{"id":360045,"date":"2023-09-28T16:50:30","date_gmt":"2023-09-28T16:50:30","guid":{"rendered":"https:\/\/pandorafms.com\/politica-de-seguridad\/"},"modified":"2025-08-21T16:20:30","modified_gmt":"2025-08-21T16:20:30","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/pandorafms.com\/en\/security-policy\/","title":{"rendered":"Security Policy"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; custom_padding_last_edited=&#8221;on|desktop&#8221; admin_label=&#8221;Header 2024&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(193,204,220,0.25)&#8221; background_enable_image=&#8221;off&#8221; background_size=&#8221;custom&#8221; background_image_width=&#8221;1280px&#8221; background_position=&#8221;bottom_center&#8221; max_width=&#8221;98%&#8221; module_alignment=&#8221;center&#8221; custom_margin=&#8221;0px||0px||true|false&#8221; custom_margin_tablet=&#8221;10px|10px|0px|10px|false|true&#8221; custom_margin_phone=&#8221;10px|10px|0px|10px|false|true&#8221; custom_margin_last_edited=&#8221;on|phone&#8221; custom_padding=&#8221;10px|20px|30px|20px|false|true&#8221; custom_padding_tablet=&#8221;10px|20px|0px|20px|false|true&#8221; custom_padding_phone=&#8221;10px|10px|0px|10px|false|true&#8221; background_last_edited=&#8221;off|desktop&#8221; background_size_tablet=&#8221;contain&#8221; border_radii=&#8221;on|20px|20px|20px|20px&#8221; global_colors_info=&#8221;{}&#8221; background__hover_enabled=&#8221;off|desktop&#8221;][et_pb_row column_structure=&#8221;3_5,2_5&#8243; use_custom_gutter=&#8221;on&#8221; gutter_width=&#8221;1&#8243; make_equal=&#8221;on&#8221; custom_padding_last_edited=&#8221;on|phone&#8221; admin_label=&#8221;Intro&#8221; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; width=&#8221;90%&#8221; width_tablet=&#8221;90%&#8221; width_phone=&#8221;100%&#8221; width_last_edited=&#8221;on|phone&#8221; max_width=&#8221;1280px&#8221; module_alignment=&#8221;center&#8221; custom_margin=&#8221;0px||0px||true|false&#8221; custom_padding=&#8221;0px||0px||true|false&#8221; custom_padding_tablet=&#8221;0px||0px||true|false&#8221; custom_padding_phone=&#8221;|0px||0px|true|true&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#ffffff&#8221; background_enable_image=&#8221;off&#8221; custom_padding=&#8221;4%|4%|4%|4%|true|true&#8221; custom_padding_tablet=&#8221;4%|4%|4%|4%|true|true&#8221; custom_padding_phone=&#8221;20px|20px|20px|20px|true|true&#8221; custom_padding_last_edited=&#8221;on|phone&#8221; custom_css_main_element=&#8221;margin-right:10px!important;&#8221; border_radii=&#8221;on|10px|10px|10px|10px&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_font_size=&#8221;2em&#8221; module_alignment=&#8221;center&#8221; custom_margin=&#8221;0px||0px||true|false&#8221; custom_padding=&#8221;0px||0px||true|false&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1 class=\"h1-b\"><span style=\"font-size: 0.4em!important; text-transform: uppercase; color: #318280; letter-spacing: 0.03em!important;\">Security Policy<\/span><br \/>\nThe purpose of this Policy is to achieve adequate protection of Pandora FMS information, preserving the following security qualities<\/h1>\n<p>&nbsp;<\/p>\n<p><strong>Confidentiality: <\/strong>Ensure that the information is accessible only to those who are authorized to have access to it.<\/p>\n<p><strong>Integrity:<\/strong> Ensure the accuracy and integrity of the information and the methods of its processing.<\/p>\n<p><strong>Availability:<\/strong> Ensure that authorized users have access to the information and its associated assets when required.<\/p>\n<p><strong>Traceability:<\/strong> ensures the ability to track and control activities related to data and information systems throughout their entire lifecycle.<\/p>\n<p><strong>Authenticity:<\/strong> ensures that an entity (user, device, system) is who it claims to be.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; disabled_on=&#8221;off|off|off&#8221; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_enable_color=&#8221;off&#8221; background_image=&#8221;https:\/\/pandorafms.com\/wp-content\/uploads\/2024\/02\/securidad2.jpg&#8221; custom_padding=&#8221;0px|0px|0px|0px|true|true&#8221; custom_css_main_element=&#8221;top:0px;&#8221; border_radii=&#8221;on|10px|10px|10px|10px&#8221; global_colors_info=&#8221;{}&#8221; custom_css_main_element_last_edited=&#8221;on|tablet&#8221; custom_css_main_element_tablet=&#8221;top:10px;&#8221; custom_css_main_element_phone=&#8221;top:10px;&#8221;][et_pb_image src=&#8221;https:\/\/pandorafms.com\/wp-content\/uploads\/2024\/01\/Invisible-frame.png&#8221; alt=&#8221;Pandora FMS&#8221; title_text=&#8221;Pandora FMS&#8221; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_enable_video_mp4=&#8221;off&#8221; background_enable_video_webm=&#8221;off&#8221; custom_margin=&#8221;0px|0px|0px|0px|false|false&#8221; custom_padding=&#8221;0px|0px|0px|0px|false|false&#8221; border_radii=&#8221;on|10px|10px|10px|10px&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row