balears, va crear, mitjançant l&amp;apos;article 32, l&amp;apos;Institut d&amp;apos;Estadística de les Illes Balears (IBESTAT) com a organisme autònom adscrit a la conselleria competent en matèria d&amp;apos;economia. Les funcions de l&amp;apos;Institut es recullen en l&amp;apos;article 34 de la Llei&amp;nbsp;3/2002 esmentada, les quals suposen assumir &lt;/span&gt;la planificació, la normalització, la coordinació i la gestió del sistema estadístic de les Illes Balears, així com dur a terme les activitats estadístiques que se li encomanin en els programes anuals d&amp;apos;estadística, i promoure la difusió de les estadístiques relatives a la comunitat autònoma de les Illes Balears.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;D&amp;apos;altra banda, l&amp;apos;article 13 de la Llei 39/2015, d&amp;apos;1 d&amp;apos;octubre, del procediment administratiu comú de les administracions públiques, estableix els drets de les persones en les seves relacions amb les administracions públiques; concretament en la lletra &lt;em&gt;h)&lt;/em&gt; estableix el dret a la seguretat i la confidencialitat de les dades que figurin en els fitxers, sistemes i aplicacions de les administracions públiques.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;La Llei 40/2015, d&amp;apos;1 d&amp;apos;octubre, de règim jurídic del sector públic, ha ampliat l&amp;apos;àmbit d&amp;apos;aplicació de l&amp;apos;Esquema Nacional de Seguretat (ENS) a tot el sector públic, i estableix en l&amp;apos;article 3, relatiu als principis generals, la necessitat que les administracions públiques es relacionin entre si i amb els seus òrgans, organismes públics i entitats vinculats o dependents a través de mitjans electrònics, que garanteixin la interoperabilitat i la seguretat de les solucions i els sistemes adoptats per cadascuna i la protecció de les dades personals, i facilitin la prestació de serveis als interessats preferentment per aquests mitjans, i assenyala l&amp;apos;ENS com a instrument fonamental per assolir aquests objectius en l&amp;apos;article 156.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;L&amp;apos;IBESTAT depèn dels sistemes basats en les tecnologies de la informació i la comunicació (TIC) per aconseguir els seus objectius. Aquests sistemes s&amp;apos;han d&amp;apos;administrar amb diligència, i s&amp;apos;han de prendre les mesures adequades per protegir-los contra danys accidentals o deliberats que puguin afectar la disponibilitat, la traçabilitat, l&amp;apos;autenticitat, la integritat o la confidencialitat de la informació tractada o dels serveis prestats. L&amp;apos;objectiu de la seguretat de la informació és garantir la qualitat de la informació i la prestació continuada dels serveis, actuant preventivament, supervisant l&amp;apos;activitat diària i reaccionant amb prestesa als incidents.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;Els diferents departaments han de garantir que la seguretat de les TIC és una part integral de cada etapa del cicle de vida del sistema, des de la concepció fins a la retirada de servei, passant per les decisions de desenvolupament o adquisició i les activitats d&amp;apos;explotació. Els requisits de seguretat i les necessitats de finançament han de ser identificats i inclosos en la planificació, en la sol·licitud d&amp;apos;ofertes i en els plecs de licitació per a projectes de TIC. La informació i els serveis prestats estan sotmesos a amenaces i riscs provinents d&amp;apos;accions malintencionades o il·lícites, errors o fallades i accidents o desastres.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;L&amp;apos;Esquema Nacional de Seguretat, regulat pel Reial decret 311/2022, de 3 de maig, determina la política de seguretat que s&amp;apos;ha d&amp;apos;aplicar en la utilització dels mitjans electrònics. L&amp;apos;ENS està constituït pels principis bàsics i els requisits mínims per a una protecció adequada de la informació. L&amp;apos;adequació ordenada a l&amp;apos;ENS requereix el tractament de les qüestions següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;a)&lt;/em&gt; Preparar i aprovar la política de seguretat, incloent-hi la definició de rols i l&amp;apos;assignació de responsabilitats.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;b)&lt;/em&gt; Categoritzar els sistemes atenent a la valoració de la informació manejada i dels serveis prestats.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;c)&lt;/em&gt; Dur a terme l&amp;apos;anàlisi de riscs, incloent-hi la valoració de les mesures de seguretat existents.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;d)&lt;/em&gt; Preparar i aprovar la declaració d&amp;apos;aplicabilitat de les mesures de l&amp;apos;annex II de l&amp;apos;ENS.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;e)&lt;/em&gt; Elaborar un pla d&amp;apos;adequació per millorar la seguretat, sobre la base de les insuficiències detectades, que ha d&amp;apos;incloure terminis estimats d&amp;apos;execució.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;f)&lt;/em&gt; Implantar, operar i monitorar les mesures de seguretat a través de la gestió continuada de la seguretat corresponent.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;g)&lt;/em&gt; Auditar la seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;h)&lt;/em&gt; Informar sobre l&amp;apos;estat de la seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;D&amp;apos;acord amb l&amp;apos;article 12 del Reial decret 311/2022 esmentat, cada administració pública ha de disposar d&amp;apos;una política de seguretat formalment aprovada per l&amp;apos;òrgan competent. Així mateix, cada òrgan o entitat amb personalitat jurídica pròpia comprès en l&amp;apos;àmbit subjectiu de l&amp;apos;article 2 del Reial decret esmentat ha de disposar d&amp;apos;una política de seguretat formalment aprovada per l&amp;apos;òrgan competent.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;La Comissió Directora de Seguretat de la Informació de la Comunitat Autònoma de les Illes Balears va emetre l&amp;apos;informe corresponent sobre l&amp;apos;esborrany de la política de seguretat de l&amp;apos;IBESTAT en la sessió de 28 d&amp;apos;octubre de 2024, d&amp;apos;acord amb el Decret 97/2006, de 24 de novembre, pel qual es creen i es regulen les comissions per a la millora contínua de la seguretat de la informació en l&amp;apos;Administració de la Comunitat Autònoma de les Illes Balears.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Per tot això, el Consell Rector en la sessió del dia 17 de desembre de 2024 adopta el següent&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;Acord&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;Primer.&lt;/span&gt;&lt;/strong&gt;&lt;span style="color: black"&gt; Aprovar la política de seguretat de la informació de &lt;/span&gt;&lt;span style="color: black"&gt;l&amp;apos;Institut d&amp;apos;Estadística de les Illes Balears, que s&amp;apos;incorpora com annex a &lt;/span&gt;&lt;span style="color: black"&gt;aquest Acord.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;Segon.