AI Assistant is here! - Make the leap to conversational eCommerce

Security Measures

The Manager, at a minimum, commits to implementing the security measures indicated below:

ORGANIZATIONAL MEASURES:

  1. An organizational structure for the management and coordination of security will be established in a documented manner. In this structure, roles and functions will be defined, as well as procedures and protocols for incident resolution and implementation of improvements.
  2. The Manager and their employees may only process and access personal data treatments authorized by the DATA CONTROLLER and necessary for the development of the functions outlined in this agreement and the provisions of the main contract, regardless of the treatment device. For this purpose, it will be necessary, by way of example and not limitation, that:
    1. Systems for raising employee awareness regarding the application of data protection regulations and basic security measures are implemented, as well as actions that allow knowledge of responsibilities in the application of the stipulated Security Regulations and Information Security procedures;
    2. The signature and commitment of employees and staff regarding the strict confidentiality necessary to comply with this agreement are guaranteed;
    3. Knowledge of protocols in case of security breaches or exercise of rights is guaranteed;
    4. Policies for the use of devices and means provided by the company for non-responsibility or function-related uses are established for employees and staff. The use of devices containing data or information affecting this agreement must be strictly professional and not personal;
    5. It is ensured that data, information systems, or resources are used only for the development of business processes defined in accordance with the provision of this service;
    6. It is guaranteed that employees do not engage in activities that may be considered illicit or illegal or that infringe the rights of the parties, their clients, or third parties;
    7. Compliance with the information access policy is guaranteed, through the observance of the password policy indicated by the company, as well as the confidentiality and safeguarding of their own passwords. User identifiers will be personal and non-transferable and will be assigned unequivocally to identifiable persons.
    8. Internal designations of data protection officers are established.
    9. A Data Protection Officer is appointed if necessary. At a minimum, they must have professional advice on data protection.

TECHNICAL MEASURES:

Management of IT supports:

  1. An inventory of supports indicating, at a minimum, the information contained in each device, as well as the authorized personnel to access them, must be available. Labeling systems will be available to make it difficult for unauthorized persons to identify the content of supports or documents.
  2. The exit of supports containing personal data (laptops, pen drives, CDs, folders, etc.) outside the premises must be authorized and controlled. There must be an entry and exit register of supports that allows, directly or indirectly, knowing the type of support, the data it contains, the date and time, the personnel transferring it, etc.
  3. Security measures for the distribution or transfer of supports outside the premises, such as encryption, some type of pseudonymization, or any other mechanism that prevents theft, loss, or improper access to information, must be available.
  4. It must be guaranteed that the process of destruction, deletion, and blocking of information (any support or temporary files) adopts measures to prevent access to the information contained in them or its subsequent recovery.
  5. Supports will be stored in a secure location with access restricted only to authorized personnel.
  6. Information must be stored encrypted on the supports.

Access control to IT equipment:

  1. An access control policy to information must be available, containing, at a minimum:
    1. Inventory of information.
    2. Departments with access to information.
    3. Permissions and privileges of departments.
  2. The removal and modification of user accounts must be done immediately, and user accounts must be periodically reviewed to eliminate obsolete ones.
  3. It must be guaranteed that the Manager’s Information Systems, where information is processed, have implemented protection systems against unauthorized access or use, alteration of operations, destruction, misuse, or theft.
  4. Individualized permissions and privileges must exist: profiles with administration rights for system installation and configuration, and users with administration privileges or rights for access to personal data.
  5. Procedures for granting, altering, or canceling authorized access to remote information resources must exist:
    1. Procedure for enabling/disabling permissions upon employee onboarding/offboarding.
    2. Procedure for modifying or revoking permissions and restrictions for users and departments.
    3. Procedure for requesting extraordinary access.
  6. An access register (user, date and time, accessed data, type of access, and whether it was authorized or denied) exists. This register is kept for at least two (2) years and reviewed at least monthly.

