Information Security Policy

Contents

Objective

To establish information security policies for KRESTON, complying with the company’s security requirements as defined in an ISMS and MSPI which, when implemented, will mitigate risks and threats through controls for confidentiality, integrity, and availability of KRESTON’s information.

Scope

This policy will apply to

a. All firm personnel.

b. Clients and suppliers.

The policies contained in this document will be applied to strategic processes; therefore, they must be complied with by employees and suppliers who have access to any of KRESTON’s information systems, repositories, or facilities.

Definition of Terms

ISMS: Information Security Management System

CONTROL: Any activity or process aimed at mitigating or preventing a risk. Includes policies, procedures, guidelines, organizational structures, and best practices, which may be administrative, technological, physical, or legal.

RISK: An incident or situation that occurs at a specific location within a given time interval, with negative or positive consequences that may affect the achievement of objectives.

THREAT: An event that can cause a security incident in a company or organization, resulting in potential losses or damage to its assets.

VULNERABILITY: A weakness that can be exploited through the materialization of one or more threats to an asset.

ASSET: An object or resource of value used in a company or organization.

CRYPTOGRAPHY: This discipline encompasses the set of principles, methods, and means for data transformation in order to conceal information content, prevent undetected information modification, and prevent unauthorized use.

COPYRIGHT: Set of norms and principles that regulate the moral and patrimonial rights granted by law to authors for the creation of documents, literary, scientific, or artistic works, whether published or unpublished.

INTELLECTUAL PROPERTY: The recognition of a particular right in favor of an author or other rights holders over works of human intellect. This recognition applies to any property considered to be of an intellectual nature deserving protection, including technological and scientific interventions, literary or artistic productions, trademarks and identifiers, industrial designs and models, and geographical indications.

CONFIDENTIALITY: The guarantee that information is not made available or disclosed to unauthorized persons, entities, or processes.

INTEGRITY: The protection of the accuracy and completeness of assets. Information asset inventory: an ordered and documented list of information assets belonging to KRESTON.

AVAILABILITY: The guarantee that authorized users have access to information and associated assets when required.

GUIDELINE: An instruction or standard taken into account when performing a task.

It also refers to that which establishes how something will be produced. Guidelines, therefore, lay the foundations for the development of an activity or project.

ETHICAL HACKING: A set of activities to access KRESTON’s data and voice networks with the objective of achieving a high degree of penetration into systems in a controlled manner, without any malicious or criminal intent and without causing damage to systems or networks, for the purpose of demonstrating the effective level of risk to which information is exposed and proposing potential corrective actions to improve the security level.

SECURITY INCIDENT: An adverse event, confirmed or suspected, that has compromised information security or attempts to compromise it, regardless of the information affected, the technology platform, frequency, consequences, number of occurrences, or origin (internal or external).

INFORMATION ASSET: Any component (human, technological, software, documentary, or infrastructure) that supports one or more business processes of Kreston RM.

CONFIDENTIALITY AGREEMENT: A document in which ETITC public servants express their willingness to maintain the confidentiality of KRESTON’s information, committing not to disclose, use, or exploit confidential information to which they have access by virtue of the work they perform within the organization.

INFORMATION SECURITY RISK ANALYSIS: Systematic process

of identifying sources, estimating impacts and probabilities, and comparing these variables against evaluation criteria to determine the potential consequences of loss of confidentiality, integrity, and availability of information.

AUTHENTICATION: The procedure for verifying the identity of a user or technological resource when attempting to access a processing resource or information system.

CAPACITY PLANNING: The process of determining the capacity of technology platform resources that KRESTON needs to meet processing needs for such resources efficiently and with adequate performance.

DATA ENCRYPTION: The transformation of data through the use of cryptography to produce unintelligible (encrypted) data and ensure its confidentiality. Encryption is a very useful technique for preventing information leakage, unauthorized monitoring, or unauthorized access to information repositories.

INFORMATION CONFIDENTIALITY: The characteristic that information is neither made available to nor disclosed to unauthorized persons, entities, or processes; its disclosure can cause various damages to the company.

AUDIT LOGS: Files where events identified in KRESTON’s information systems, technological resources, and data networks are recorded. Such events may include, among others, user identification, events and actions executed, terminals or locations, successful and failed access attempts, configuration changes, use of utilities, and system failures.

COMMUNICATIONS NETWORKS: Information transport media that carry data from one medium to another, including dedicated facilities provided by a telecommunications service provider company (e.g., ETB, Movistar, among others).