&lt;/span&gt;&lt;/strong&gt;&lt;span style="color: black"&gt; Disposar que &lt;/span&gt;&lt;span style="color: black"&gt;aquest Acord&lt;/span&gt;&lt;span style="color: black"&gt;, juntament amb l&amp;apos;annex,&lt;em&gt; &lt;/em&gt;es publiqui en el &lt;em&gt;Butlletí Oficial de les Illes Balears&lt;/em&gt; i en el portal web &lt;/span&gt;de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;Tercer.&lt;/span&gt;&lt;/strong&gt; &lt;span style="color: black"&gt;Establir que &lt;/span&gt;&lt;span style="color: black"&gt;aquest Acord produeixi efectes des de la data de la publicació en el &lt;em&gt;Butlletí Oficial de les Illes Balears&lt;/em&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Palma, en la data de la signatura electrònica&lt;em&gt; (14 de gener de 2025)&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;strong&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;La secretària suplent del Consell Rector de l&amp;apos;IBESTAT&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;&lt;span style="display: block; line-height: 1.6; margin-bottom: 0px; margin-top: 0px; width: 100%"&gt; &lt;/span&gt;Laura Alomar Llorente&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;ANNEX&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;&lt;span style="display: block; line-height: 1.6; margin-bottom: 0px; margin-top: 0px; width: 100%"&gt; &lt;/span&gt;Política de seguretat de la informació de l&amp;apos;Institut d&amp;apos;Estadística de les Illes Balears&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;1. Objecte&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;1.1. Constitueix l&amp;apos;objecte d&amp;apos;&lt;span style="color: black"&gt;aquest Acord&lt;/span&gt; fixar la política de seguretat de la informació (PSI) en l&amp;apos;àmbit de l&amp;apos;Institut d&amp;apos;Estadística de les Illes Balears (IBESTAT), així com establir el marc organitzatiu, operacional i tecnològic d&amp;apos;aquesta entitat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;1.2. La política de seguretat de la informació identifica responsabilitats i estableix principis i directrius per assolir una protecció apropiada i consistent dels serveis i actius d&amp;apos;informació gestionats per mitjà de les tecnologies de la informació i la comunicació (TIC).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;1.3. La política de seguretat de la informació és l&amp;apos;instrument en què es basa l&amp;apos;IBESTAT per assolir els seus objectius emprant de manera segura els sistemes d&amp;apos;informació i les comunicacions. La seguretat, concebuda com a procés integral, comprèn tots els elements tècnics, humans, materials i organitzatius relacionats amb els sistemes d&amp;apos;informació i les comunicacions, i cal entendre-la no com un producte, sinó com un procés continu d&amp;apos;adaptació i millora, que ha de ser controlat, gestionat i monitorat amb la implantació de la cultura de la seguretat a l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;2. Àmbit d&amp;apos;aplicació&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;2.1. La PSI és de compliment obligat per a totes les persones responsables de l&amp;apos;IBESTAT tant en el camp de la gestió com en el tècnic; també és de compliment obligat per a tot el personal que accedeixi tant als sistemes d&amp;apos;informació com a la mateixa informació que gestioni cada àrea, amb independència de quina sigui la destinació, l&amp;apos;adscripció o la relació amb l&amp;apos;àrea.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;2.2. Aquesta política és d&amp;apos;aplicació i de compliment obligat per a totes les àrees i serveis de l&amp;apos;IBESTAT i també n&amp;apos;afecta tots els recursos i els processos inclosos en el Reial decret 311/2022, de 3 de maig, pel qual es regula l&amp;apos;Esquema Nacional de Seguretat, ja siguin interns o externs, vinculats a l&amp;apos;entitat a través de contractes o acords amb tercers.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;2.3. Aquesta política s&amp;apos;ha d&amp;apos;aplicar als sistemes d&amp;apos;informació de l&amp;apos;IBESTAT que estan relacionats amb la prestació de serveis per mitjans electrònics a la ciutadania, amb el compliment de deures per mitjans electrònics o amb l&amp;apos;accés a la informació o al procediment administratiu i que es troben dins l&amp;apos;abast de l&amp;apos;Esquema Nacional de Seguretat (ENS).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;3. Missió&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;L&amp;apos;IBESTAT és l&amp;apos;òrgan central d&amp;apos;estadística de la Comunitat Autònoma de les Illes Balears, creat per la Llei 3/2002, de 17 de maig, d&amp;apos;estadística de les Illes Balears. Entre les funcions que determinen la seva missió destaquen les següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Dur a terme les activitats estadístiques que li assignin els plans i els programes estadístics aprovats pel Govern de les Illes Balears, amb independència tècnica i professional, atenent al fet insular i altres desagregacions territorials, i complint els principis establerts en el Codi de bones pràctiques de les estadístiques europees.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Coordinar l&amp;apos;activitat estadística autonòmica com a responsable de la promoció, la gestió i la coordinació del Sistema Estadístic de les Illes Balears (SESTIB). En aquest sentit, confecciona la proposta de plans i programes estadístics que aprovarà el Govern de les Illes Balears.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Establir tots els elements tècnics necessaris per desplegar l&amp;apos;article 30.32 de l&amp;apos;Estatut d&amp;apos;autonomia referent a la competència exclusiva en matèria estadística d&amp;apos;interès de la comunitat autònoma, d&amp;apos;acord amb la Llei d&amp;apos;estadística &lt;/span&gt;autonòmica esmentada i l&amp;apos;altra normativa estadística que la pugui afectar.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;4. Objectius&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;4.1. Són objectius generals de l&amp;apos;IBESTAT els següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Establir un marc de gestió de la seguretat de la informació adequat al Reial decret 311/2022 i reconèixer així com a actius estratègics la informació i els sistemes que la suporten.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Establir les bases sobre les quals el personal de l&amp;apos;IBESTAT i la ciutadania poden accedir als serveis en un entorn de gestió segur, anticipant-ne les necessitats i preservant-ne els drets.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Protegir la informació d&amp;apos;un ventall ampli d&amp;apos;amenaces, amb la finalitat de garantir la continuïtat dels sistemes d&amp;apos;informació, minimitzar els riscs de dany i assegurar el compliment eficient dels objectius de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;d)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Garantir el funcionament adequat de les activitats de control, monitoratge i manteniment de les infraestructures i les instal·lacions generals, necessàries per prestar serveis de manera adequada, així com de la informació derivada d&amp;apos;aquest funcionament.