Identification and authentication

  1. A password policy for all employees must be established. Passwords must be secure, robust, and protocols (preferably automatic) for changing them must be established. It is recommended to change them every ninety (90) days.
  2. When different people access the same device/computer/application/program, personalized user and password must be available for each person with access to personal data.
  3. Confidentiality of passwords must be guaranteed, avoiding exposure to third parties; and, under no circumstances, passwords are communicated or left written in a common place.
  4. Repeated access with different user and password must be limited.

Backups

  1. Backups of the data of this agreement processed in their information systems must be performed daily unless the Manager indicates another frequency, which in no case will exceed weekly.
  2. The process of performing backups and data recovery must be documented.
  3. This process is reviewed at least every six months.
  4. Tests with real data are performed to verify that the backup and data restoration process is effective.
  5. An uninterrupted power supply (e.g., UPS, batteries, generators, etc.) is used to protect the power supply.
  6. Business contingency plans for critical business processes are defined and recovery strategies in case of disaster for critical services for the company can be offered.
  7. A different location from the IT equipment must be enabled to store backups.

Protection of Equipment and Transmission

  1. Media and computer files must be updated periodically.
  2. Computer systems must have antivirus and/or antimalware, firewall, antispam, and antiphishing systems implemented.
  3. Web pages and applications must be filtered to restrict access by employees, as well as download and file restrictions. The download of external files not related to business operations must be prohibited.
  4. Security patch management must be implemented to provide regular and periodic implementations of relevant security updates.
  5. The use of unauthorized software must be restricted.

Protection of Own Networks

  1. Restrictions on certain network elements must be implemented.
  2. Network activity monitoring systems must be implemented.
  3. The WiFi network has been hidden from external devices to the organization and protected with a password (WPA/WPA2/WEP encryption). This password is updated periodically.
  4. Full remote access to the corporate network and critical infrastructure must be protected by a VPN or strong authentication.
  5. The transmission of documentation must be carried out through secure channels that effectively guarantee confidentiality, integrity, and availability. In short, it must ensure that data transmission is carried out using encryption systems or any other mechanism that guarantees that the information is not intelligible or manipulated by third parties. This point will mainly apply when transmitted over: Public networks, external networks, and Wireless networks (e.g., WiFi) even if it is a network restricted to the local office environment.

Protection on External Networks

  1. The use of public or external networks should not be allowed without guaranteeing the provisions of the previous section.

Physical Access Control

  1. Buildings must be secured with access control systems. For example, specific access profiles, personalized access cards to the facilities, video surveillance, intruder alarm systems, and/or security-controlled buildings can be implemented.
  2. Servers must be stored in a secure location with access restricted only to authorized personnel.
  3. Access rights must be granted to authorized persons individually and records (name, date and time, accessed data, etc.) must be kept.
  4. Documents must be filed in folders or filing cabinets, allowing for proper document preservation, location, consultation, and exercise of rights.
  5. Documents or folders containing particularly “sensitive” data will be identified confidentially, so that the labeling used or similar mechanisms are understandable and meaningful to authorized users and incomprehensible to others.
  6. Lock cabinets, drawers with information, and doors when the office is closed.
  7. Only authorized personnel make copies (paper prints). Printers, scanners, faxes, or portable or removable devices (USBs, external hard drives, etc.) should not be placed within reach of clients, outsiders, or unauthorized personnel.
  8. While the documentation is not archived because it is under review or processing, the person in charge must guard it and prevent it from being accessed by unauthorized persons at all times.
  9. Paper documentation must be destroyed using shredders or by hiring a company for this purpose.
  10. Computer screens must be locked whenever it is necessary to temporarily leave the workstation.
  11. Establish a real clean desk policy.

Updates to Security Regulations

  1. Due to the evolution of technology and security threats, regulatory, contractual, or legal changes, the DATA CONTROLLER reserves the right to modify these Security Regulations when deemed appropriate.
  2. Periodic internal audits must be carried out to review security measures.