{"id":2381,"date":"2025-01-17T12:03:42","date_gmt":"2025-01-17T11:03:42","guid":{"rendered":"https:\/\/copla.io\/?page_id=2381"},"modified":"2026-10-09T21:01:57","modified_gmt":"2026-10-09T19:01:57","slug":"politica-de-seguridad","status":"publish","type":"page","link":"https:\/\/copla.io\/en\/politica-de-seguridad\/","title":{"rendered":"Security policy"},"content":{"rendered":"<p>[et_pb_section _builder_version=&#8221;4.27.7&#8243; fb_built=&#8221;1&#8243; module_class=&#8221;migas-pan-90 copla-documento&#8221; background_color=&#8221;#e7eef5&#8243; background_image=&#8221;https:\/\/copla.io\/wp-content\/uploads\/2024\/05\/fondo-copla.png&#8221; custom_padding=&#8221;|0px|60px|0px|false|false&#8221; custom_padding_phone=&#8221;|0px|40px|0px|false|false&#8221; custom_padding_last_edited=&#8221;on|phone&#8221;][et_pb_row _builder_version=&#8221;4.27.7&#8243; width=&#8221;90%&#8221; max_width=&#8221;2560px&#8221; background_image=&#8221;https:\/\/copla.io\/wp-content\/uploads\/2024\/11\/Isolation_Mode.png&#8221; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221;][et_pb_column _builder_version=&#8221;4.27.7&#8243; type=&#8221;4_4&#8243;][et_pb_text _builder_version=&#8221;4.27.7&#8243; text_font=&#8221;&#8211;et_global_body_font||||||||&#8221; text_text_color=&#8221;#04080f&#8221; text_font_size=&#8221;18px&#8221; text_font_size_tablet=&#8221;18px&#8221; text_font_size_phone=&#8221;16px&#8221; text_font_size_last_edited=&#8221;on|phone&#8221; text_line_height=&#8221;1.65em&#8221; custom_css_main_element=&#8221;overflow-wrap:anywhere;&#8221; header_font=&#8221;Archivo|700|||||||&#8221; header_text_color=&#8221;#000000&#8243; header_font_size=&#8221;50px&#8221; header_font_size_tablet=&#8221;50px&#8221; header_font_size_phone=&#8221;34px&#8221; header_font_size_last_edited=&#8221;on|phone&#8221; header_line_height=&#8221;60px&#8221; header_2_font=&#8221;Archivo|700|||||||&#8221; header_2_text_color=&#8221;#000000&#8243; header_2_font_size=&#8221;30px&#8221; header_2_font_size_tablet=&#8221;28px&#8221; header_2_font_size_phone=&#8221;24px&#8221; header_2_font_size_last_edited=&#8221;on|phone&#8221; header_2_line_height=&#8221;1.3em&#8221; header_3_font=&#8221;Archivo|700|||||||&#8221; header_3_text_color=&#8221;#000000&#8243; header_3_font_size=&#8221;24px&#8221; header_3_font_size_tablet=&#8221;22px&#8221; header_3_font_size_phone=&#8221;20px&#8221; header_3_font_size_last_edited=&#8221;on|phone&#8221; header_3_line_height=&#8221;1.35em&#8221; custom_margin=&#8221;|||40px|false|false&#8221; module_class=&#8221;copla-documento-titulo&#8221; custom_margin_tablet=&#8221;|||40px|false|false&#8221; custom_margin_phone=&#8221;|||40px|false|false&#8221; custom_margin_last_edited=&#8221;on|phone&#8221; custom_padding_phone=&#8221;|40px|||false|false&#8221; custom_padding_last_edited=&#8221;on|phone&#8221;]<\/p>\n<h1><span style=\"border-bottom:10px solid #3a65d3;box-decoration-break:clone;-webkit-box-decoration-break:clone;\">Security policy<\/span><\/h1>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.7&#8243; width=&#8221;90%&#8221; max_width=&#8221;1200px&#8221; background_color=&#8221;#f4f9fd&#8221; border_radii=&#8221;on|20px|20px|20px|20px&#8221; custom_padding=&#8221;32px|32px|32px|32px|true|true&#8221; custom_padding_tablet=&#8221;24px|24px|24px|24px|true|true&#8221; custom_padding_phone=&#8221;20px|40px|20px|20px|false|false&#8221; custom_padding_last_edited=&#8221;on|phone&#8221; custom_margin=&#8221;20px|auto|0px|auto|false|false&#8221;][et_pb_column _builder_version=&#8221;4.27.7&#8243; type=&#8221;4_4&#8243;][et_pb_text _builder_version=&#8221;4.27.7&#8243; text_font=&#8221;&#8211;et_global_body_font||||||||&#8221; text_text_color=&#8221;#04080f&#8221; text_font_size=&#8221;18px&#8221; text_font_size_tablet=&#8221;18px&#8221; text_font_size_phone=&#8221;16px&#8221; text_font_size_last_edited=&#8221;on|phone&#8221; text_line_height=&#8221;1.65em&#8221; custom_css_main_element=&#8221;overflow-wrap:anywhere;&#8221; header_font=&#8221;Archivo|700|||||||&#8221; header_text_color=&#8221;#000000&#8243; header_font_size=&#8221;50px&#8221; header_font_size_tablet=&#8221;44px&#8221; header_font_size_phone=&#8221;34px&#8221; header_font_size_last_edited=&#8221;on|phone&#8221; header_line_height=&#8221;1.35em&#8221; header_2_font=&#8221;Archivo|700|||||||&#8221; header_2_text_color=&#8221;#000000&#8243; header_2_font_size=&#8221;30px&#8221; header_2_font_size_tablet=&#8221;28px&#8221; header_2_font_size_phone=&#8221;24px&#8221; header_2_font_size_last_edited=&#8221;on|phone&#8221; header_2_line_height=&#8221;1.3em&#8221; header_3_font=&#8221;Archivo|700|||||||&#8221; header_3_text_color=&#8221;#000000&#8243; header_3_font_size=&#8221;24px&#8221; header_3_font_size_tablet=&#8221;22px&#8221; header_3_font_size_phone=&#8221;20px&#8221; header_3_font_size_last_edited=&#8221;on|phone&#8221; header_3_line_height=&#8221;1.35em&#8221; custom_margin=&#8221;0px||0px||false|false&#8221; module_class=&#8221;copla-documento-contenido&#8221;]<\/p>\n<h2 style=\"margin-top:0;margin-bottom:.4em;padding-bottom:0;\">Approval and entry into force<\/h2>\n<p><span style=\"font-weight: 400;\">This Information Security Policy is effective from the date of signature and until replaced by a new Policy.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">APTENT Mission<\/h2>\n<p><span style=\"font-weight: 400;\">To achieve its objectives, APTENT assumes its commitment to information security, committing to its proper management, in order to offer all its interest groups the greatest guarantees regarding the security of the information used.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These systems must be managed diligently, taking appropriate measures to protect them against accidental or deliberate damage that may affect the availability, integrity or confidentiality of the information processed or the services provided.