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;4.2. Són objectius específics de l&amp;apos;IBESTAT els següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Contribuir des de la gestió de la seguretat de la informació al compliment de la &lt;/span&gt;missió i els objectius establerts per a l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Disposar de les mesures de control necessàries per complir els requisits legals que siguin d&amp;apos;aplicació com a conseqüència de l&amp;apos;activitat desenvolupada, especialment pel que fa a la protecció de dades de caràcter personal i a la prestació de serveis a través de mitjans electrònics.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Assegurar l&amp;apos;accés, la integritat, la confidencialitat, la disponibilitat, l&amp;apos;autenticitat i la traçabilitat de la informació i la prestació continuada dels serveis, actuant preventivament, supervisant l&amp;apos;activitat diària i reaccionant amb rapidesa als incidents.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;d)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Protegir els recursos d&amp;apos;informació de l&amp;apos;IBESTAT i la tecnologia emprada per processar-los contra amenaces, internes o externes, deliberades o accidentals, amb la finalitat d&amp;apos;assegurar el compliment de la confidencialitat, la integritat, la disponibilitat, la legalitat i la fiabilitat de la informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;5. Revisió de la política de seguretat de la informació&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;5.1. El Comitè per a la Gestió i la Coordinació de la Seguretat de la Informació &lt;span style="color: black"&gt;(d&amp;apos;ara endavant, Comitè) &lt;/span&gt;ha de proposar, revisar i difondre la PSI, amb el suport de la persona responsable de seguretat, que ha de vetlar activament per conservar-la, actualitzar-la i difondre-la entre totes les parts afectades.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;5.2. La política de seguretat de la informació s&amp;apos;ha de revisar un cop l&amp;apos;any i sempre que hi hagi canvis rellevants en l&amp;apos;organització, amb la finalitat d&amp;apos;assegurar que s&amp;apos;adequa a l&amp;apos;estratègia i les necessitats de l&amp;apos;organització.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;5.3. En cas de conflictes o diferents interpretacions d&amp;apos;aquesta política, la direcció de l&amp;apos;IBESTAT és l&amp;apos;òrgan competent per resoldre&amp;apos;ls.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;6. Marc normatiu&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;S&amp;apos;agafa com a referència bàsica en matèria de seguretat de la informació la normativa relacionada amb el Codi del dret de la ciberseguretat establert pel Ministeri de la Presidència, Relacions amb les Corts i Memòria Democràtica, en què es detalla tota la normativa aplicable, entre les quals es troben les normatives següents, enunciades a títol informatiu no limitatiu:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reglament (UE) núm. 2016/679, del Parlament Europeu i del Consell, de 27 d&amp;apos;abril de 2016, relatiu a la protecció de les persones físiques pel que fa al tractament de dades personals i a la lliure circulació d&amp;apos;aquestes dades i pel qual es deroga la Directiva 95/46/CE (Reglament general de protecció de dades).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei orgànica 3/2018, de 5 de desembre, de protecció de dades personals i garantia dels drets digitals.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 25/2007, de 18 d&amp;apos;octubre, de conservació de dades relatives a les comunicacions electròniques i a les xarxes públiques de comunicacions.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 37/2007, de 16 de novembre, sobre reutilització de la informació del sector públic.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 56/2007, de 28 de desembre, de mesures d&amp;apos;impuls de la societat de la informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 19/2013, de 9 de desembre, de transparència, accés a la informació pública i bon govern.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 39/2015, d&amp;apos;1 d&amp;apos;octubre, del procediment administratiu comú de les administracions públiques.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 40/2015, d&amp;apos;1 d&amp;apos;octubre, de règim jurídic del sector públic.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 9/2017, de 8 de novembre, de contractes del sector públic, per la qual es transposen a l&amp;apos;ordenament jurídic espanyol les directives del Parlament Europeu i del Consell 2014/23/UE i 2014/24/UE, de 26 de febrer de 2014.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 6/2020, d&amp;apos;11 de novembre, reguladora de determinats aspectes dels serveis electrònics de confiança.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 11/2022, de 28 de juny, general de telecomunicacions.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reial decret llei 14/2019, de 31 d&amp;apos;octubre, pel qual s&amp;apos;adopten mesures urgents per raons de seguretat pública en matèria d&amp;apos;administració digital, contractació del sector públic i telecomunicacions.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reial decret legislatiu 1/1996, de 12 d&amp;apos;abril, pel qual s&amp;apos;aprova el Text refós de la Llei de propietat intel·lectual.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reial decret legislatiu 5/2015, de 30 d&amp;apos;octubre, pel qual s&amp;apos;aprova el Text refós de la Llei de l&amp;apos;Estatut bàsic de l&amp;apos;empleat públic.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reial decret 1553/2005, de 23 de desembre, pel qual es regula el document nacional d&amp;apos;identitat i els seus certificats de signatura electrònica.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reial decret 4/2010, de 8 de gener, pel qual es regula l&amp;apos;Esquema Nacional d&amp;apos;Interoperabilitat en l&amp;apos;àmbit de l&amp;apos;administració electrònica.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reial decret 203/2021, de 30 de març, pel qual s&amp;apos;aprova el Reglament d&amp;apos;actuació i funcionament del sector públic per mitjans electrònics.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Reial decret 311/2022, de 3 de maig, pel qual es regula l&amp;apos;Esquema Nacional de Seguretat en l&amp;apos;àmbit de l&amp;apos;administració electrònica.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Resolució de 7 d&amp;apos;octubre de 2016 de la Secretaria d&amp;apos;Estat d&amp;apos;Administracions Públiques per la qual s&amp;apos;aprova la Instrucció tècnica de seguretat de l&amp;apos;informe de l&amp;apos;estat de la seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Resolució de 13 d&amp;apos;octubre de 2016 de la Secretaria d&amp;apos;Estat d&amp;apos;Administracions Públiques per la qual s&amp;apos;aprova la Instrucció tècnica de seguretat de conformitat amb l&amp;apos;Esquema Nacional de Seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Resolució de 27 de març de 2018 de la Secretaria d&amp;apos;Estat de Funció Pública per la qual s&amp;apos;aprova la Instrucció tècnica de seguretat de l&amp;apos;auditoria de la seguretat dels sistemes d&amp;apos;informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Resolució de 13 d&amp;apos;abril de 2018 de la Secretaria d&amp;apos;Estat de Funció Pública per la qual s&amp;apos;aprova la Instrucció tècnica de seguretat de notificació d&amp;apos;incidents de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 3/2002, de 17 de maig, d&amp;apos;estadística de les Illes Balears.