Cybersecurity Policy
In SIGLA We are committed to protecting information assets and implementing measures to prevent, detect, and respond to cybersecurity risks. To this end, the organization establishes the following guidelines:
Access management
- Use strong passwords to access equipment, applications, and information systems.
- Do not share passwords or login credentials with other people.
- Assign access permissions according to the roles and responsibilities of each user, applying the principle of least privilege..
- Manage access through the advisor and/or Information Technology (IT) area.
Remote access and use of personal equipment
- Allow remote access to corporate resources only through secure connections and/or VPNs.
- Only authorize access from personal computers or mobile devices when authorized and when the security controls established by the organization are met..
- Avoid storing corporate information on personal devices, prioritizing the use of institutional servers.
Information protection
- Store corporate information on internal NAS-type servers managed by the organization.
- Organize information using shared folders with permissions defined according to each user’s role.
- Implement network segmentation using VLANs to limit access between areas and strengthen the security of the technological infrastructure.
Backups
- Perform regular backups of institutional information.
- Maintain RAID configurations on NAS servers to reduce the risk of data loss due to hardware failures. • Perform additional backups to external media when projects are completed or when data criticality requires it..
- Avoid relying exclusively on local storage of the equipment.
Security of the technological infrastructure
- Manage network and internet access using firewalls and content filtering policies.
- Maintain network segmentation using VLANs to reduce the risk of unauthorized access..
- Having primary and backup internet links that guarantee operational continuity.
- Protect the wireless (Wi-Fi) network using authentication mechanisms and security controls.
- Having high-performance network infrastructure and uninterruptible power supply (UPS) systems to protect equipment against power outages.
- Restrict physical access to the data center and critical equipment through authorized access controls.
Equipment upgrade and protection
- Keep operating systems and applications installed on corporate computers up to date.
- Use antivirus solutions with automatic updates for the prevention and detection of computer threats.
Using email
Users must:
- Verify the sender before opening links or attachments.
- Do not share confidential information without proper authorization.
- Use corporate email exclusively for work purposes.
Information management
All information generated, received or managed by SIGLA must:
- To be used solely for the development of the organization’s own activities.
- To remain protected against unauthorized access, modification, loss, or disclosure.
- To be treated under the principles of confidentiality, integrity and availability.
Security incident management
All authorized employees or users must immediately report any security incident or suspected security incident to the advisor and/or IT department, including:
- Loss or theft of equipment.
- Unauthorized or suspicious access.
- Presence of viruses, malware, or unusual behavior.
- Loss, alteration, or unauthorized disclosure of information.
The IT advisor and/or department will be responsible for evaluating the incident, implementing the corresponding containment, recovery and improvement actions, as well as continuously monitoring the technological infrastructure..
Compliance with this policy is mandatory for all employees, contractors, and third parties who use the technological resources of SIGLA. Failure to comply with these provisions may result in disciplinary, contractual or legal measures as appropriate, in accordance with current regulations and the organization’s internal rules.