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The objective of information security is to guarantee the quality of information and the continued provision of services, acting preventively, supervising daily activity and reacting quickly to incidents.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">ICT systems must be protected against rapidly evolving threats with the potential to impact the confidentiality, integrity, availability, intended use and value of information and services. Defending against these threats requires a strategy that adapts to changes in environmental conditions to ensure continued service delivery. This implies that departments must apply the minimum security measures required by the National Security Scheme, as well as continuously monitor service delivery levels, follow and analyze reported vulnerabilities, and prepare an effective response to incidents to guarantee the continuity of the services provided.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The different departments must ensure that ICT security is an integral part of each stage of the system&#8217;s life cycle, from its conception to its decommissioning, through development or acquisition decisions and exploitation activities. Security requirements and financing needs must be identified, both for the products you develop and their associated services, as well as for the base software acquired from third parties.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Departments must be prepared to prevent, detect, react and recover from incidents, in accordance with Article 8 of the ENS (Article 8. Prevention, detection, response and conservation).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The information security policy is the set of guidelines that govern the way in which an organization manages and protects the information it processes and the services it provides. To this end, the instrument that approves said security policy must include, at a minimum, the following points:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">a)\u2003The objectives or mission of the organization.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">b)\u2003The regulatory framework in which the activities will be carried out.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">c)\u2003The security roles or functions, defining for each one, their duties and responsibilities, as well as the procedure for their appointment and renewal.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">d)\u2003The structure and composition of the committee or committees for the management and coordination of the\u00a0<\/span><span style=\"font-weight: 400;\">security, detailing its scope of responsibility and the relationship with other elements of the organization.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">e)\u2003The guidelines for structuring the system&#8217;s security documentation, its management and access.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">f)\u2003The risks arising from the processing of personal data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The security policy has been established in accordance with the basic principles indicated in chapter II and will be developed applying the following minimum requirements:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">a)\u2003Organization and implementation of the security process.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">b)\u2003Risk analysis and management.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">c)\u2003Personnel management.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">d)\u2003Professionalism.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">e)\u2003Authorization and access control.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">f)\u2003Protection of facilities.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">g)\u2003Acquisition of security products and contracting of security services.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">h)\u2003Least privilege.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">i)\u2003Integrity and updating of the system.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">j)\u2003Protection of information stored and in transit.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">k)\u2003Prevention against other interconnected information systems.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">l)\u2003Activity recording and detection of harmful code.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">m)\u2003Security incidents.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">n)\u2003Continuity of the activity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00f1)\u2003Continuous improvement of the security process.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Scope<\/h2>\n<p><span style=\"font-weight: 400;\">The information systems that support the development, implementation, consulting carried out by the accessibility department according to the current categorization.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Objectives<\/h2>\n<p><span style=\"font-weight: 400;\">For all of the above, the Management establishes the following information security objectives:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Provide a framework to increase resilience to provide an effective response.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure the rapid and efficient recovery of services, in the face of any physical disaster or contingency that may occur and put the continuity of operations at risk.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Prevent information security incidents to the extent technically and economically viable, as well as mitigate information security risks generated by our activities.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Guarantee the confidentiality, integrity, availability, authenticity and traceability of the information.