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Llei 7/2010, de 21 de juliol, del sector públic instrumental de la Comunitat Autònoma de les Illes Balears.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Decret 128/2007, de 5 d&amp;apos;octubre, d&amp;apos;organització i funcionament de l&amp;apos;Institut d&amp;apos;Estadística de les Illes Balears.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Decret 8/2021, de 9 de febrer, sobre la transparència i el dret d&amp;apos;accés a la informació pública.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;— Decret 31/2023, de 22 de maig, pel qual s&amp;apos;estableix l&amp;apos;organització administrativa en matèria de transparència i es desenvolupa l&amp;apos;exercici del dret d&amp;apos;accés a la informació pública en l&amp;apos;Administració de la Comunitat Autònoma de les Illes Balears i en el seu sector públic instrumental.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;7. Principis bàsics en matèria de seguretat de la informació&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;L&amp;apos;IBESTAT, per aconseguir el compliment de les previsions recollides en el Reial decret 311/2022, ha d&amp;apos;implementar les mesures de seguretat proporcionals a la naturalesa de la informació i els serveis que s&amp;apos;han de protegir i tenint en compte la categoria dels sistemes afectats.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Per això, s&amp;apos;han de tenir en compte els principis bàsics desglossats en el capítol 2 del Reial decret 311/2022:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a) &lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt;Seguretat com a procés integral.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b) &lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt;Gestió de la seguretat basada en els riscs.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c) &lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt;Prevenció, detecció, resposta i conservació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;d)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Existència de línies de defensa.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;e)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Vigilància contínua.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;f)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Reavaluació periòdica.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;g)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Diferenciació de responsabilitats.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;8. Estructura de la documentació de seguretat&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;8.1. Sens perjudici del marc normatiu que preveu el punt 6 d&amp;apos;aquest annex, el cos jurídic específic de la PSI d&amp;apos;aquest organisme autònom que sigui de compliment obligat s&amp;apos;ha de desenvolupar en tres nivells, segons l&amp;apos;àmbit d&amp;apos;aplicació i el detall tècnic. Aquests nivells són els següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Primer nivell: marc comú i directrius bàsiques de la política de seguretat de la informació en l&amp;apos;àmbit de l&amp;apos;administració electrònica de la Comunitat Autònoma de les Illes Balears. Constitueixen aquest primer nivell l&amp;apos;Acord del Consell Rector de l&amp;apos;Institut d&amp;apos;Estadística de les Illes Balears pel qual s&amp;apos;aprova la política de seguretat de la informació de l&amp;apos;Institut i les disposicions, directrius i normes de seguretat generals dins l&amp;apos;àmbit d&amp;apos;aplicació de la PSI que defineix el punt 6 d&amp;apos;aquest annex.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Segon nivell: instruccions operatives de seguretat de la informació i instruccions de les TIC. Aquestes instruccions donen resposta, sense entrar en detalls d&amp;apos;implementació ni tecnològics, al que es pot fer i al que no es pot fer en relació amb un determinat tema des del punt de vista de la seguretat, què es considera un ús apropiat o inapropiat, o quines conseqüències es deriven de l&amp;apos;incompliment, entre altres aspectes. Els documents relatius a aquest segon nivell els ha &lt;/span&gt;d&amp;apos;elaborar el Comitè i els ha d&amp;apos;aprovar la persona titular de la direcció de l&amp;apos;IBESTAT, a proposta de la persona responsable de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;c)&lt;/em&gt; Tercer nivell: instruccions tècniques de seguretat de les tecnologies de la informació i la comunicació (STIC). Són documents que donen resposta, incloent-hi detalls d&amp;apos;implementació i tecnològics, a la manera com es pot dur a terme una determinada tasca, respectant els principis de seguretat de l&amp;apos;organització i els processos interns establerts. Els documents relatius a aquest tercer nivell els ha d&amp;apos;elaborar el Comitè i els ha d&amp;apos;aprovar la persona titular de la direcció de l&amp;apos;IBESTAT, a proposta de la persona responsable de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;8.2. A més dels documents esmentats en l&amp;apos;apartat anterior, la documentació de seguretat del sistema pot disposar, sota el criteri de la persona responsable de seguretat, d&amp;apos;altres documents de caràcter no vinculant: recomanacions, bones pràctiques, informes, registres o evidències electròniques, entre altres aspectes.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;9. Desenvolupament de la política de seguretat de la informació&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Aquesta política de seguretat de la informació s&amp;apos;ha de desplegar mitjançant normativa de seguretat que tracti aspectes específics. La normativa de seguretat ha d&amp;apos;estar a disposició de tots els membres de l&amp;apos;organització que necessitin conèixer-la, en particular per als que utilitzin, operin o administrin els sistemes d&amp;apos;informació i les comunicacions.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Les normes i els procediments han de preveure, almenys, els aspectes següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Protecció de dades de caràcter personal: s&amp;apos;han d&amp;apos;implantar mesures tècniques i organitzatives que permetin complir els requisits normatius en aquesta matèria.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Gestió d&amp;apos;actius d&amp;apos;informació: els actius d&amp;apos;informació s&amp;apos;han d&amp;apos;inventariar, categoritzar i associar a un responsable.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Seguretat lligada als recursos humans: la seguretat lligada al personal és fonamental per reduir els riscs d&amp;apos;errors humans, robatoris, fraus o mal ús de les instal·lacions i els serveis, per la qual cosa s&amp;apos;han d&amp;apos;implantar els mecanismes que permetin als usuaris conèixer les seves responsabilitats i com complir-les.