use_custom_gutter=&#8221;on&#8221; gutter_width=&#8221;1&#8243; make_equal=&#8221;on&#8221; custom_padding_last_edited=&#8221;off|tablet&#8221; admin_label=&#8221;Intro&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; width=&#8221;90%&#8221; width_tablet=&#8221;90%&#8221; width_phone=&#8221;100%&#8221; width_last_edited=&#8221;on|phone&#8221; max_width=&#8221;1280px&#8221; module_alignment=&#8221;center&#8221; custom_margin=&#8221;0px||0px||true|false&#8221; custom_padding=&#8221;20px||0px||false|false&#8221; custom_padding_tablet=&#8221;40px||40px||true|false&#8221; custom_padding_phone=&#8221;|0px||0px|true|true&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover_enabled=&#8221;off|desktop&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#ffffff&#8221; background_enable_image=&#8221;off&#8221; custom_padding=&#8221;4%|4%|4%|4%|true|true&#8221; custom_padding_tablet=&#8221;4%|4%|4%|4%|true|true&#8221; custom_padding_phone=&#8221;20px|20px|20px|20px|true|true&#8221; custom_padding_last_edited=&#8221;on|phone&#8221; custom_css_main_element=&#8221;margin-right:10px!important;&#8221; border_radii=&#8221;on|10px|10px|10px|10px&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;0px||0px||true|false&#8221; custom_padding=&#8221;0px||0px||true|false&#8221; hover_enabled=&#8221;0&#8243; custom_css_main_element=&#8221;font-family:%22Pandora-Light%22!important; font-size:1em!important;&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p>These basic principles must be preserved and ensured in any form that the information takes, whether in digital, printed, visual or spoken format, and regardless of whether it is processed in Pandora FMS facilities or outside them. Likewise, these principles must be considered in the following security areas:<\/p>\n<ul class=\"introti\">\n<li style=\"margin-bottom: 10px;\"><strong>Physical:<\/strong> Covering the security of dependencies, facilities, hardware systems, supports and any physical asset that processes or may process information.<\/li>\n<li style=\"margin-bottom: 10px;\"><strong>Logical:<\/strong> Including the aspects of protection of applications, networks and prototypes of digital communication and computer systems.<\/li>\n<li style=\"margin-bottom: 10px;\"><strong>Corporate-political:<\/strong> Made up by the security aspects related to the organization itself, to internal rules, regulations and legal regulations.<\/li>\n<\/ul>\n<p>Pandora FMS is firmly committed to maintaining a continuous improvement approach to information security management. This commitment includes the periodic review and updating of policies, procedures and controls, as well as the adoption of new technologies and best practices. Continuous improvement will be an essential part of the Information Security Management System (ISMS), and will be reflected in all management reviews, as well as in the action plans developed to meet the organization&#8217;s strategic objectives.<\/p>\n<p>Pandora FMS bases its activity on the processing of different types of data and information. This allows to run basic business processes. In such a way that the damage or loss of the organization&#8217;s assets affects the performance of its operations and may jeopardize the continuity of the organization. To prevent this from happening, an Information Security Policy has been designed, whose main objectives are:<\/p>\n<ul class=\"introti\">\n<li style=\"margin-bottom: 10px;\">Protecting, through controls and security measures, the company&#8217;s assets against threats that may lead to security incidents.<\/li>\n<li style=\"margin-bottom: 10px;\">Mitigating the effects of security incidents, which may affect both members of the organization and external stakeholders.<\/li>\n<li style=\"margin-bottom: 10px;\">Establishing an information and data classification system in order to protect critical information assets, both internal and those that may be of interest to external stakeholders.<\/li>\n<li style=\"margin-bottom: 10px;\">Defining the responsibilities in terms of information security by generating the corresponding organizational structure.<\/li>\n<li style=\"margin-bottom: 10px;\">Developing a set of rules, standards and procedures applicable to management bodies, employees, partners, external service providers, etc. These security policies and compliance with ISO 27001 standards will be particularly relevant to customers, suppliers and external organizations and must be communicated in a timely manner. Of course, internally there will be greater communication of the operation of the ISMS and all internal policies and regulations.<\/li>\n<li style=\"margin-bottom: 10px;\">Specifying the effects of non-compliance with the Safety Policy in the workplace, through continuous training and internal communication.<\/li>\n<li style=\"margin-bottom: 10px;\">Continuously assessing the risks affecting the assets in order to adopt the appropriate security measures\/controls.