This policy manual applies to employees, contractors, third parties, users and visitors of ATOM CHAT S.A.S. who for any reason have any kind of interaction with information assets, databases or digital infrastructure, or who relate in any way to our digital platforms.
1. PURPOSE:
To establish guidelines relating to information security addressing specific topics, as a complement to what has been defined by the Company's information security team, in order to preserve the confidentiality, integrity and availability of the assets of ATOM CHAT S.A.S. (hereinafter the Company, which includes all of its subsidiaries and/or parent company).
2. DEFINITIONS:
For the correct interpretation of this Manual, the following definitions must be taken into account:
- Information Asset: refers to any information or element related to its processing (systems, documents, media, people) that has value for the Company.
- Confidentiality: property of information that makes it unavailable or not disclosed to unauthorized individuals, entities or processes.
- Integrity: property of information that seeks to preserve its accuracy and completeness.
- Availability: property of information of being accessible and usable on demand by an interested party.
- Restricted circulation: refers to the processing of information that allows it to circulate (pass from one place to another) in a controlled manner without the information becoming a freely accessible and consultable file.
- Controls: a measure that makes it possible to reduce or mitigate a risk.
3. BASIC GUIDELINES:
The Company hereby establishes the following basic information security guidelines, which must be complied with by all employees, contractors, third parties, users and visitors. The security guidelines are classified into different topics, taking into account the Company's internal and external context:
A. HR (recruitment and management):
- During the personnel selection process, criminal background checks will be carried out on candidates regardless of the role or position they are applying for.
- All personnel working at the Company must sign a confidentiality agreement and a document acknowledging and accepting the policies defined for information security and the proper use of information assets.
- All personnel working at the Company or providing any type of service that may bring them into contact with information assets will receive a training session on the legislation applicable to the processing of personal data and to cybersecurity. The human resources department will be responsible for indicating in the job description for each role which individuals will come into contact with third-party personal information, so that those individuals receive additional training.
- The Company will maintain a clean desk policy. In the Company's digital and working environment this means that every computer or digital device must be password-protected, files must all be stored and classified, databases will have restricted access, and copying information will not be permitted without relevant justification. The HR team is responsible for training in this regard.
- Whenever employees leave the Company, an inventory must be taken of the information stored on their devices, the number of copies of information, and the integrity of the devices.
B. ACCESS CONTROL:
- For the protection of information assets, procedures and policies will be established for controlling access to the network, information systems and physical infrastructure (premises where applicable), in order to mitigate the risks associated with unauthorized access to information.
- All users must take responsibility for the physical or digital information they access and process, using it appropriately in order to safeguard the confidentiality, integrity and availability of the information.
- To that end, all access to the Company's information systems must use a secure, confidential password meeting the appropriate security standards set by the Company.
- The Company will implement encryption tools in order to protect the confidentiality and integrity of information whenever it deems this necessary. It will likewise determine which devices must have additional cryptographic controls installed where required.
C. SECURITY FOR THE USE OF DEVICES:
- In order to secure the operations carried out on the technology resources that support the Company's business operation, the Company plans, manages, backs up and monitors its technology infrastructure in order to detect unusual or suspicious activity.
- Preventive maintenance must be carried out on all equipment, software and systems at least once a year.
- Information Assets must not circulate without control by the Company. A record must be kept of each database, where it is located, who has access to it, its purpose and its retention period.
- Every website visited must have a secure SSL authentication certificate — Secure Sockets Layer — (https://) to verify that information is communicated securely.
- Information belonging to the Company or its customers may not be published or circulated, even where it is not labeled as confidential. Its disclosure must be authorized by the line manager.
- The use of personal computers to carry out Company activities is not permitted.
- The use of Company devices by third parties outside the Company is not permitted.
- Downloading programs, photos, music, videos and any other format of information, known or as yet unknown, that is unrelated to the Company onto Company devices and systems is prohibited.
- Using a co-worker's access credentials.
D. SELECTION OF SUPPLIERS:
- The Company, through its procurement and technology team, will ensure that the information systems implemented at the Company comply with the security requirements and good practices established by the Superintendencia de Industria y Comercio (Colombia's industry and commerce regulator) in everything relating to the processing of personal data; it will likewise establish a standard in line with the industry, imminent risks and the recommendations provided by commercial partners.
- All Company teams must inform the procurement and technology area of their plans to acquire information systems or software, so that the relevant observations can be provided and the technical aspects necessary for their development and implementation can be reviewed.
- Before beginning the performance of contracts that involve access to the Company's technology infrastructure, the corresponding confidentiality agreements must be signed, including information security protocols for the contractual and post-contractual stages.
E. MINIMUM EXPECTED CONDUCT ON THE INTERNET:
The internet is a valuable and necessary resource for carrying out the Company's corporate purpose; the following guidelines are therefore defined for its appropriate use, constituting a minimum standard of conduct:
- While people are using the Company's electronic devices and have its information systems open, use of the internet is limited to carrying out the tasks assigned to them.