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;d)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Seguretat física: les instal·lacions de l&amp;apos;IBESTAT han de mantenir una correcta seguretat física per evitar els accessos no autoritzats, així com qualsevol altre tipus de dany o interferència externa.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;e)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Seguretat lògica: s&amp;apos;han d&amp;apos;establir mesures organitzatives i tècniques per controlar els accessos, protegir davant codis nocius, assegurar les comunicacions, fer còpies de seguretat, etc.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;f)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Gestió d&amp;apos;incidents de seguretat: s&amp;apos;han d&amp;apos;establir responsabilitats i procediments de gestió d&amp;apos;incidències per assegurar una resposta ràpida, eficaç i ordenada als esdeveniments en matèria de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;10. Gestió i accés a la documentació del sistema&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;10.1. L&amp;apos;IBESTAT desenvolupa la política de gestió i conservació dels documents electrònics que s&amp;apos;implementa mitjançant normes internes, procediments i instruccions tècniques.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;10.2. &lt;/span&gt;S&amp;apos;ha de disposar d&amp;apos;un sistema per gestionar l&amp;apos;elaboració, l&amp;apos;aprovació, la conservació, l&amp;apos;estructura i l&amp;apos;accés, entre d&amp;apos;altres, dels documents del sistema de gestió de la seguretat aplicat sobre els sistemes d&amp;apos;informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;11. Organització de la gestió de la PSI&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;11.1. L&amp;apos;organització de la seguretat queda establerta mitjançant la identificació i la definició de les diferents activitats i responsabilitats en matèria de gestió de la seguretat dels sistemes i la implantació d&amp;apos;una estructura que les suporti.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;11.2. Totes i cadascuna de les persones usuàries dels sistemes d&amp;apos;informació de l&amp;apos;IBESTAT són responsables de la seguretat dels actius d&amp;apos;informació, per la qual cosa han de fer-ne sempre un ús correcte, d&amp;apos;acord amb les seves atribucions professionals.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;11.3. Per respondre millor a incidents de seguretat, l&amp;apos;IBESTAT ha de mantenir relacions de cooperació en matèria de seguretat amb les autoritats &lt;/span&gt;competents,&lt;span style="color: black"&gt; els proveïdors de serveis informàtics o de comunicació, així com amb organismes públics o privats dedicats a promoure la seguretat dels sistemes d&amp;apos;informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;11.4. L&amp;apos;estructura organitzativa per gestionar la seguretat de la informació en l&amp;apos;àmbit descrit en aquesta PSI de l&amp;apos;IBESTAT està integrada pels òrgans i els agents següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Comitè per a la Gestió i la Coordinació de la Seguretat de la Informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Responsable de la informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Responsable del servei.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;d)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Responsable de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;e)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Responsable del sistema.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;12. &lt;/span&gt;Comitè per a la Gestió i la Coordinació de la Seguretat de la Informació&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;12.1. Es crea el &lt;/span&gt;Comitè per a la Gestió i la Coordinació de la Seguretat de la Informació&lt;span style="color: black"&gt; com una comissió de treball integrada a l&amp;apos;IBESTAT, i està constituït pels membres següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Presidència: la persona responsable de la direcció de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Secretaria: una persona de l&amp;apos;IBESTAT, amb vincle funcionarial, designada per la presidència, que actua amb veu i sense vot.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Vocalies: les persones titulars dels serveis de l&amp;apos;IBESTAT; la persona o l&amp;apos;òrgan designat &lt;/span&gt;delegat de protecció de dades, que actua amb independència i no pot participar en les decisions relatives als fins i als mitjans del tractament, i la persona que ocupi el lloc de feina de cap de la Secció I de l&amp;apos;especialitat d&amp;apos;informàtica de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;12.2. El Comitè s&amp;apos;ha de regir pel que disposa la Llei 40/2015 per als òrgans col·legiats pel que fa al règim de funcionament en tot allò que no estigui previst en aquest annex.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;12.3. El Comitè s&amp;apos;ha de reunir amb caràcter ordinari cada any i amb caràcter extraordinari a proposta de la presidència. No es percebran indemnitzacions en concepte d&amp;apos;assistència a les reunions del Comitè.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;12.4. Es pot acordar la constitució de grups de treball per analitzar, elaborar i executar treballs o activitats específiques, dins l&amp;apos;àmbit de les seves funcions. El Comitè ha de conèixer en les sessions del ple el resultats de les actuacions dels grups de treball.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;12.5. Corresponen al Comitè les funcions següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Elaborar els esborranys de modificació i actualització de la PSI.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Analitzar els riscs i impulsar-ne l&amp;apos;avaluació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Revisar l&amp;apos;informe anual d&amp;apos;anàlisi de riscs fet per la persona responsable de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;d)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Impulsar l&amp;apos;actualització dels criteris i les directrius sobre seguretat de la informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;e)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Impulsar mesures per millorar i reforçar els sistemes de seguretat i control.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;f)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Impulsar la difusió i el compliment de la PSI, i promoure activitats de conscienciació i formació en matèria de seguretat per al personal de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;g)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Elaborar els esborranys de directrius i normes de seguretat generals de l&amp;apos;IBESTAT, que han de complir el marc normatiu d&amp;apos;aquest annex.