Information security initiative assumptions and recommendations
I) Whereas the CLIENT uses services and/or products supplied by the CONTRACTED PARTY in its technological environment;
II) Considering the unquestionable importance of protecting and raising the level of information security and mitigating risks associated with various threats, including cyber threats;
II) Whereas the CONTRACTOR has specialized knowledge and operates in accordance with the best practices it recommends;
The Parties agree to the following information security initiatives as strong recommendations for use and implementation in the CLIENT’s technology environment, and the CLIENT undertakes to use its best efforts to comply with them in full:
a) Strong Password Policy: It is recommended that the CLIENT implement a strong password policy requiring complex passwords, updated periodically and not related to personal information. The password policy should also encourage the use of multi-factor authentication (MFA - multi-factor authentication) whenever possible and necessary. It is recommended that applications use temporary credentials instead of permanent credentials.
b) Software Updates: The
CLIENT
should keep its operating systems, applications and security software updated with the latest versions and security patches across all its technology environments and devices, including third-party environments and devices where applicable, in order to mitigate known vulnerabilities.
c) Access Control: It is recommended that the
CLIENT
implement appropriate access controls to restrict unauthorized access to systems and/or confidential information. This may include the use of two-factor authentication, assignment of the minimum privileges required and regular review of users' access rights.
d) Intrusion Monitoring and Detection: The
CUSTOMER
is advised to implement intrusion monitoring and detection systems to identify suspicious and/or unauthorized activity on its network or systems, enabling a rapid response to security incidents.
e) Traceability: It is recommended that the CLIENT implement and maintain appropriate technical and organizational measures to ensure the integrity, confidentiality, and availability of log records, with the aim of ensuring traceability of any access to or changes in internal or external identities. This includes protecting these records against loss, corruption, unauthorized access, and/or improper disclosure.
f) Information Security Awareness Training: The CLIENT is advised to provide regular information security awareness training and materials to its personnel, including its employees, representatives, partners, contractors, subcontractors, etc., in order to promote security best practices and reduce the risk of social engineering, phishing attacks and any other form of attempted information security breach.
g) Data Backups: The
CLIENT
is advised to periodically back up data considered relevant/important and regularly test the restoration of those backups, ensuring the integrity and availability of information in the event of loss, breach, and/or even corrupted data.
h) Security Incident Management: The CLIENT is advised to develop and maintain a security incident response plan that includes clear actions to be taken in the event of a security breach and/or suspected malicious activity.
i) Security Assessments: It is recommended that the
CLIENT
conduct regular security assessments in its technology environment, such as penetration tests and vulnerability analyses, in order to identify and remediate potential weaknesses in its environment.
j) Data Privacy: It is recommended that the CLIENT comply with applicable data privacy laws and implement appropriate measures to protect the personal information of its customers, employees and other stakeholders.
k) Access Revocation: It is recommended that the CLIENT implement procedures to immediately revoke access to its technological and physical environments for professionals and/or users who have left the organization or whose access rights have been revoked, in order to prevent or mitigate the risk of unauthorized access.
l) Preventive Actions: The CUSTOMER is advised to adopt Critical Security Controls or CIS Controls, which establish a prescriptive and prioritized set of recommended cybersecurity practices and defensive actions that can help prevent various types of attacks.
The Parties agree that failure to comply with information security initiatives increases the likelihood of data breaches, hacker attacks, and the consumption or misuse of technological resources, whether in the cloud or otherwise. The
CLIENT
understands and agrees that all economic and financial risks are its sole and exclusive responsibility and, therefore, the practices referred to herein, as well as any other security best practices available on the market, are strongly recommended.
At the
CLIENT’s
option, security configuration and management for its technology environment and acquired solutions to enhance protection may be provided by the
CONTRACTED PARTY, under specific scopes and quotations. Further details about the security and compliance services available from the
CONTRACTED PARTY
can be found at
www.processor.com.br/seguranca.
The primary purpose of this term is to reinforce the
CONTRACTED PARTY's
commitment to market best practices regarding information security and to promote their incorporation into our customers' day-to-day operations.