<\/li>\n<li style=\"margin-bottom: 10px;\">Verifying the operation of security measures and controls through internal security audits carried out by independent auditors.<\/li>\n<li style=\"margin-bottom: 10px;\">Training users in security management and information and communications technologies.<\/li>\n<li style=\"margin-bottom: 10px;\">Controlling the traffic of information and data through communications infrastructures or by sending optical, magnetic, paper data carriers, etc.<\/li>\n<li style=\"margin-bottom: 10px;\">Observing the legislation on data protection, intellectual property, labor, information society services, criminal, etc., that affects the assets of Pandora FMS and its relationship with external stakeholders.<\/li>\n<li style=\"margin-bottom: 10px;\">Protecting the intellectual capital of the organization so that it is not disclosed or used unlawfully.<\/li>\n<li style=\"margin-bottom: 10px;\">Ensuring an efficient service to our customers and other external stakeholders with a high level of quality and integrity, thus preserving their trust.<\/li>\n<li style=\"margin-bottom: 10px;\">Obtaining the evidence that allows to prove the security incidents and the identification of their author, whether it is external (suppliers, customers, users) or internal to the company.<\/li>\n<li style=\"margin-bottom: 10px;\">Reducing the chances of unavailability through the proper use of the organization&#8217;s assets, both internal and external.<\/li>\n<li style=\"margin-bottom: 10px;\">Defending assets against internal or external attacks so that they do not become security incidents.<\/li>\n<li style=\"margin-bottom: 10px;\">Controlling the operation of security measures by finding out the number of incidents, their nature and effects.<\/li>\n<\/ul>\n<h3 class=\"h4-b\">Regulatory Framework<\/h3>\n<p>One of the objectives must be to comply with applicable legal requirements and any other requirements we subscribe to, in addition to the commitments made with clients, as well as their continuous updating. To this end, the legal and regulatory framework in which we carry out our activities is:<\/p>\n<ul class=\"introti\">\n<li style=\"margin-bottom: 10px;\">REGULATION (EU) 2016\/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.<\/li>\n<li style=\"margin-bottom: 10px;\">Organic Law 3\/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights.<\/li>\n<li style=\"margin-bottom: 10px;\">Royal Legislative Decree 1\/1996, of 12 April, Intellectual Property Law.<\/li>\n<li style=\"margin-bottom: 10px;\">Law 2\/2019, of 1 March, amending the recast text of the Intellectual Property Law, approved by Royal Legislative Decree 1\/1996 of 12 April, and incorporating into Spanish law Directive 2014\/26\/EU of the European Parliament and of the Council of 26 February 2014, and Directive (EU) 2017\/1564 of the European Parliament and of the Council of 13 September 2017.<\/li>\n<li style=\"margin-bottom: 10px;\">Royal Decree 311\/2022, of 3 May, developing the National Security Framework, amended by Royal Decree 951\/2015, of 23 October.<\/li>\n<li style=\"margin-bottom: 10px;\">Law 34\/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI).<\/li>\n<li style=\"margin-bottom: 10px;\">Law 40\/2015, of 1 October, on the Legal Regime of the Public Sector.<\/li>\n<li style=\"margin-bottom: 10px;\">Law 39\/2015, of 1 October, on the Common Administrative Procedure of Public Administrations.<\/li>\n<\/ul>\n<h3 class=\"h4-b\">Security Committee<\/h3>\n<p>The Security Committee is the body with the highest responsibility within the ISMS, ensuring that all major decisions related to security are agreed upon by this committee.<\/p>\n<p>The members of the Security Committee are:<\/p>\n<ul class=\"introti\">\n<li style=\"margin-bottom: 10px;\">Information Officer<\/li>\n<li style=\"margin-bottom: 10px;\">Services Officer<\/li>\n<li style=\"margin-bottom: 10px;\">Security Officer<\/li>\n<li>Systems Officer<\/li>\n<\/ul>\n<p>In the event of a conflict between the roles defined in this Security Policy regarding the compliance and execution of the assigned functions and tasks, the resolution will be determined by the common hierarchical superior, prioritizing the decision that ensures a higher level of personal data protection. In the absence of a common hierarchical superior, the Security Committee will assume the resolution of the conflict.<\/p>\n<h3 class=\"h4-b\">Risk Management<\/h3>\n<p>All systems subject to this Policy must carry out a risk analysis, assessing the threats and risks to which they are exposed. This analysis is reviewed regularly:<\/p>\n<ul class=\"introti\">\n<li style=\"margin-bottom: 10px;\">At least once a year;<\/li>\n<li style=\"margin-bottom: 10px;\">When the information being handled changes;<\/li>\n<li style=\"margin-bottom: 10px;\">When the services provided change;<\/li>\n<li style=\"margin-bottom: 10px;\">When a major security incident occurs;<\/li>\n<li>When serious vulnerabilities are reported.