Ir al contenido principal

nBC Services

SECURITY AND PRIVACY POLICY

The Information Security and Privacy Policy is the general statement that represents the position of the management of Nuvola Business Consulting SAS (hereinafter nBC), regarding the protection of information assets (employees, contractors, third parties, information, processes, information technologies including hardware and software), which support the processes of the Entity and support the implementation of the Information Security Management System, through the generation and publication of its policies, procedures and instructions, as well as the allocation of general and specific responsibilities for the management of information security.

nBC,in order to ensure the strategic direction of the company, establishes the compatibility of the information security policy and the information security objectives, the latter corresponding to:

  • Minimize the risk of the company’s mission processes.
  • Comply with the principles of information security.
  • Comply with the principles of the administrative function.
  • Maintain the trust of employees, contractors and third parties.
  • Support technological innovation.
  • Implement the information security management system.
  • Protect information assets.
  • Establish policies, procedures and instructions on information security.
  • Strengthen the information security culture among employees, third parties, trainees, interns and clients of the company.
  • Ensure business continuity in the event of incidents.

 

Scope/Applicability

  • This policy applies to the entire entity, its employees, contractors and third parties of nBC.

 

Level of compliance

All persons covered by the scope and applicability shall give 100% compliance with the policy.

 

Policies:

  1. Security Policy:

    1. nBC must define the mechanisms to protect information, its use, processing, storage, dissemination; and, it is its duty, to keep this policy updated, as well as the other components of the Information Security Management System that must be aligned with the other management systems of the company.
    2. nBC must evaluate the cost/benefit of the security and information recovery mechanisms, as well as the technological resources involved.
    3. All users of ICT resources must protect, back up and prevent access to information by unauthorized persons, i.e. they are responsible for taking care of all digital information assets, whether or not they are owned by nBC
    4. All nBC employees must follow the information backup procedures and keep a backup log. For the company, this consists of keeping all documents and sensitive information in a One Drive folder associated with corporate email.
    5. All ICT users are responsible for the protection of the information they are in charge of and must not share, publish or leave sensitive data such as username and password, IP addresses, among others.
    6. All ICT users must block the work session of their computer when they leave, even for a short time, minimizing the time that the station is unprotected in their absence.
    7. Any information that comes from an external nBC file or that must be restored must be scanned with the current institutional antivirus.
    8. No user of ICT resources should generate, compile, copy, store, replicate or execute malicious computer code with the intention of causing damage, affecting and interfering with the services of any ICT resource.
    9. All users of ICT resources must not visit sites that are explicitly or implicitly restricted by nBC, or sites that affect productivity in the company; such as access from nBC to sites related to pornography, games, entertainment, etc.

    10. It is prohibited to download malicious software or documents that provide information that threatens the security of nBC information.

    11. No staff member shall provide unauthorized information on any nBC internal or external site.

    12. No user shall download and/or use information, files, images, sound or other copyrighted information, files, images, sound or other copyrighted material from third parties without the prior permission of the third party.
    13. The controls that must be applied for the proper use of the information handled in the offices from the work point of view will be documented and disclosed.
    14. Users must not download software from the Internet under any circumstances and if required must inform the leader.

  1. Information Organization:
    1. nBC must have control of its information prior organization and administration according to the definition of its management framework (roles and responsibilities).
    2. Each area must determine which is its sensitive information and its availability.
    3. All users of the company’s ICT resources must locate the information that needs to be backed up in the places previously established for this purpose (folder in OneDrive 365, corporate account); otherwise they are responsible for their actions and consequences.

 

 

Failure to comply with the Security and Privacy of Information policy will bring with it the legal consequences that apply to the rules of the entity, including the provisions of the rules that fall under the national and territorial government in terms of Security and Privacy of Information.

For more information about the nBC Services experience or to schedule an appointment,
contact info@nbc.services