{"id":5305,"date":"2026-01-21T15:14:00","date_gmt":"2026-01-21T18:14:00","guid":{"rendered":"https:\/\/www.iccbrazil.com\/?page_id=5305"},"modified":"2026-01-21T15:38:11","modified_gmt":"2026-01-21T18:38:11","slug":"politica-ti","status":"publish","type":"page","link":"https:\/\/www.iccbrazil.com\/en\/politica-ti\/","title":{"rendered":"INFORMATION AND TECHNOLOGY SECURITY POLICY \u2013 ICC BRAZIL"},"content":{"rendered":"<h3>1. OBJECTIVE<\/h3>\n<p>Establish clear and comprehensive guidelines for the appropriate use of Information Technology (IT) resources and to ensure the security, integrity, confidentiality, and availability of information in compliance with applicable legal and regulatory standards, including the Brazilian General Data Protection Law (LGPD \u2013 Law No. 13.709\/2018) and international frameworks.<\/p>\n<h3>2. SCOPE AND APPLICABILITY<\/h3>\n<p>This policy applies to all employees, interns, third parties, service providers, suppliers, and partners who use information, IT assets, or technological resources made available by the organization, regardless of geographic location.<\/p>\n<h3>3. DEFINITIONS<\/h3>\n<p>The definitions applicable to this policy are consolidated in a single glossary (see Annex I), covering terms related to the LGPD, information security, IT assets, corporate systems, the internet, data networks, and printing.<\/p>\n<h3>4. GOVERNANCE AND COMPLIANCE<\/h3>\n<p>The organization maintains an information security governance program aligned with ISO 27001 and local legislation.<\/p>\n<p>A Data Protection Officer (DPO) is responsible for ensuring compliance with the LGPD and acting as the point of contact with authorities and data subjects.<\/p>\n<p>All personal data processing operations must be mapped, assessed, and documented.<\/p>\n<h3>5. GENERAL INFORMATION SECURITY GUIDELINES<\/h3>\n<p>Information produced or held by the organization is the company\u2019s property and must be classified and protected. Access to information and resources must follow the principle of least privilege.<\/p>\n<p>The use of corporate resources may be monitored.<\/p>\n<p>Security incidents must be formally reported to the IT department.<\/p>\n<p>Limited personal use of resources is tolerated, provided it does not compromise security, performance, or the company\u2019s reputation.<\/p>\n<h3>6. ACCESS AND PASSWORD SECURITY<\/h3>\n<p>Credentials are personal and non-transferable.<\/p>\n<p>Passwords must have at least 8 characters, including uppercase, lowercase, numbers, and special characters.<\/p>\n<p>Multi-Factor Authentication (MFA) is mandatory for critical access.<\/p>\n<p>Passwords must be changed on first login and every 90 days.<\/p>\n<p>Reuse of the last 5 passwords is prohibited.<\/p>\n<p>After 3 invalid attempts, the account will be locked.<\/p>\n<h3>7. USE OF TECHNOLOGICAL RESOURCES<\/h3>\n<p>7.1 IT Assets \u2013 Company property, intended for professional use only.<\/p>\n<p>7.2 Data Network \u2013 Access is granted through authentication; personal devices are prohibited.<\/p>\n<p>7.3 Internet \u2013 Corporate resource subject to monitoring; limited personal use tolerated.<\/p>\n<p>7.4 Printing \u2013 Limited to necessity; confidential documents must be retrieved immediately.<\/p>\n<p>7.5 Corporate Systems \u2013 Access through formal request; credentials are personal and nontransferable.<\/p>\n<h3>8. PERSONAL DATA PROTECTION AND PROCESSING (LGPD)<\/h3>\n<p>This policy complies with the Brazilian General Data Protection Law (LGPD), similar in principles to the EU General Data Protection Regulation (GDPR).<\/p>\n<p>For LGPD purposes, ICC is the Data Controller, and RL Solucion acts as the Processor (third party).<\/p>\n<p>In case of a security incident, RL Solucion must notify ICC within 24 hours.<\/p>\n<p>Data processing must follow LGPD principles: purpose, adequacy, necessity, transparency, and security.<\/p>\n<p>Consent must be obtained when applicable.<\/p>\n<p>Data subjects have rights to access, correct, delete, and port their data.