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;h)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Elaborar la normativa de seguretat de segon i tercer nivell.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;i)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Coordinar les decisions i les actuacions de la persona responsable de seguretat, i assessorar per resoldre els possibles conflictes sota el criteri de garantir la seguretat de les infraestructures tecnològiques compartides.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;j)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Impulsar els projectes per adequar-los al compliment de l&amp;apos;Esquema Nacional de Seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;k)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Compartir experiències d&amp;apos;èxit en matèria de seguretat entre els membres del Comitè per vetlar pel compliment de la PSI i la normativa que la desplega.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;l)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Coordinar totes les activitats relacionades amb la seguretat dels sistemes d&amp;apos;informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;m)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Vetlar perquè la seguretat de la informació sigui part del procés de planificació de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;n)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Qualsevol altra actuació en matèria de seguretat de la informació que no correspongui específicament a un altre agent.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;13. Responsable de la informació&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;13.1. Les funcions de la persona responsable de la informació que estableix la normativa que regula l&amp;apos;Esquema Nacional de Seguretat corresponen a la direcció de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;13.2. Dins el seu àmbit d&amp;apos;actuació, ha de determinar els requisits de la informació tractada, establir les necessitats de seguretat de la informació i fer les valoracions de l&amp;apos;impacte que tindria un incident que n&amp;apos;afectàs la seguretat; a més, té la potestat de modificar el nivell de seguretat requerit.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;13.3. Per desenvolupar aquestes funcions, ha de comptar amb la col·laboració de les persones gestores titulars de les unitats a càrrec seu amb rang de servei o equivalent.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;14. Responsable del servei&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;14.1. La tasca de responsable del servei correspon als caps de servei per a les àrees de gestió de les quals són titulars, tal com estableix la normativa que regula l&amp;apos;Esquema Nacional de Seguretat. Concretament els serveis afectats són els següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Producció Estadística&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Difusió Estadística&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;Coordinació i Planificació Estadística&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;14.2. Dins el seu àmbit d&amp;apos;actuació, determina els requisits de seguretat dels serveis prestats.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;15. Responsable de seguretat&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;15.1. Les funcions de la persona responsable de seguretat corresponen a la direcció de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;15.2. Determina les decisions per satisfer els requisits de seguretat de la informació i dels serveis, supervisa la implantació de les mesures necessàries per garantir la consecució dels requisits i informa sobre aquestes qüestions.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;15.3. L&amp;apos;àmbit d&amp;apos;actuació del responsable de seguretat s&amp;apos;ha de limitar únicament i exclusiva als sistemes d&amp;apos;informació i als serveis de tecnologies de la informació i la comunicació que siguin competència i responsabilitat directa de l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;15.4. Coordina de manera contínua el desenvolupament de la seguretat de la informació en l&amp;apos;àmbit d&amp;apos;aplicació d&amp;apos;aquest annex, a més d&amp;apos;exercir les funcions específiques següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;a)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Promoure la seguretat de la informació emprada i dels serveis electrònics dels sistemes d&amp;apos;informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;b)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Mantenir la documentació de seguretat actualitzada i organitzada en els sistemes de coneixement corporatius i gestionar els mecanismes per accedir-hi.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;c)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Proposar al Comitè la normativa de seguretat de segon i tercer nivell.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;e)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Promoure les activitats de conscienciació i informació en matèria de seguretat en el seu àmbit de responsabilitat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;f)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Dur a terme la coordinació i el seguiment de la implantació dels projectes d&amp;apos;adequació a l&amp;apos;Esquema Nacional de Seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;g)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Elaborar, amb els responsables dels serveis, les preceptives anàlisis de risc, seleccionar les salvaguardes que s&amp;apos;han d&amp;apos;implantar, revisar el procés de gestió del risc i elevar un informe anual al Comitè.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;h)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Promoure auditories periòdiques per verificar el compliment de les obligacions en matèria de seguretat de la informació, analitzar els informes d&amp;apos;auditoria i elaborar les conclusions que s&amp;apos;han de presentar a les persones responsables del servei perquè, juntament amb la persona responsable de la informació, adoptin les mesures correctores adients.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;i)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Coordinar el procés de gestió de la seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;j)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Signar la declaració d&amp;apos;aplicabilitat, que comprèn l&amp;apos;aplicació de mesures de seguretat seleccionades per un sistema conforme a l&amp;apos;article 28 del Reial decret&amp;nbsp;311/2022.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;k)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Elaborar informes periòdics de seguretat que incloguin els incidents més rellevants de cada període.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;l)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Determinar la categoria de seguretat dels sistemes d&amp;apos;informació, segons el procediment descrit en l&amp;apos;annex 1 del Reial decret 311/2022, i les mesures de seguretat que s&amp;apos;han d&amp;apos;aplicar d&amp;apos;acord amb l&amp;apos;annex 2 d&amp;apos;aquest Reial decret.