ISMS: Information Security Management System.

INFORMATION SYSTEM: An organized set of data, operations, and transactions that interact for the storage and processing of information, which in turn requires the interaction of one or more information assets to perform its tasks. An information system is any software component, whether of internal origin—developed by KRESTON—or of external origin, whether acquired by KRESTON as a standard market product or developed for its needs.

MALICIOUS SOFTWARE: A variety of software or hostile and intrusive code programs intended to infiltrate or damage KRESTON’s technological resources, operating systems, data networks, or information systems.

THIRD PARTIES: All persons, legal or natural, such as suppliers, contractors, or consultants, who provide services or products to KRESTON.

VULNERABILITIES: Weaknesses, security gaps, or deficiencies inherent to information assets that can be exploited by external and uncontrollable factors (threats), which constitute sources of risk.

SOFTWARE LICENSE: A contract specifying all the rules and clauses governing the use of a particular software product, taking into account aspects such as: scope of use, installation, reproduction, and copying of these products.

USER PROFILES: Groups that concentrate multiple users with similar information needs and identical authorizations over technological resources or information systems, to which access is granted according to the functions performed. Modifications to a user profile affect all users covered by it.

INFORMATION OWNER: The directors and leaders of KRESTON RM.

INFORMATION CUSTODIAN(S): The leaders or directors of KRESTON RM.

Benefits

  • Reduces information security risks.

  • Reduces the probability and impact of security incidents.

  • Certification to a standard.

  • Marketing/brand advantages.

  • Consistent, structured approach.

  • Risk assessment.

  • Focuses information security spending where it produces the greatest advantage.

  • Demonstrable governance.

Costs

  • Organizational change requires organizational resources.

  • Design, development, testing, implementation.

  • Certification and follow-up visits.

  • Ongoing operation and maintenance.

Risks and Challenges

  • Overcoming fear of change: resistance from people by socializing the policy.

  • Differences in management committees.

  • Delegation of all responsibilities between companies.

  • Not assuming that information security is inherent to business processes.

  • Inadequate training and awareness plans.

  • Review schedules that cannot be met.

  • Unclear definition of scope.

  • Excessive technical measures to the detriment of training, awareness, and organizational measures.

  • Failure to communicate progress to organizational personnel.

Policies to Implement

7.1. Information Backup Policy This policy is defined for Servers, Information Systems, and End-user Equipment, also defining the appropriate frequency for each.

  • Backup of information from employee equipment on a monthly, quarterly, or semi-annual basis.

  • Backup for Servers, Databases, and Information Systems will be incremental or full according to the administrator.

7.2. File Download Policy

  • It will be permitted for work purposes; guidance will be provided on when it should be used and what its limitations are.

  • Download server ports will be blocked, as they saturate the network and cause slowdowns.

7.3. Password Policy (Creation and Use)

  • Do not use the same passwords on multiple websites or share them. Do not lend passwords to other employees.

  • Passwords must be secure and must include uppercase, special, and numeric characters.

7.4. Internet and Browsing Use Policy

  • Through filtering, access to unauthorized pages will be limited, and internet use and its purpose will be monitored.

  • Restricted access to social networks for purposes other than corporate. Guidance must be provided with recommendations for internet use.

7.5. Memory Device Use Policy

  • The use of memory devices will be restricted to the minimum possible and only for work purposes.

7.6. Information Access and Classification Policy

  • The same definition established for document management will be adopted; physical work documents must have a designated information storage location and must be classified according to public, private, confidential, or non-confidential document management standards.

  • A document management system is in place for digitized information and will be accessed after requesting access to it.

  • Access to confidential company information only to authorized persons.

7.7. Corporate Email Use Policy

  • Corporate email must not be used for personal purposes and must be managed by avoiding forwarding mass emails and regularly cleaning mailboxes.

  • Web-based email use will be exclusively for inquiries; use of the desktop application on the company-authorized device is mandatory, with all other devices prohibited for this use.

  • The copy generated at the time of the employee’s departure will be stored on the server designated by management permanently or until management deems it appropriate.

  • Upon departure, the employee must deliver to the IT department a backup of the stored email information in a .pst file; this file can only be generated from the Outlook desktop application.

7.8. Licensing Policy

  • Licensed software must be in place for each workstation, whether rented or company-owned equipment.

  • The same applies to software installed on servers.

  • This licensing must be kept current, thereby respecting copyright.

