Corporate Information Security and Cybersecurity Policy
Entel Connect, in the performance of its functions and understanding the importance of properly managing information security, commits to safeguarding business information through the implementation of an Information Security Management System (ISMS) aligned with the NTP ISO/IEC 27001:2022 standard for the Peru location and NCH ISO27001:2022 for the Chile location, respectively.
Entel Connect faces various challenges and opportunities in matters of security, such as increasingly demanding regulation, customers' privacy concerns and expectations, and the protection of the critical infrastructure that supports all industries across the board.
Objective
The objective of Entel Connect's Corporate Information Security and Cybersecurity Policy is to define and regulate the principles of Information Security and Cybersecurity that govern the organization's conduct. This policy reflects Entel Connect's commitment to respecting the privacy of customers and employees, ensuring the continuity and quality of services, and complying with legislation and international standards in matters of Information Security and Cybersecurity.
Definitions
- Information security: refers to the processes and methodologies that are designed and implemented to protect information, both physical and digital, from unauthorized access, use, modification, disclosure, and destruction.
- Cybersecurity: the set of practices, technologies, and procedures intended to protect Entel Connect's information systems, networks, and data. Its objective is to prevent, detect, and respond to cyber threats and to ensure a secure and trustworthy digital environment for all operations and Assets.
- Asset: refers to any physical or digital resource of value to an organization, including, but not limited to, information systems, data, equipment, software, network infrastructure, services, and intellectual property.
- Security Controls: These are technical measures or procedures designed to protect an organization's information systems and assets against cyber threats. These controls help to prevent, detect, mitigate, and respond to malicious attacks, ensuring the confidentiality, integrity, and availability of the company's critical data and services.
- Security Incident: an unexpected and emerging event or situation that causes or may cause a limited interruption of services. These events are part of the daily operation of Entel Connect's services.
Scope
This policy is applicable to:
- Physical or digital information assets, whether owned by Entel Connect or by its customers, that are under the custody or administration of Entel Connect.
- The communication resources and fundamental services that enable the use of information assets and cyberspace resources, whether these belong to Entel Connect personnel, customers, or service-provider companies, which are required to comply with the principles and procedures that make up Entel Connect's information security policy. This is even more the case if they are part of Entel Connect's continuity plan.
Principles
The guiding security principles are the fundamental guidelines that steer the design, implementation, and management of security at Entel Connect. They act as the foundation upon which all standards, procedures, and Security Controls are built.
- Principle of accountability: the Asset Owner decides on the purpose, content, and use of the Asset, and is therefore responsible for its security. The Owner is also the owner of the risk associated with the Asset, and thus holds the ultimate responsibility and authority to manage and accept the risk.
- Principle of resilience: the ability to prevent, withstand, and recover from Cybersecurity incidents. Having the capability to continue delivering services despite facing cyberattacks.
- Principle of awareness and training: to educate and raise awareness among all members of the organization about security risks and the best practices to mitigate them.
- Principle of confidentiality: to guarantee that information and systems are accessible only to authorized persons.
- Principle of integrity: to guarantee that information can only be added, modified, or deleted by authorized persons and processes.
- Principle of availability: to guarantee that information, processes, and services are accessible and operational when needed.
- Principle of traceability: refers to the ability to trace and identify all actions carried out in a system, whether by another system or by one or more persons.
- Principle of security by design: to integrate security from the beginning of the life cycle of systems and applications, rather than adding it as a complement after their development.
- Principle of legality: to comply with all applicable laws, regulations, and rules. This entails knowing and adhering to the legal and regulatory obligations in matters of Cybersecurity and reporting any infractions of this policy of which one is aware.
- Principle of due diligence: to act with the level of care and caution necessary to prevent or mitigate the Cybersecurity risks that may affect the organization or third parties.
Policy Rules
The Policy establishes the following rules, which are considered in the various Security Standards, and which all employees must know, understand, and comply with.
- Data and information must be used responsibly, respecting laws, standards, and ethical values.
- Information must be classified by the Asset Owners, and the appropriate protection measures defined for each category must be applied.
- The corresponding authorization must be requested and obtained to access and download personal data and confidential and/or restricted information, respecting the restrictions that are established.
- Information and data must be used only for the purposes for which they were authorized and collected, in no case for other personal purposes or purposes unrelated to work.
- It must be guaranteed that digital identities are configured in such a way that no person has access to functions or activities that may generate conflicts of interest or security risks.
- The identification or digital identity to access the company's systems and resources is unique, personal, and non-transferable, and must not be shared with anyone.