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;&lt;span style="color: black"&gt;m)&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black"&gt; Determinar la categoria de seguretat sobre la base de les valoracions que facin els responsables de la informació i del servei conforme a l&amp;apos;annex 1 del Reial decret&amp;nbsp;311/2022.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;15.5. Per exercir les seves funcions, ha de comptar amb el suport del Comitè.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;15.6. Atès que el responsable de seguretat recau sobre la direcció de l&amp;apos;IBESTAT, es prendran mesures compensatòries, consistents a dur a terme auditories periòdiques de seguretat o bé documentar i justificar les decisions preses pel &lt;/span&gt;Comitè per a la Gestió i la Coordinació de la Seguretat de la Informació&lt;span style="color: black"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;16. Responsable del sistema&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;16.1. És responsable del sistema la persona titular del Servei d&amp;apos;Assistència Tècnica i Computacional de l&amp;apos;IBESTAT, atès que és la unitat administrativa que exerceix les competències en matèria de gestió de sistemes d&amp;apos;informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;16.2. Les funcions de la persona responsable del sistema són les següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;a)&lt;/em&gt; Implantar les mesures necessàries per garantir la seguretat del sistema durant tot el seu cicle de vida, seguint les indicacions de la persona responsable de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;b)&lt;/em&gt; Aprovar totes les modificacions substancials de qualsevol element del sistema.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;c)&lt;/em&gt; Suspendre el maneig d&amp;apos;una determinada informació o la prestació d&amp;apos;un servei electrònic si és informada de deficiències greus de seguretat amb l&amp;apos;informe previ de la persona responsable d&amp;apos;aquesta informació o servei i de la persona responsable de seguretat. En cas de no arribar a un acord en aquest sentit, s&amp;apos;ha d&amp;apos;atenir al règim de resolució de conflictes previst en el punt 20 d&amp;apos;&lt;span style="color: black"&gt;aquest annex&lt;/span&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;17. Obligacions del personal&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;17.1. Tota persona que presti serveis a l&amp;apos;IBESTAT té l&amp;apos;obligació de conèixer i complir la PSI i la normativa de seguretat derivada, i és responsabilitat del Comitè disposar dels mitjans necessaris perquè la informació estigui disponible per a les persones afectades i comunicar aquesta disponibilitat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;17.2. Totes les persones que emprin o tenguin accés als sistemes tecnològics o d&amp;apos;informació tenen les obligacions següents:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;a)&lt;/em&gt; Conèixer i respectar la PSI, així com les normes de seguretat i els procediments de seguretat que la despleguen i que l&amp;apos;afecten.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;b)&lt;/em&gt; Assistir a les accions de conscienciació en matèria de seguretat de la informació que es duguin a terme.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;c)&lt;/em&gt; Emprar els serveis i els sistemes d&amp;apos;informació, així com la informació que contenguin i a la qual tenguin accés, amb una finalitat professional d&amp;apos;acord amb les tasques encomanades en funció del lloc de treball i les finalitats i els propòsits que van motivar la concessió de l&amp;apos;accés.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;d)&lt;/em&gt; Vetlar per la confidencialitat de la informació a la qual tenguin accés segons la classificació i les característiques d&amp;apos;aquesta.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;e)&lt;/em&gt; Notificar actuacions o fets que puguin suposar una incidència de seguretat o evidenciïn una debilitat que pugui implicar incidents posteriors.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;f)&lt;/em&gt; Col·laborar en la resolució d&amp;apos;incidents de seguretat i en la realització d&amp;apos;accions preventives quan sigui necessària la seva participació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;g)&lt;/em&gt; No dur a terme accions intencionades que perjudiquin la seguretat dels sistemes tecnològics o d&amp;apos;informació, ni la informació que contenen.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;17.3. L&amp;apos;incompliment d&amp;apos;aquestes obligacions pot ser sancionat de conformitat amb la normativa disciplinària corresponent.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;17.4. En cas de persones vinculades a entitats externes, l&amp;apos;ús de sistemes tecnològics o d&amp;apos;informació s&amp;apos;ha de limitar a les tasques o activitats circumscrites en els termes del contracte o acord que regula la relació entre aquesta entitat i l&amp;apos;IBESTAT.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;18. Terceres parts&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;18.1. Quan es prestin serveis a altres organismes o es cedeixi informació a tercers:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;a)&lt;/em&gt; Se&amp;apos;ls ha de fer participar de la PSI i de les normes de seguretat o procediments de seguretat relacionats amb el servei o la informació afectats.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p style="margin-bottom: 0px; margin-left: 40px; margin-right: 0px; margin-top: 0px"&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;em&gt;b)&lt;/em&gt; S&amp;apos;han d&amp;apos;establir canals d&amp;apos;informació i coordinació entre les respectives persones responsables de gestió de la seguretat de la informació i establir procediments de seguretat per reaccionar davant els incidents que es puguin dur a terme.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;18.2. Quan s&amp;apos;emprin serveis o es manegi informació d&amp;apos;altres organismes o entitats, s&amp;apos;han de procurar canals d&amp;apos;informació i coordinació en matèria de seguretat de la informació.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;18.3. En els contractes d&amp;apos;implantació, manteniment o gestió de sistemes o aplicacions informàtiques, de prestació de serveis tecnològics, i també en el cas de contractes de prestació de serveis d&amp;apos;altre tipus que impliqui l&amp;apos;ús de serveis, aplicacions o sistemes informàtics interns, s&amp;apos;han de tenir en compte les mesures i les consideracions de seguretat de la informació que siguin d&amp;apos;aplicació, segons la legislació vigent en la matèria. També s&amp;apos;han de tenir en comptes les mesures i les consideracions de seguretat de la informació que resultin d&amp;apos;aplicació legal, en cas d&amp;apos;acord de cessió de sistemes, aplicacions o accés a serveis d&amp;apos;altres organismes o entitats.