<\/span><\/li>\n<\/ul>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Regulatory framework<\/h2>\n<p><span style=\"font-weight: 400;\">One of the objectives must be to comply with applicable legal requirements and any other requirements that we subscribe to in addition to the commitments acquired with clients, as well as their continuous updating. To this end, the legal and regulatory framework in which we develop our activities is:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">REGULATION (EU) 2016\/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016 regarding the protection of natural persons with regard to the processing of personal data and the free circulation of these data.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Organic Law 3\/2018, of December 5, on the Protection of Personal Data and guarantee of digital rights.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Royal Legislative Decree 1\/1996, of April 12, Intellectual Property Law.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Law 2\/2019, of March 1, which modifies the consolidated text of the Intellectual Property Law, approved by Royal Legislative Decree 1\/1996, of April 12, and by which Directive 2014\/26\/EU of the European Parliament and of the Council, of February 26, 2014, and the Directive (EU) are incorporated into the Spanish legal system. 2017\/1564 of the European Parliament and of the Council, of September 13, 2017.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Royal Decree 311\/2022, of May 3, which regulates the National Security Scheme.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Law 34\/2002 of July 11 on Information Society Services and Electronic Commerce (LSSI).<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Law 40\/2015, of October 1, on the Legal Regime of the Public Sector.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Law 39\/2015, of October 1, on the Common Administrative Procedure of Public Administrations.<\/span><\/li>\n<\/ul>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Development<\/h2>\n<p><span style=\"font-weight: 400;\">In order to achieve these objectives it is necessary:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Continuously improve our information security system.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Identify potential threats, as well as the impact on business operations that these threats, if they materialize, may cause.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Preserve the interests of its main stakeholders (customers, shareholders, employees and suppliers), reputation, brand and value creation activities.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Work jointly with our suppliers and subcontractors in order to improve the provision of IT services, the continuity of services and the security of information, which results in greater efficiency in our activity.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Evaluate and guarantee the technical competence of the staff, as well as ensure their adequate motivation for their participation in the continuous improvement of our processes, providing adequate training and internal communication so that they develop good practices defined in the system.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Guarantee the correct condition of the facilities and the appropriate equipment, so that they are in accordance with the activity, objectives and goals of the company.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Guarantee a continuous analysis of all relevant processes, establishing the relevant improvements in each case, based on the results obtained and the established objectives.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Structure our management system so that it is easy to understand. Our management system has the following structure:<\/span><\/li>\n<\/ul>\n<p><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Pyramid structure of the management system. Records at the base, above procedures and at the top policies.\" viewBox=\"0 0 300 96\" width=\"300\" height=\"96\" style=\"display:block;margin:0 auto;max-width:100%;height:auto;\"><path d=\"M150 1 L200 32 H100 Z\" fill=\"#c74d4d\" stroke=\"#fff\" stroke-width=\"2\"\/><path d=\"M100 32 H200 L250 64 H50 Z\" fill=\"#bb9849\" stroke=\"#fff\" stroke-width=\"2\"\/><path d=\"M50 64 H250 L298 95 H2 Z\" fill=\"#98b956\" stroke=\"#fff\" stroke-width=\"2\"\/><text x=\"150\" y=\"25\" text-anchor=\"middle\" font-size=\"9\" font-family=\"Arial,sans-serif\" fill=\"#111\">Policies<\/text><text x=\"150\" y=\"54\" text-anchor=\"middle\" font-size=\"9\" font-family=\"Arial,sans-serif\" fill=\"#111\">Procedures<\/text><text x=\"150\" y=\"84\" text-anchor=\"middle\" font-size=\"9\" font-family=\"Arial,sans-serif\" fill=\"#111\">Records<\/text><\/svg><\/p>\n<p><span style=\"font-weight: 400;\">The management of our system is entrusted to the SYSTEMS MANAGER and the system will be available in our information system in a repository, which can be accessed according to the access profiles granted according to our current access management procedure.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Security Organization<\/h2>\n<p><span style=\"font-weight: 400;\">The essential responsibility falls on the General Management of APTENT, since it is responsible for organizing the functions and responsibilities and for providing adequate resources to achieve the objectives of the ENS. Managers are also responsible for setting a good example by following established safety standards.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These principles are assumed by the Management, who provides the necessary means and provides its employees with sufficient resources for their compliance, expressing and making them publicly known through these Security Policies.