Information Security Policy

Ensuring the confidentiality, integrity, and availability of information.

1. Objective

Establish the principles and guidelines of the Information Security Management System (ISMS), as part of the Integrated Management System (IMS) of Soluciones Globales JM, aimed at protecting the confidentiality, integrity, and availability of information, managing associated risks, and ensuring compliance with applicable requirements, promoting continuous improvement.

2. Scope

This policy applies to:

  • All information processed, stored, or transmitted by the organization, regardless of its format or location.
  • All processes, services, and assets included in the scope of the IMS.
  • All personnel, contractors, suppliers, and third parties with access to information or assets.

3. Terms and definitions

  • Information Security: preservation of the confidentiality, integrity, and availability of information, through organizational, physical, and technological controls.
  • Risk: possibility that a threat exploits a vulnerability and causes an impact on business objectives.
  • Threat: potential cause of an unwanted incident that can cause harm to an information asset.
  • Vulnerability: weakness or condition that can be exploited by a threat.
  • Control: administrative, technical, or physical measure designed to prevent, detect, correct, or reduce risk to an acceptable level.
  • Information Security Incident: confirmed event that compromises or has the potential to compromise the confidentiality, integrity, or availability of information or the assets that support it.
  • Traceability: ability to reconstruct what happened, when, how, who executed it, and what the evidence was, through formal records.
  • Confidential Information: Sensitive information whose disclosure, alteration, or loss significantly impacts the organization, clients, or compliance.
  • Cybersecurity: Practices, processes, and technological controls designed to protect information, systems, networks, and programs from attacks, damage, or unauthorized access in the digital environment.
  • Information asset: Elements that have value to the organization, including data, hardware, software, documentation, etc.
  • Business Continuity: Strategic and tactical ability of the organization to plan and respond to disruptive incidents, ensuring the operation and delivery of services at previously defined acceptable levels.

4. Applicable guidelines

4.1. Responsibilities

4.1.1. Management

  • Approves the Policy and its revisions.
  • Defines strategic guidelines and security priorities.
  • Ensures resources to implement and maintain the ISMS.
  • Defines the organization's risk appetite and is the final authority for the formal acceptance of residual risks associated with information security.

4.1.2. Personnel and Collaborators

  • Comply with the policy and associated guidelines.
  • Protect credentials and assigned assets.
  • Report security events or incidents immediately through defined channels.

4.1.3. Third Parties and Suppliers

  • Comply with confidentiality agreements and contractual security conditions.
  • Guarantee the protection of the information they have access to.

4.2. Organization's Commitment

  1. Soluciones Globales JM assumes the protection of information as a strategic principle transversal to its operations.
  2. Information security is managed under a risk-based approach, promoting the identification, evaluation, and timely treatment of threats and vulnerabilities.
  3. The organization defines and maintains the necessary controls to safeguard information, according to the Statement of Applicability (SoA) and applicable legal and contractual requirements.
  4. This Policy guides the establishment and review of Information Security Objectives, which are aligned with the organizational strategy and the Integrated Management System.
  5. The Policy is communicated and made available to relevant interested parties, and is reviewed periodically to ensure its relevance and effectiveness.

4.3. Classification, handling, and protection of information

  1. All information must be classified according to the scheme defined by the organization and handled according to its confidentiality classification.
  2. Proportional protection controls must be applied: minimum necessary access, secure storage, protected transmission, and retention according to requirements.
  3. Classified information is not allowed to be shared through unauthorized channels or without proper controls. Cryptographic controls will be applied to protect sensitive data.

4.4. Access and identity control

  1. Access is granted under the principle of least privilege and need-to-know. All access must be formally approved, recorded, traceable, and subject to periodic review and recertification.
  2. Accounts and credentials are personal and non-transferable. Third-party access is limited by scope and revoked when the need ends.

4.5. Acceptable use and protection of assets

  1. Technological and information assets are used exclusively for authorized work purposes and protected against unauthorized physical access.
  2. The unauthorized installation or use of software, devices, or services that compromise security or corporate licensing is prohibited.
  3. Information must be backed up, safeguarded, and securely deleted at the end of its life cycle, according to its criticality and operational guidelines.

4.6. Security in operations and change management

  1. Every relevant change in infrastructure, systems, or configurations in the production environment must be planned, evaluated, and formally authorized to avoid operational interruptions.
  2. Isolated backups and periodically tested recovery mechanisms must be maintained, aligned with the criticality level of the service.
  3. Monitoring, logs, and security reviews must be enabled, maintaining protected evidence for auditing and incident investigation.

4.7. Information security incident management

  1. Every incident or suspicion must be reported, recorded, analyzed, contained, and formally managed through defined channels, prioritizing the preservation of forensic evidence.
  2. No incident may be closed without a formal record, validation of secure technical restoration, and, in case of affecting Personal Data, due legal and compliance evaluation for notification to data subjects or authorities as required by Law 172-13.
  3. Lessons learned and corrective actions will be documented for critical incidents to prevent recurrence.

4.8. Supplier and third-party management

  1. Every third party that processes or accesses institutional information must be subject to confidentiality agreements (NDA) and/or contractual information security conditions.
  2. Critical suppliers and cloud services are evaluated and monitored periodically according to the quality, SLAs, and security criteria established in the IMS.
  3. Upon contract termination, the supplier must certify the secure return or destruction of the company's assets and information.

4.9. Business continuity

  1. Critical services must have continuity and recovery measures, according to the Business Impact Analysis (BIA) and risk assessments.
  2. Tests of continuity and technological recovery plans (DRP) will be carried out with the frequency established by the IMS to ensure their effectiveness in the event of disasters.

4.10. Teleworking and Mobile Devices

  1. Remote work and the use of mobile devices (corporate or BYOD) are governed by current regulations to ensure information protection.
  2. Remote access and accounts with administrator privileges will be mandatory protected with strong authentication (MFA), except for justified technical exceptions with approved compensatory controls.
  3. The organization reserves the right to revoke access and remotely wipe corporate data in case of device loss, incidents, or termination.

4.11. Security in Projects and Software Development

  1. Information security and privacy protection must be integrated from the planning and design phase of any technological project.
  2. Development, testing, and production environments will operate strictly separated to protect operational data and source code.
  3. No solution will go into production without passing the corresponding security, functionality, and acceptance tests, using anonymized test data.

4.12. Exceptions

  1. Any exception to this policy must be formally managed, ensuring the evaluation of residual risk, appropriate approval, and the implementation of compensatory controls when applicable.
  2. Exceptions will be temporary and must establish a validity or review date, in order to periodically re-evaluate if the risk level remains acceptable for the organization.

4.13. Compliance, awareness, and continuous improvement

  1. Compliance: Compliance with this policy is part of the responsibilities of all personnel, who must apply and comply with the provisions established in the Integrated Management System (IMS) documentation, according to the processes, procedures, and controls defined by the organization.
  2. Awareness and capacity building: The organization will promote awareness, education, and continuous training in information security, strengthening the competencies of personnel and their commitment to information protection and IMS compliance.
  3. Evaluation and continuous improvement: The effectiveness of the Information Security Management System (ISMS) will be evaluated periodically through audits, performance indicators, and management reviews, in order to identify opportunities for improvement and ensure continuous improvement.