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;18.4. Quan alguna part no pugui satisfer algun aspecte de la PSI, s&amp;apos;ha de requerir al Comitè un informe sobre els riscs en què es pot incórrer i la forma de tractar-los. En vista d&amp;apos;aquest informe, i abans que es faci efectiva la prestació, l&amp;apos;ús, l&amp;apos;accés o la gestió de què es tracti, les persones responsables de la informació o dels serveis afectats han de decidir sobre l&amp;apos;acceptació del risc residual.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;18.5. En tot cas, s&amp;apos;ha de donar compliment tant a la normativa de l&amp;apos;Esquema Nacional de Seguretat com a la normativa en matèria de protecció de dades personals. És d&amp;apos;especial aplicació l&amp;apos;Esquema Nacional de Seguretat als sistemes d&amp;apos;informació de les entitats del sector privat, inclosa l&amp;apos;obligació de disposar de la política de seguretat, quan, d&amp;apos;acord amb la normativa aplicable, i en virtut d&amp;apos;una relació contractual, prestin serveis o proveeixin solucions a l&amp;apos;IBESTAT perquè aquest pugui exercir les seves competències i potestats administratives, de conformitat amb l&amp;apos;article 2.3 del Reial decret 311/2022.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;19. Gestió de riscs&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;19.1. La gestió de riscs és un factor essencial per gestionar correctament la seguretat de la informació, i s&amp;apos;ha de dur a terme de manera contínua sobre els sistemes d&amp;apos;informació, conforme als principis de gestió de la seguretat basada en els riscs de l&amp;apos;article 7 i la reavaluació periòdica de l&amp;apos;article 10 del Reial decret&amp;nbsp;311/2022.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;19.2. La persona responsable de seguretat és l&amp;apos;encarregada de l&amp;apos;anàlisi del risc dels sistemes d&amp;apos;informació gestionats per l&amp;apos;IBESTAT i de seleccionar les mesures que s&amp;apos;han d&amp;apos;implantar. L&amp;apos;informe de l&amp;apos;anàlisi de riscs amb les mesures que conté ha de ser analitzat i revisat pel Comitè.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;19.3. Les persones responsables de la informació i del servei són les responsables dels riscs sobre la informació i sobre els serveis respectivament i, per tant, d&amp;apos;acceptar els riscs residuals calculats en l&amp;apos;anàlisi i de fer-ne el seguiment i el control.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;19.4. El procés de gestió de riscs, que comprèn les fases de categorització dels sistemes, anàlisi de riscs i selecció de mesures de seguretat que s&amp;apos;han d&amp;apos;aplicar, que han de ser proporcionades als riscs i estar justificades, s&amp;apos;ha de revisar cada any.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;19.5. En el cas de riscs que es derivin del tractament de dades personals, la persona responsable del tractament, assessorada per la persona delegada de protecció de dades, ha de dur a terme una anàlisi de riscs i, en els supòsits prevists en la normativa de protecció de dades, una avaluació d&amp;apos;impacte en la protecció de dades. En tot cas, aquestes mesures prevaldran en cas de resultar agreujades respecte de les previstes en el Reial decret 311/2022.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;20. Resolució de conflictes&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;20.1. En cas de conflicte entre les persones responsables de l&amp;apos;estructura organitzativa de la PSI, aquest serà resolt per la persona superior jeràrquicament. Si no n&amp;apos;hi ha, serà resolt per la persona titular de la direcció de l&amp;apos;IBESTAT, un cop escoltat el Comitè.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;20.2. En cas de conflicte entre les persones responsables que componen l&amp;apos;estructura organitzativa de la PSI i les definides en la normativa de protecció de dades de caràcter personal, prevaldrà la decisió que presenti un nivell d&amp;apos;exigència més gran respecte a la protecció de dades de caràcter personal segons determini la persona responsable del tractament.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;&lt;span style="color: black"&gt;21. Auditoria&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;21.1. Els sistemes d&amp;apos;informació propis de l&amp;apos;IBESTAT han de ser objecte d&amp;apos;una auditoria ordinària interna o externa que verifiqui el compliment dels requeriments de l&amp;apos;Esquema Nacional de Seguretat. Amb caràcter extraordinari s&amp;apos;ha de fer aquesta auditoria sempre que es duguin a terme modificacions substancials en el sistema d&amp;apos;informació que puguin repercutir en el compliment de les mesures de seguretat requerides.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;span style="color: black"&gt;21.2. Els informes d&amp;apos;auditoria han de restar a disposició del Comitè.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;&lt;strong&gt;22. Formació i conscienciació&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;22.1. L&amp;apos;IBESTAT ha de desenvolupar activitats formatives específiques orientades a conscienciar i formar el personal d&amp;apos;aquest organisme autònom, així com difondre la PSI i desplegar-la normativament.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1"&gt;&lt;span style="font-family: Times New Roman, Times, serif; font-size: 12px"&gt;&lt;span style="background-color: white"&gt;22.2. El Comitè i la persona responsable de seguretat s&amp;apos;han d&amp;apos;encarregar de promoure les activitats de formació i conscienciació en matèria de seguretat.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;]]</env:contingut>
    <env:sumariEnviament rdf:parseType="Literal">![CDATA[Acord del Consell Rector de l’Institut d’Estadística de les Illes Balears pel qual s’aprova la política de seguretat de la informació de l’Institut  ]]</env:sumariEnviament>
    <dc:date>2025-01-18</dc:date>
    <env:dataPublicacio>2025-01-18</env:dataPublicacio>
    <env:ordre rdf:parseType="Literal">320</env:ordre>
    <env:html rdf:resource="https://intranet.caib.es/eboibfront/ca/2025/12044/695850/acord-del-consell-rector-de-l-institut-d-estadisti/"/>
    <env:lang>ca</env:lang>
    <dc:description>CAIB</dc:description>
    <env:enviatTo rdf:resource="https://www.caib.es/eboibfront/ca/2025/12044"/>
    <dc:language>ca</dc:language>
    <env:organisme rdf:resource="https://www.caib.es/eboibfront/ca/organisme/2121"/>
    <dc:creator>CAIB</dc:creator>
    <env:numPaginaFinal rdf:parseType="Literal">2748</env:numPaginaFinal>
    <rdf:type rdf:resource="https://www.caib.es/eboibfront/rdf/schema/enviament/1.0/"/>
    <env:numeroRegistre>28029</env:numeroRegistre>
    <env:tipusPublicacio rdf:resource="https://www.caib.es/eboibfront/ca/tipus-publicacio/5763"/>
    <env:numPaginaInicial rdf:parseType="Literal">2740</env:numPaginaInicial>
    <env:dataRegistre>2025-01-16</env:dataRegistre>
    <env:idEnviament>695850</env:idEnviament>
    <env:seccio rdf:resource="https://www.caib.es/eboibfront/ca/seccio/472"/>
    <dc:format>text/html</dc:format>
    <dc:publisher>CAIB</dc:publisher>
  </rdf:Description>
</rdf:RDF>