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The defined security roles or functions are:<\/span><\/p>\n<div aria-label=\"Table 1: security policy\" role=\"region\" style=\"max-width:100%;overflow-x:auto;margin:.5em 0 .75em;\" tabindex=\"0\">\n<table border=\"1\" style=\"width:100%;border-collapse:collapse;\">\n<tbody>\n<tr style=\"background-color: #6aa84f; color: white;\">\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\"><strong>Function<\/strong><\/td>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\"><strong>Duties and responsibilities<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\"><b>Information Manager (RINFO)<\/b><\/td>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\">\n<ul>\n<li><span style=\"font-weight: 400;\">Make decisions regarding the information processed<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\"><b>Responsible for services (RSER)<\/b><\/td>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\">\n<ul>\n<li><span style=\"font-weight: 400;\">Coordinate the implementation of the system<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Continuously improve the system<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\"><b>Security Manager (RSEG)<\/b><\/td>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\">\n<ul>\n<li><span style=\"font-weight: 400;\">Determine the suitability of technical measures<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Provide the best technology for the service<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\"><b>System Manager (RSIS)<\/b><\/td>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\">\n<ul>\n<li><span style=\"font-weight: 400;\">Coordinate the implementation of the system<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Continuously improve the system<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\"><b>Address<\/b><\/td>\n<td style=\"padding:10px;vertical-align:top;border:1px solid #c9d6e3;overflow-wrap:anywhere;\">\n<ul>\n<li><span style=\"font-weight: 400;\">Provide the necessary resources for the system<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Lead the system<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p><span style=\"font-weight: 400;\">This definition of duties and responsibilities is completed in the job profiles and in the Registry of Managers, Roles and Responsibilities system documents.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Conflict Resolution<\/h2>\n<p><span style=\"font-weight: 400;\">Differences in criteria that could lead to a conflict will be dealt with within the Security Committee and the criteria of the General Directorate will prevail in all cases.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Security Committee<\/h2>\n<p><span style=\"font-weight: 400;\">The procedure for their appointment and renewal will be ratification by the security committee.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The committee for security management and coordination is the body with the greatest responsibility within the information security management system, so that all the most important decisions related to security are agreed upon by this committee.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The members of the Information Security Committee are:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Information Manager<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Responsible for Services<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Security Manager<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">System Manager<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Company Address\u00a0<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">These members are appointed by the committee, the only body that can appoint, renew and dismiss them.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The safety committee is an autonomous, executive body with autonomy for decision-making and that does not have to subordinate its activity to any other element of our company.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">APTENT Information Security is developed in the complementary document to this Security Organization Policy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This policy is complemented by the rest of the policies, procedures and documents in force to develop our management system.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Risk Management<\/h2>\n<p><span style=\"font-weight: 400;\">All systems subject to this Policy must carry out a risk analysis, evaluating the threats and risks to which they are exposed. This analysis is reviewed regularly:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">at least once a year;<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">when the information handled changes;<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">when the services provided change;<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">when a serious security incident occurs;<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">when serious vulnerabilities are reported.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">To harmonize risk analyses, the ICT Security Committee will establish a reference assessment for the different types of information handled and the different services provided. The ICT Security Committee will boost the availability of resources to meet the security needs of the different systems, promoting horizontal investments.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To carry out the risk analysis, the risk analysis methodology developed in the Risk Analysis procedure will be taken into account.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Personnel Management<\/h2>\n<p><span style=\"font-weight: 400;\">All members of APTENT have the obligation to know and comply with this Information Security Policy and the Security Regulations, and it is the responsibility of the ICT Security Committee to provide the necessary means for the information to reach those affected.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">All APTENT members will attend an ICT security awareness session at least once a year. A continuous awareness program will be established to serve all APTENT members, particularly new members.