7.8.1 Microsoft Product Licensing

  • For Kreston’s auditing personnel, licensing is not provided when equipment is personal; the Auditor is responsible for the licenses on the equipment to be used for work done for Kreston RM. Licensing is only provided when equipment is rented or owned by KRESTON RM.

  • Delivery of licensing information to personnel with rented or KRESTON-owned equipment must be accompanied by a letter or delivery certificate listing the product with the serial code and the person responsible for the custody of this asset during installation. This license installation must be performed by KRESTON support personnel.

7.9. Cabling Centers and Computer Centers Policy

  • A secure location must be available to house computer equipment, and structured and secure cabling centers with access controls must be in place.

  • Structured cabling is required for company workstations.

  • A datacenter or suitable location for housing voice and data servers is required.

  • Only authorized personnel should have access to cabling centers and computer centers.

7.10. Version Management Policy

  • Software versions must be controlled in development, testing, and production environments.

  • A pre-production environment and a repository must be in place to manage versions, retaining the last two versions, thus allowing for rollback.

7.11. Workstation Policy

  • Liquid or solid food must not be kept near work equipment at workstations.

  • Physical work documents must have a designated information storage location and must be classified according to public, private, confidential, or non-confidential document management standards.

  • Signage for access points, such as evacuation routes, must be in place.

  • If personnel bring their personal laptop or if the laptop is rented or owned by KRESTON, a cable lock must be assigned.

7.12. Malicious Attacks Policy

  • Users must be warned about the prevalence of malicious programs and the dangers they pose; therefore, files or image attachments from unknown emails must not be downloaded, as they may be malicious software containing viruses, worms, Trojans, among others.

  • Awareness must be raised regarding how malware can be installed on workstations and unexpected behavior in information.

  • New and significant malware-related risks must be promptly notified via email through the intranet. This risk is present in downloading email attachments or downloading applications or installation files that may be required.

  • Antivirus protection software must be acquired.

7.13. Remote Connection Policy

  • It must be ensured that connection methods, within the intranet and from outside it, are appropriate, thereby guaranteeing optimal security levels during the execution of remote activities.

  • The Remote Connection Use Policy applies to all employees, suppliers, and interested parties who use the remote connection service to fulfill any of their functions.

  • Existing remote connection methods must be reviewed with the objective of defining which are most suitable for use on KRESTON’s LAN.

  • KRESTON, together with KRESTON’s Information Security Professional, must analyze and approve remote connection methods to KRESTON’s technology platform.

  • KRESTON must implement methods and security controls to establish remote connections to KRESTON’s technology platform.

  • KRESTON must restrict remote connections to technology platform resources; such access should only be permitted to authorized personnel and for established time periods, according to the duties performed.

  • KRESTON must verify the effectiveness of controls applied to remote connections to KRESTON’s technology platform resources on an ongoing basis.

  • All employees, suppliers, and interested parties who make remote connections to KRESTON’s LAN must have the required approvals to establish such connection to technology platform devices and must comply with the conditions of use established for such remote connections.

  • All suppliers and interested parties who make remote connections to KRESTON’s network must establish such connections on previously identified computers and, under no circumstances, on public computers, hotel computers, or internet cafés, among others.

INFORMATION SECURITY PROFESSIONAL:

  • The Information Security Professional must design, disseminate, and raise awareness about information security, with the objective of supporting the adequate protection of KRESTON’s information systems and physical areas.

  • The Information Security Professional must train employees and interested parties working for Kreston RM in the information security awareness program to prevent possible information security risks.

  • The Information Security Professional must monitor attendance at information security talks and/or events scheduled for all employees, suppliers, and interested parties working for KRESTON.

  • All employees must comply with information security policies, standards, procedures, confidentiality agreements/clauses, information security policy acceptance agreements/clauses, and attend talks and/or training sessions related to information security.

Information Asset Management Policy

  • To ensure that all KRESTON information assets have an owner and/or custodian who guarantees the preservation of confidentiality, integrity, and availability of information in each of the business group companies.

  • The Asset Management Policy will be applied by the IT and Communications area, Senior Management, as well as Asset Owners, Asset Custodians, the Information Security Professional, and employees, suppliers, and interested parties who have access to KRESTON’s physical facilities and information systems.

  • Asset Owners will be all process leaders and directors, defined and approved by KRESTON’s Senior Management. Asset Custodians will be the directors of each Kreston entity. All workstations and other technological resources are assigned to a responsible party; therefore, it is their commitment to make appropriate and efficient use of such resources.