- Access will be restricted to sites covering: games, pornography, psychoactive substances, terrorism, racial segregation, hacking, malware, free or illegal software and/or any other page that contravenes the laws in force in Colombia, as well as cloud and mass file-sharing portals (with the exception of the corporate cloud).
- The Company may review browsing logs or records where this is requested or required for any investigations or requirements that may arise.
F. USE OF EMAIL:
- The mailboxes assigned to the Company's staff belong to the Company; therefore, their content is also the property of the Company.
- Email must be used only for corporate purposes and for performing the duties corresponding to each role.
- The Company may review the content of corporate email mailboxes and telephones, tablets, or any other device in cases where it is necessary to access information in order to continue providing the service or for specific investigations.
- Falling for phishing or similar practices must be avoided at all costs. To that end, all staff must bear in mind that if they do not recognize the sender of an email, or the domain does not match the company or service it claims to be from, if the subject line contains an alarmist statement, if the wording is odd or has poor spelling, if it lacks personalized details, or if it requests personal data or the download of or access to a link, they must refrain from viewing that content any further and must contact the information security team.
G. CONTRACTS
Contracts with customers must contain:
- A clear statement of the existence of any transfer or transmission of information, so that the Company can verify its responsibility.
- Efficient means of communication.
- The Controls to be used for information transfer or transmission activities and the Availability that will apply to the shared information.
- The scope of the processing of personal data, that is, with respect to their collection, use, storage, circulation and/or erasure.
- The activities the Company will carry out on the customer's behalf.
4. RESEARCH AND LEGISLATIVE MONITORING GROUP:
The HR team will appoint a research and legislative monitoring working group, which will define a plan for ongoing training and updates, planning ANNUALLY how information security recommendations or tips will be communicated through different channels to all co-workers, in order to socialize corporate information security policies or the good security practices that are to be shared in order to increase the capabilities of all of the Company's areas and processes.
This working group will ensure compliance with the legislation in force regarding the requirements established for information security and privacy, intellectual property rights and personal data protection.
Likewise, this working group will be required to closely follow any change in the privacy policies of the commercial partners involved in the provision of the Company's services, in order to verify that these are consistent with the jurisdiction where their customers are located.
5. SECURITY INCIDENTS:
All staff must report any incident, vulnerability or potential risk to Information Assets without exception.
Any staff member who becomes aware of the incident must cooperate with the person in charge of the investigation, and it must be verified whether that incident is capable of affecting or in any way concerning a supplier and/or customer.
Those involved in the investigation must verify whether the incident must be reported to the authorities. In all cases, notice will be given to the supplier or customer whom the incident may concern or affect in any way, even where the harm has not materialized and has only been potential. Corporate service agreements must always establish fast and effective channels of communication for such cases.
The Company must have a security incident protocol. The security incident protocol will be based on the following:
- Containment of the incident and protection of assets. All routes for protecting and sealing off the technology infrastructure must be activated.
- The risks and impacts associated with the security incident will be assessed.
- The harm that may have been caused to data subjects and interested third parties (customers and suppliers) must be identified.
- The authorities will be notified where necessary in accordance with the legislation.
- The occurrence of the event will be communicated to the data subjects, together with the other parties involved. This step is essential, as it allows those directly affected to take useful measures against the consequences of a security incident.
- An improvement plan will be drawn up.
After the investigation of the security incident, the following questions will need to be answered:
Which protocols or measures did not have the expected effect?
Which assets were vulnerable?
What actions could have been taken? Why were they not taken?
What risks were the data subjects exposed to? Examples of risks include: risk to the personal integrity of individuals, financial extortion, identity theft, profiling for unlawful purposes, loss of opportunities, discrimination, humiliation, and reputational damage.
6. CONTINUOUS UPDATING:
The policies defined here will take effect upon their approval by the Company's General Manager and will be reviewed at least annually in order to ensure they remain current.
7. BINDING NATURE AND IGNORANCE OF THE POLICY:
Failure to comply with this policy is a serious breach of the duties of all staff and may lead to termination of the contractual relationship, in addition to criminal complaint before the corresponding authorities where it constitutes an offense. In this regard:
Colombian Criminal Code — Article 269F. Violation of personal data
Whoever, without being authorized to do so, for their own benefit or that of a third party, obtains, compiles, extracts, offers, sells, exchanges, sends, buys, intercepts, discloses, modifies or uses personal codes or personal data contained in files, records, databases or similar media, shall incur a prison sentence of forty-eight (48) to ninety-six (96) months and a fine of 100 to 1,000 current monthly legal minimum wages (the Colombian statutory unit for fines).
ATOM CHAT
Last updated 02/04/2023