Security Policy

INFORMATION SYSTEMS SECURITY POLICY

FAMAR considers that information, especially that relating to its customers, and the different information systems used for its processing are critical assets that must be adequately protected, whatever their form and means of storage, to ensure the proper functioning of FAMAR, safeguarding the operation of its business and the correct service to its customers. The security policy (hereinafter, the “Policy”) seeks to guarantee the correct management of information elements and systems based on three basic pillars, which are key:

  • Confidentiality: guaranteeing its accessibility in a unique and controlled way to authorize people, processes or systems, preventing unauthorized disclosure of the same.
  • Integrity: preventing it from being manipulated by unauthorized third parties in a malicious manner.
  • Availability, through authorization and its recovery in the event of security incidents that cause its loss or corruption.

 
To achieve the objectives established in the field of Information Security, the Policy establishes a series of procedures and actions, always complying with the different applicable standards and requirements in force and maintaining a balance between risk levels and the efficient use of resources through proportionality criteria. The policy applies to all FAMAR members and is established at group level in Spain, Greece, Italy and Germany. Likewise, this Policy will be extended to third parties directly or indirectly involved in the correct operation of the services involved in FAMAR. The fundamental principles to develop FAMAR’s express commitment to the continuous improvement of the information security management system are the following:

  • To ensure that FAMAR’s Information Systems have the appropriate level of security and resilience proposed by FAMAR’s Information Security Committee.
  • To establish a least privileged policy, assigning users the minimum levels or permissions of access necessary, so that the content and the number of people with access to information are limited.
  • To maintain a closed access control policy by default, providing that the information and the systems that process or store it are initially closed, and allowing access to it later, only when necessary.
  • To specify a set of clearly defined information security roles and responsibilities.
  • To segregate the functions and responsibilities in terms of information security, so that they are clearly defined and assigned in the FAMAR organizational chart, avoiding possible conflicts of interest and that more people know the information than necessary.
  • To design and implement several levels of security that are in accordance with the risk analysis carried out on the different assets that encompass the information, to favor in-depth defense.
  • To raise awareness among all FAMAR members about security risks and to ensure that they have information security training as well as the technological capabilities necessary to protect the security of FAMAR’s information systems.
  • To collaborate with relevant government bodies and agencies to improve FAMAR’s safety and compliance with current legislation.
  • To establish fast and accessible communication channels for potential security incidents.
  • To support the process of continuous review and updating of the security management model to always adapt it to the threats that arise and may affect FAMAR:
     
    o Identification: Understand the current context, identifying potential threats that could materialize and be harmful to FAMAR.
    o Protection: Establish appropriate technical and organizational security measures to protect FAMAR’s work, eliminating a potential cybersecurity incident or limiting its impact.
    o Detection: Defining appropriate activities to identify and discover the occurrence of a cybersecurity event.
    o Response: Establishing appropriate measures to be taken in the event of a security incident affecting information.
    o Recovery: Promoting appropriate activities to maintain resilience plans and data restoration

 

FAMAR GROUP

Last updated, 20/07/2026