RESPONSIBILITIES OF KRESTON AREAS, ORGANIZATIONS, AND PERSONNEL - ASSET OWNERS:

  • Asset Owners must periodically monitor the validity of users and their information access profiles.

  • Asset Owners must determine criteria and levels of information access.

  • Asset Owners must be aware that KRESTON’s information processing resources are subject to audits and compliance reviews by KRESTON’s Information Security Professional.

  • Asset Owners and/or custodians must authorize their employees, suppliers, and interested parties to use technological resources previously prepared by KRESTON employees.

  • Asset Owners must receive technological resources assigned to their employees, suppliers, and interested parties when they leave Kreston or are transferred from one company to another area.

ASSET CUSTODIANS:

  • Asset Custodians must verify that information access levels defined and approved by the owner are met.

  • Asset Custodians must verify that access to physical, magnetic, or optical information files is appropriate and approved by the information owner.

  • IT, together with the Presidency, must authorize the installation, change, or removal of components from KRESTON’s technology platform.

  • IT must establish an appropriate information access configuration for each employee, supplier, and interested party requiring access to KRESTON’s information systems and IT resources.

  • IT must prepare fixed and/or portable workstations for employees and deliver them to their owner or custodian.

  • IT must receive work equipment, fixed and/or portable, for reassignment or final disposal, and generate backup copies of information from employees who leave or change duties when formally requested.

INFORMATION SECURITY PROFESSIONAL:

  • The Information Security Professional, together with Asset Owners and/or Custodians, must ensure the identification of KRESTON information assets, thereby generating the corresponding inventory, which will be the responsibility of the IT leader.

  • The Information Security Professional must conduct a security risk analysis periodically, thereby evaluating security gaps in identified information assets.

  • The Information Security Professional must define the conditions of use and protection of information assets, both physical and digital.

  • The Information Security Professional must conduct periodic reviews of KRESTON’s technology platform resources and information systems.

EMPLOYEES:

  • Employees, suppliers, and interested parties must use KRESTON’s technological resources ethically and in compliance with current laws and regulations, in order to avoid damage or losses to operations or the company’s image.

  • Employees, suppliers, and interested parties must use KRESTON’s technological resources for the purpose of carrying out KRESTON RM’s work; therefore, they must not be used for personal purposes or purposes unrelated to it.

  • Employees, suppliers, and interested parties must not use their personal computers and mobile devices to perform work activities.

  • Employees, suppliers, and interested parties must not use unauthorized or personally owned software on KRESTON’s technology platform.

  • At the time of termination, leave, vacation, or change of duties, suppliers and interested parties must deliver their workstation to the Asset Owner or Asset Custodian; likewise, they must be cleared with the delivery of technological resources and other information assets provided at the time of their employment.

Security Policy Dissemination

KRESTON’s information security training policy and procedures must periodically disseminate the Information Security policy to have trained personnel and thus mitigate risks.

Information Systems Controls (Event Management)

  • In case of processing failure: The information system alerts the appropriate responsible party in the event of a processing failure and executes the following possible actions: shutdown, overwrites the oldest audit log, stops the generation of audit logs.

  • In case of Storage alert: The server hosting the applications must have an audit module that displays an alert when the storage volume of audit logs reaches the defined maximum capacity.

  • If the information system reaches its maximum capacity reserved for log generation, it must create a real-time alert when audit failure events occur.

  • Protection of audit information: A system must be created to protect audit information and tools against unauthorized access, modification, or deletion.

Contingency and Continuity Plan:

  • Define and Apply Contingency Plan.

  • Define and Apply Continuity Plan.

  • Audit Log Retention: KRESTON, together with the Information Security Professional, must define a retention period for audit logs to have supporting documentation for information security incident investigations, including purpose, scope, roles, and responsibilities.

  • Information System Interfaces: KRESTON must conduct an evaluation of security controls in the information system for the companies to determine whether they are adequately implemented according to system security requirements.

Continuous Improvement

These are the points and recommendations to consider in order to achieve a higher level of maturity in the process.

10.1. Baselines

  • Efforts should be made to generate PC baselines by profile to control installed software and provide rapid service when an employee joins for end-user technology.

  • Have a contingency plan containing backup copies of sensitive company information such as user authentication, data integrity, confidentiality of stored information, and access controls.

10.3. Access Management

  • From the moment an employee joins, access to Email, Network, and Information Systems must be generated according to defined profiles.
  • Define the policy for PC assignment to employees and their security at the workplace.
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.