Skip to main content

SECURITY POLICY

Objective

This policy aims to protect company information and is based on the National Security Framework (ENS) and the ISO 27001 standard.

Commitment to security: The company’s management is committed to information security and the policy is communicated to all employees.
Risk-based approach: A periodic risk analysis is performed to determine the security measures to be implemented, and risks that may affect service delivery are prioritized.
Scope: The policy applies to all information systems and all personnel, including external providers.
Access control: Access to systems is limited to authorized users and privileges are restricted to the minimum necessary.
Information protection: Measures are implemented to protect information stored and in transit, including making backups.
Incident response: Procedures are established for the management of security incidents, including mechanisms for detection, classification, analysis, and resolution.
Continuous improvement: The security process is continuously updated and improved.
Security Committee: A Security Committee has been established responsible for defining security requirements, protecting data and privacy, monitoring access to information, developing incident response measures, ensuring regulatory compliance, promoting security training and awareness, and monitoring the response to security breaches.
Note: This document is an excerpt from our Security Policy. If you would like access to the full version, please request it and we will provide it to you.