<\/p>\n<h3>9. ACCESS CONTROL AND ACCOUNT MANAGEMENT<\/h3>\n<p>All access requests must be formalized.<\/p>\n<p>Accounts of terminated employees must be blocked immediately.<\/p>\n<p>Access monitoring and audits will be conducted periodically.<\/p>\n<h3>10. THREAT AND INCIDENT PROTECTION<\/h3>\n<p>Systems must be updated and protected with antivirus and firewall.<\/p>\n<p>VPN use is mandatory on public networks.<\/p>\n<p>Incidents or phishing suspicions must be reported immediately.<\/p>\n<p>The company maintains an incident response and business continuity plan.<\/p>\n<h3>11. TRAINING AND AWARENESS<\/h3>\n<p>All employees must participate in periodic training on security and privacy.<\/p>\n<p>Awareness campaigns will reinforce the importance of information protection.<\/p>\n<h3>12. ROLES AND RESPONSIBILITIES<\/h3>\n<p>Users \u2013 Comply with this policy and report incidents immediately.<\/p>\n<p>Managers \u2013 Ensure compliance and control access.<\/p>\n<p>IT Department \u2013 Manage assets, networks, and systems.<\/p>\n<p>HR \u2013 Ensure awareness and inform terminations.<\/p>\n<p>DPO \u2013 Ensure LGPD compliance and act as contact point.<\/p>\n<h3>13. PENALTIES<\/h3>\n<p>Noncompliance with this policy may result in disciplinary measures, contract termination, or legal action.<\/p>\n<h3>14. REVIEW AND UPDATE<\/h3>\n<p>This policy will be reviewed annually or as needed. Exceptions will be analyzed by ICC\u2019s IT department and Executive Board.<\/p>\n<h3>15. INFORMATION CLASSIFICATION<\/h3>\n<p>Information must be classified as Public, Internal, Confidential, or Restricted, with specific controls for each level.<\/p>\n<h3>16. RISK MANAGEMENT<\/h3>\n<p>Maintain processes for risk identification, assessment, and treatment; review risks periodically.<\/p>\n<h3>17. BACKUP AND RECOVERY POLICY<\/h3>\n<p>Perform periodic backups, store copies securely, and test restoration regularly.<\/p>\n<h3>18. PHYSICAL AND ENVIRONMENTAL SECURITY<\/h3>\n<p>Control access to critical areas; ensure climate control, fire protection, and redundant power; escort visitors.<\/p>\n<h3>19. CLEAN DESK POLICY<\/h3>\n<p>Keep confidential documents locked, lock workstations when away, and never write down passwords visibly.<\/p>\n<h3>20. MOBILE DEVICES AND REMOTE ACCESS<\/h3>\n<p>Enable encryption on corporate mobile devices; VPN mandatory; report losses immediately;<\/p>\n<p>BYOD allowed only with IT authorization.<\/p>\n<h3>21. SECURE SYSTEM DEVELOPMENT<\/h3>\n<p>Follow secure coding practices; perform vulnerability testing and code review before production.<\/p>\n<h3>22. THIRD-PARTY AND SUPPLIER MANAGEMENT<\/h3>\n<p>Include confidentiality and data protection clauses in contracts; suppliers must comply with LGPD; conduct periodic assessments.<\/p>\n<p>RACI:<br \/>\nA \u2013 ICC IT<br \/>\n5R \u2013 RL Solucion<br \/>\nC \u2013 Legal\/DPO and Managers<br \/>\nI \u2013 Executive Board and Employees.<\/p>\n<h3>23. AUDIT, MONITORING, AND COMPLIANCE<\/h3>\n<p>Log all relevant activities; conduct periodic internal and external audits; evaluate compliance annually.<\/p>\n<h3>24. REVIEW AND UPDATE<\/h3>\n<p>Unaddressed cases will be analyzed by ICC\u2019s IT and Executive Board; exceptions cannot be delegated to third parties.<\/p>\n<h3>ANNEX I \u2013 GLOSSARY OF TERMS<\/h3>\n<p>Consolidation of definitions: personal data, sensitive data, data processing, consent, confidentiality, integrity, availability, authentication, credentials, user account, generic account, security incident, IT assets, information leakage, MFA, VPN, etc.<\/p>\n<p><strong>Document Control<\/strong><\/p>\n<p>Version: 1.0<br \/>\nIssue Date: October 2025<br \/>\nResponsible Area: ICC Brazil IT<br \/>\nClassification: Internal, External<br \/>\nApproval: Executive Board and Data Protection Officer (DPO) \u2013 ICC Brazil<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. OBJECTIVE Establish clear and comprehensive guidelines for the appropriate use of Information Technology (IT) resources and to ensure the security, integrity, confidentiality, and availability of information in compliance with applicable legal and regulatory standards, including the Brazilian General Data <a href=\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/\"><\/p>\n<div class=\"read-more\">\n<p>Read more &#8250;<\/p>\n<\/div>\n<p><!