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Persons with responsibility for the use, operation or administration of ICT systems will receive training in the safe handling of the systems to the extent they need it to carry out their work. Training will be mandatory before assuming a responsibility, whether it is your first assignment or whether it is a change of job or responsibilities therein. <\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">HR Professionalism and Safety<\/h2>\n<p><span style=\"font-weight: 400;\">This Policy applies to all APTENT personnel and external personnel who perform tasks within the company.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">HR will include information security functions in employee job descriptions, inform all hired personnel of their obligations regarding compliance with the Information Security Policy, manage Confidentiality Commitments with personnel, and coordinate user training regarding this Policy.<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The Security Management Manager (RGS) is responsible for monitoring, documenting and analyzing reported security incidents, as well as communicating to the Information Security Committee and information owners.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The Information Security Committee will be responsible for implementing the necessary means and channels for the Security Management Manager (RGS) to handle incident reports and system anomalies. The Committee will also be aware of, supervise the investigation, monitor the evolution of information and promote the resolution of information security incidents.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The Security Management Manager (RGS) will participate in the preparation of the Confidentiality Commitment to be signed by employees and third parties who perform functions at APTENT, in advising on the sanctions that will be applied for non-compliance with this Policy and in the treatment of information security incidents.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">All APTENT staff are responsible for reporting information security weaknesses and incidents that are detected in a timely manner.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Professionalism of human resources:<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Determine the necessary competence of personnel to carry out work that affects Information Security.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that people are competent based on appropriate education, training or experience.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Demonstrate through documented information that the competency of personnel in matters of Information Security is necessary.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">The objectives of controlling personnel safety are:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Reduce the risks of human error, implementation of irregularities, improper use of facilities and resources, and unauthorized handling of information.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Explain security responsibilities at the personnel recruitment stage and include them in the agreements to be signed and verify compliance during the performance of the tasks.\u00a0<\/span><span style=\"font-weight: 400;\">employee tasks.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that users are aware of information security threats and concerns and are trained to support the APTENT Information Security Policy in the course of their normal duties.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Establish confidentiality commitments with all staff and users outside the information processing facilities.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Establish the necessary tools and mechanisms to promote the communication of existing security weaknesses, as well as incidents, in order to minimize their effects and prevent their recurrence.<\/span><\/li>\n<\/ul>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Authorization and Access Control to Information Systems<\/h2>\n<p><span style=\"font-weight: 400;\">Controlling access to information systems aims to:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Prevent unauthorized access to information systems, databases and information services.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Implement security in user access through authentication and authorization techniques.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Control the security of the connection between the APTENT network and other public or private networks.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Review critical events and activities carried out by users on the systems.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Raise awareness about your responsibility for the use of passwords and equipment.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure information security when using laptops and personal computers for remote work.<\/span><\/li>\n<\/ul>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Protection of Facilities<\/h2>\n<p><span style=\"font-weight: 400;\">The objectives of this policy regarding the protection of facilities are:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Prevent unauthorized access, damage and interference to APTENT headquarters, facilities and information<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Protect APTENT critical information processing equipment by placing it in protected areas and protected by a defined security perimeter, with appropriate security measures and access controls. Likewise, consider its protection during its transfer and remain outside the protected areas, for maintenance or other reasons.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Control environmental factors that could harm the proper functioning of the computer equipment that houses the APTENT information.