INFORMATION SECURITY POLICY

1. Purpose

Brahm Precision Products Corporation Spain, S.A. recognises information as a critical business asset and is committed to protecting the information entrusted to the organisation by its customers, employees, suppliers and other interested parties.

This Information Security Policy establishes the main principles that guide the protection of information and the responsible use of information systems throughout the organisation.

2. Scope

This Policy applies to all information, processes, people, systems, devices and third parties involved in the activities of Brahm Precision Products Corporation Spain, S.A.

It covers information in any format, whether digital, physical, verbal or visual, and applies throughout its entire lifecycle.

3. Our Commitments

Brahm Precision Products Corporation Spain, S.A. is committed to:

  • Protecting the confidentiality, integrity and availability of information.
  • Managing information security risks systematically and proportionately.
  • Complying with applicable legal, regulatory, contractual and customer requirements.
  • Ensuring that access to information is granted only to authorised persons and according to business needs.
  • Protecting personal data, confidential information and intellectual property.
  • Promoting information security awareness and appropriate training among employees.
  • Preventing, detecting, reporting and managing information security incidents.
  • Maintaining appropriate business continuity and recovery arrangements.
  • Applying information security requirements to suppliers, contractors and other relevant third parties.
  • Reviewing information security objectives and continually improving the effectiveness of security measures.

4. Responsibilities

Information security is a shared responsibility.

The Management of Brahm Precision Products Corporation Spain, S.A. provides the necessary direction, resources and support to maintain appropriate information security controls.

Employees, contractors, suppliers and other authorised users are expected to comply with the organisation’s applicable security requirements and to use information and information systems responsibly.

5. Review and Continual Improvement

This Policy is reviewed periodically and whenever significant changes occur in the organisation, technology, applicable legislation, contractual requirements or information security risks.

Brahm Precision Products Corporation Spain, S.A. is committed to the continual improvement of its information security management practices.

6. Contact

Questions, concerns or information security matters related to this Policy may be submitted to:

dataprotection.bppcs@brahmcorp.com