<\/li>\n<\/ul>\n<p>To harmonize risk analyses, the Security Committee will establish a reference assessment for the different types of information handled and the different services provided. The Security Committee will promote the availability of resources to meet the security needs of the different systems, fostering horizontal security investments.<\/p>\n<p>For the execution of the risk analysis, the risk analysis methodology developed in the Risk Analysis procedure will be taken into account.<\/p>\n<h3 class=\"h4-b\">Security by Default<\/h3>\n<p>Information security is a comprehensive and transversal process that must be integrated into all stages of the information systems and services lifecycle, from creation to retirement.<\/p>\n<p>PANDORA FMS will manage changes to the physical or logical elements of the system through a prior authorization process, with an evaluation of the security impact. Regular security reviews will be carried out to assess the status of systems and manage risk.<\/p>\n<p>PANDORA FMS implements security measures to protect information, both stored and in transit, in environments considered insecure. These environments include laptops, personal digital assistants (PDA), peripheral devices, information media, and communications using open networks or weak encryption.<\/p>\n<p>PANDORA FMS establishes security protection measures for information, especially when connecting to public networks. System interconnection risks will be analyzed and their connection points controlled, including electronic connections available to the public.<\/p>\n<p>PANDORA FMS will keep a log of user activities and retain the information necessary to monitor, analyze, investigate, and document improper or unauthorized activities, allowing identification at all times of the person performing the action.<\/p>\n<p>Through its incident management, PANDORA FMS establishes a detection, response, and recovery system against incidents, ensuring business continuity, reducing impact, and improving security through management, analysis, communication, and recording procedures.<\/p>\n<p>To ensure operational continuity in case of loss of usual working means, PANDORA FMS has implemented measures so that systems have backup copies and recovery mechanisms.<\/p>\n<h3 class=\"h4-b\">Personal data protection<\/h3>\n<p>Pandora FMS processes personal data for purposes previously communicated to the data subjects (their owners) and, if necessary, previously consented to by them at the time of data collection or subsequently.<\/p>\n<p>In terms of data protection, those affected have rights of access, rectification, limitation of processing, portability, opposition, deletion and others (called ARCO\/ARLtPOS rights). This means that any natural person can request information from Pandora FMS about what data is held on them, where it has been obtained, what is done with it, what it is used for and request changes in its use. In the event of the exercise of the ARCO\/ARLtPOS rights of any affected party, Pandora FMS personnel are obliged to immediately notify the Data Protection Officer by sending an email to dpo@pandorafms.com. It is vitally important to do so immediately as there are strict legal deadlines for providing a response.<\/p>\n<p>Anyone with access to Pandora FMS information resources or information assets (both their own or subcontracted personnel) must read, understand, know and accept the Information Security Policy and the Information Systems Use Policy at the beginning of the employment or commercial relationship with Pandora FMS and subsequently its modifications on an annual basis.<\/p>\n<h3 class=\"h4-b\">Address and Contact Information<\/h3>\n<p><strong>Pandora FMS S.L.U<\/strong><br \/>Street Jos\u00e9 Echegaray 8, Alvia, Building I, Floor 2, Office 12. 28232 Las Rozas de Madrid, Madrid. Espa\u00f1a.<\/p>\n<p><strong>Office phone:<\/strong> +34-915597222<br \/><strong>General contact e-mail:<\/strong> info@pandorafms.com<br \/><strong>Data Privacy Officer (DPO):<\/strong> dpo@pandorafms.com<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Policy The purpose of this Policy is to achieve adequate protection of Pandora FMS information, preserving the following security qualities &nbsp; Confidentiality: Ensure that the information is accessible only to those who are authorized to have access to it. Integrity: Ensure the accuracy and integrity of the information and the methods of its processing. [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","_joinchat":[],"footnotes":""},"class_list":["post-360045","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/pages\/360045","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/comments?post=360045"}],"version-history":[{"count":8,"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/pages\/360045\/revisions"}],"predecessor-version":[{"id":402923,"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/pages\/360045\/revisions\/402923"}],"wp:attachment":[{"href":"https:\/\/pandorafms.com\/en\/wp-json\/wp\/v2\/media?parent=360045"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}