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Implement measures to protect the information handled by staff in the offices, within the normal framework of their usual tasks.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Provide protection proportional to the identified risks.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This Policy applies to all physical resources related to APTENT information systems, facilities, equipment, wiring, files, storage media, etc.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It should be noted that in the case of APTENT, all development, quality, etc. environments are located externally in secure hosting, so only the laptops and peripherals must be protected locally.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Head of Security Management (RGS), together with the Information Holders, as appropriate, will define the physical and environmental security measures for the protection of critical assets, based on a risk analysis, and will supervise their application. It will also verify compliance with physical and environmental security provisions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Those responsible for the different departments will define the levels of physical access of APTENT staff to the restricted areas under their responsibility. Information Owners will formally authorize off-site work with information about their business to APTENT employees when they deem it appropriate.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">All APTENT staff are responsible for compliance with the clean screen and desktop policy, for the protection of information related to daily work in the offices.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Product acquisition<\/h2>\n<p><span style=\"font-weight: 400;\">The different departments must ensure that ICT security is an integral part of each stage of the system&#8217;s life cycle, from its conception to its decommissioning, through development or acquisition decisions and exploitation activities. Security requirements and financing needs must be identified and included in planning, requests for offers, and bidding documents for ICT projects.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On the other hand, information security will be taken into account in the acquisition and maintenance of information systems, limiting and managing change.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Default security<\/h2>\n<p><span style=\"font-weight: 400;\">APTENT considers it strategic for the entity that the processes integrate information security as part of their life cycle. Information systems and services must include security by default from their creation to their withdrawal, including security in development and\/or acquisition decisions and in all activities in operation, establishing security as an integral and transversal process.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">System integrity and updating<\/h2>\n<p><span style=\"font-weight: 400;\">APTENT is committed to guaranteeing the integrity of the system through a change management process that allows control of the update of physical or logical elements through authorization prior to their installation in the system. Said evaluation will be carried out mainly by the technical management who will evaluate the impact on the security of the system before making the changes and will control in a documented manner those changes that are evaluated as important or with implications on the security of the systems.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Through periodic security reviews, the security status of the systems will be evaluated in relation to the manufacturers&#8217; specifications, vulnerabilities and updates that affect them, reacting diligently to manage the risk in view of their security status.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Protection of information stored and in transit<\/h2>\n<p><span style=\"font-weight: 400;\">APTENT establishes protection measures for the Security of Information stored or in transit through insecure environments. Laptops, peripheral devices, information carriers and communications over open networks or with weak encryption will be considered insecure environments. <\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Prevention of interconnected information systems<\/h2>\n<p><span style=\"font-weight: 400;\">APTENT, establishes protection measures for Information Security especially to protect the perimeter, in particular, if connected to public networks, especially if they are used in whole or mainly, for the provision of electronic communications services available to the public.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In any case, the risks derived from the interconnection of the system, through networks, with other systems will be analyzed, and their connection point will be controlled. Electronic connections available to the public.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Activity logs<\/h2>\n<p><span style=\"font-weight: 400;\">APTENT will record user activities, retaining the necessary information to monitor, analyze, investigate and document improper or unauthorized activities, allowing the person acting to be identified at all times.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The main objectives of Incident Management are to:<\/span><\/p>\n<ul style=\"padding-bottom:.5em;\">\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Establish a detection and reaction system against harmful code.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Have procedures for managing security incidents and weaknesses detected in the elements of the information system.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">These procedures will cover detection mechanisms, classification criteria, analysis and resolution procedures, as well as communication channels to interested parties and the record of actions.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">This log is used for continuous improvement of system security.