Commitment Statement | General Information Security and Privacy Policy

Commitment Statement | General Information Security and Privacy Policy

Forvis Mazars in Portugal recognizes information security as an essential element for the sustainable success of its operations and for fulfilling its responsibilities to its stakeholders.

Our global purpose - to help build the economic foundations of a prosperous and fair world by promoting the success of our clients and our people, confidence in the markets, and the integrity of our profession - guides our ongoing efforts and investments in the most critical areas.

In this regard, the Partners Board states its commitment to information security and privacy, ensuring support for the Information Security Management System (ISMS) and its continuous improvement, with the objectives of maintaining ISO/IEC 27001:2022 certification, increasing information security awareness, strengthening the Partners’ Board commitment to the Information Security Management System, and reducing the number of security incidents. To achieve these objectives, the following commitments are assumed:

  • Information Protection and Classification: Ensure the protection and classification of information and assets across the three fundamental pillars – confidentiality, integrity and availability – taking into account their criticality to Forvis Mazars in Portugal.
  • Legal Compliance: Ensure compliance with all laws, regulations and legal requirements applicable to information security, as well as internal policies (local and Forvis Mazars Group), associated standards, client requirements and requirements from other parties external to Forvis Mazars in Portugal, ensuring compliance across all internal areas.
  • Data Privacy: Safeguard privacy rights and the protection of personal data, ensuring the security of information relating to clients, employees and other data subjects.
  • Risk Management: Adopt a systematic approach to continuously assess and monitor risks related to information security, implementing effective controls that ensure the management of identified threats, while guaranteeing the continuous protection of data throughout all stages of the asset lifecycle, from its design to its decommissioning.
  • Shared Responsibility and Training: Information security is a shared responsibility among employees, clients, suppliers and partners, requiring a joint commitment to best practices. This commitment shall be supported by continuous awareness and training actions, ensuring that all parties understand their responsibility and adopt effective measures to protect information.
  • Security Incident Management: Establish and maintain effective processes for managing security incidents, including the prevention, detection, recording, reporting, response and investigation of incidents and vulnerabilities that may compromise information security, personal data protection or business continuity.
  • Business Continuity and Integration into Business Processes: Ensure the continuity of operations through resilient procedures that protect critical processes and enable a rapid response to adverse situations, integrating Information Security into internal strategic objectives. This alignment strengthens client confidence, ensures the availability of essential systems and constitutes a differentiating and competitive factor.
  • Information Security Management and Continuous Improvement: Ensure the maintenance of a robust Information Security Management System aligned with best practices, supported by a systematic process of continuous improvement. This process includes the periodic review of policies, procedures and controls, with the objective of identifying opportunities for improvement and implementing proactive measures that ensure effective protection against internal and external threats.