Information Security Policy
Information Security Policy
1. Objective
To establish the principles, guidelines, and responsibilities adopted by URMOBO to protect information, ensuring its confidentiality, integrity, availability, and authenticity, as well as compliance with applicable legal, regulatory, and contractual requirements.
2. Application
This Information Security Policy (ISP) applies to all IT users and to any employee or person in custody of URMOBO information or that of its clients.
3. Principles
Information security at URMOBO is guided by the following principles:
- Information is a strategic asset and belongs to URMOBO;
- Protecting information is everyone's responsibility;
- Access to information must adhere to the principle of least privilege;
- Information security depends on people, processes, and technology;
- The processing of personal data complies with applicable laws, including the General Data Protection Law (LGPD).
4. Computer Users
All employees, self-employed professionals, temporary workers, or service providers who obtain written approval from their hierarchical supervisor and the IT area's release management for the prescription of access passwords to computing resources are recognized as users of the IT infrastructure.
5. responsibilities
- Employees and third parties: comply with this policy, protect the information under your responsibility, and report incidents or suspected breaches;
- Managers: To support and ensure compliance with the Information Security Policy (PSI), authorizing access as needed for business purposes;
- Board of Directors: approve the PSI and ensure the resources and institutional support necessary for its effectiveness;
- Internal LGPD Committee: To define guidelines, analyze risks, promote awareness, and support incident management;
- Information Technology (IT): To implement, operate, and monitor technical safety controls.
6. General Safety Guidelines
URMOBO adopts, among others, the following guidelines:
- Risk management: Identification, analysis, and treatment of risks related to information security;
- Information classification: Defining confidentiality levels and applying appropriate controls throughout the entire information lifecycle;
- Access control: Granting, reviewing, and revoking access in a formal and controlled manner;
- Privacy and confidentiality: Protection of corporate information and personal data, using confidentiality clauses and technical and administrative measures;
- Operational security: Proper use of technological resources, including email, internet, devices and systems;
- Safe development: Incorporating security requirements into the processes of developing and acquiring systems;
- Incident management: The existence of a structured process for identifying, responding to, and handling security incidents;
- Business Continuity: Adopting measures to ensure business continuity and recovery in the event of adverse events;
- Safe discard: Proper disposal of documents and media containing sensitive information.
7. Awareness
URMOBO promotes awareness and training initiatives in information security, aiming to strengthen the safe and responsible behavior of all users.
8. Compliance and Auditing
Information security practices are aligned with recognized standards and best practices, such as ISO/IEC 27001 and ISO/IEC 27701, and are subject to reviews and audits to verify compliance and promote continuous improvement.
9. Sanctions
Failure to comply with this policy and related documents may result in disciplinary action, depending on the severity of the violation and applicable law.
10. Policy Review
For a higher level of maturity in this policy, reviews should be conducted every two (02) years or whenever there is a significant change in the controls it encompasses.
| REVISION | DESCRIPTION | RESPONSIBLE | DATA |
| 1.0 | Initial Version | Podium Technology | 04/2026 |