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that IT services return to optimal performance.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Reduce the possible risks and impacts that the incident may cause.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Ensure the integrity of the systems in the event of a security incident.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Communicate the impact of an incident as soon as it is detected to activate the alarm; and implement an appropriate business communication plan.<\/span><\/li>\n<li aria-level=\"1\" style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Promote business efficiency.<\/span><\/li>\n<\/ul>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Continuity of activity<\/h2>\n<p><span style=\"font-weight: 400;\">APTENT, with the aim of guaranteeing the continuity of activities, establishes measures so that the systems have backup copies and establishes necessary mechanisms to guarantee the continuity of operations, in the event of loss of the usual means of work.<\/span><\/p>\n<h2 style=\"margin-top:.9em;margin-bottom:.4em;padding-bottom:0;\">Continuous improvement of the security process<\/h2>\n<p><span style=\"font-weight: 400;\">APTENT establishes a process of continuous improvement of information security by applying the criteria and methodology established in the National Security Scheme.<\/span><\/p>\n<p style=\"text-align: center;\">In Legan\u00e9s, on January 17, 2025<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security policyApproval and entry into forceThis Information Security Policy is effective from the date of signature and until replaced by a new Policy.APTENT MissionTo achieve its objectives, APTENT assumes its commitment to information security, committing to its proper management, in order to offer all its interest groups the greatest guarantees regarding the security of the [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"class_list":["post-2381","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Security policy - Copla<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/copla.io\/en\/politica-de-seguridad\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security policy - Copla\" \/>\n<meta property=\"og:description\" content=\"Security policyApproval and entry into forceThis Information Security Policy is effective from the date of signature and until replaced by a new Policy.APTENT MissionTo achieve its objectives, APTENT assumes its commitment to information security, committing to its proper management, in order to offer all its interest groups the greatest guarantees regarding the security of the [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/copla.io\/en\/politica-de-seguridad\/\" \/>\n<meta property=\"og:site_name\" content=\"Copla\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-09T19:01:57+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"18 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/copla.io\/en\/politica-de-seguridad\/\",\"url\":\"https:\/\/copla.io\/en\/politica-de-seguridad\/\",\"name\":\"Security policy - Copla\",\"isPartOf\":{\"@id\":\"https:\/\/copla.io\/#website\"},\"datePublished\":\"2025-01-17T11:03:42+00:00\",\"dateModified\":\"2026-10-09T19:01:57+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/copla.io\/en\/politica-de-seguridad\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/copla.io\/en\/politica-de-seguridad\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/copla.io\/en\/politica-de-seguridad\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\/\/copla.io\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/copla.io\/#website\",\"url\":\"https:\/\/copla.io\/\",\"name\":\"Copla\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/copla.io\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security policy - Copla","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/copla.io\/en\/politica-de-seguridad\/","og_locale":"en_US","og_type":"article","og_title":"Security policy - Copla","og_description":"Security policyApproval and entry into forceThis Information Security Policy is effective from the date of signature and until replaced by a new Policy.APTENT MissionTo achieve its objectives, APTENT assumes its commitment to information security, committing to its proper management, in order to offer all its interest groups the greatest guarantees regarding the security of the [&hellip;]","og_url":"https:\/\/copla.io\/en\/politica-de-seguridad\/","og_site_name":"Copla","article_modified_time":"2026-10-09T19:01:57+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"18 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/copla.io\/en\/politica-de-seguridad\/","url":"https:\/\/copla.io\/en\/politica-de-seguridad\/","name":"Security policy - Copla","isPartOf":{"@id":"https:\/\/copla.io\/#website"},"datePublished":"2025-01-17T11:03:42+00:00","dateModified":"2026-10-09T19:01:57+00:00","breadcrumb":{"@id":"https:\/\/copla.io\/en\/politica-de-seguridad\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/copla.io\/en\/politica-de-seguridad\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/copla.io\/en\/politica-de-seguridad\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/copla.io\/en\/"},{"@type":"ListItem","position":2,"name":"Security policy"}]},{"@type":"WebSite","@id":"https:\/\/copla.io\/#website","url":"https:\/\/copla.io\/","name":"Copla","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/copla.io\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/pages\/2381","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/comments?post=2381"}],"version-history":[{"count":1,"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/pages\/2381\/revisions"}],"predecessor-version":[{"id":2417,"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/pages\/2381\/revisions\/2417"}],"wp:attachment":[{"href":"https:\/\/copla.io\/en\/wp-json\/wp\/v2\/media?parent=2381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}