-- end of .read-more --><\/a><\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-5305","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>INFORMATION AND TECHNOLOGY SECURITY POLICY \u2013 ICC BRAZIL - ICC Brazil<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"INFORMATION AND TECHNOLOGY SECURITY POLICY \u2013 ICC BRAZIL - ICC Brazil\" \/>\n<meta property=\"og:description\" content=\"1. OBJECTIVE Establish clear and comprehensive guidelines for the appropriate use of Information Technology (IT) resources and to ensure the security, integrity, confidentiality, and availability of information in compliance with applicable legal and regulatory standards, including the Brazilian General Data Read more &#8250;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/\" \/>\n<meta property=\"og:site_name\" content=\"ICC Brazil\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/ICCBrazil\" \/>\n<meta property=\"article:modified_time\" content=\"2026-01-21T18:38:11+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/\",\"url\":\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/\",\"name\":\"INFORMATION AND TECHNOLOGY SECURITY POLICY \u2013 ICC BRAZIL - ICC Brazil\",\"isPartOf\":{\"@id\":\"https:\/\/www.iccbrazil.com\/en\/#website\"},\"datePublished\":\"2026-01-21T18:14:00+00:00\",\"dateModified\":\"2026-01-21T18:38:11+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[[\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/\"]]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.iccbrazil.com\/en\/politica-ti\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.iccbrazil.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"POL\u00cdTICA DE SEGURAN\u00c7A DA INFORMA\u00c7\u00c3O E TECNOLOGIA\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.iccbrazil.com\/en\/#website\",\"url\":\"https:\/\/www.iccbrazil.com\/en\/\",\"name\":\"ICC Brazil\",\"description\":\"Innovative solutions  for animal health and  nutrition market\",\"publisher\":{\"@id\":\"https:\/\/www.iccbrazil.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.iccbrazil.com\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.iccbrazil.com\/en\/#organization\",\"name\":\"ICC Brazil\",\"url\":\"https:\/\/www.iccbrazil.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.iccbrazil.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"ICC Brazil\"},\"image\":{\"@id\":\"https:\/\/www.iccbrazil.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/ICCBrazil\",\"https:\/\/www.linkedin.com\/company\/iccbrazil\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"INFORMATION AND TECHNOLOGY SECURITY POLICY \u2013 ICC BRAZIL - ICC Brazil","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.iccbrazil.com\/en\/politica-ti\/","og_locale":"en_US","og_type":"article","og_title":"INFORMATION AND TECHNOLOGY SECURITY POLICY \u2013 ICC BRAZIL - ICC Brazil","og_description":"1. OBJECTIVE Establish clear and comprehensive guidelines for the appropriate use of Information Technology (IT) resources and to ensure the security, integrity, confidentiality, and availability of information in compliance with applicable legal and regulatory standards, including the Brazilian General Data Read more &#8250;","og_url":"https:\/\/www.iccbrazil.com\/en\/politica-ti\/","og_site_name":"ICC Brazil","article_publisher":"https:\/\/www.facebook.com\/ICCBrazil","article_modified_time":"2026-01-21T18:38:11+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.iccbrazil.com\/en\/politica-ti\/","url":"https:\/\/www.iccbrazil.com\/en\/politica-ti\/","name":"INFORMATION AND TECHNOLOGY SECURITY POLICY \u2013 ICC BRAZIL - ICC Brazil","isPartOf":{"@id":"https:\/\/www.iccbrazil.com\/en\/#website"},"datePublished":"2026-01-21T18:14:00+00:00","dateModified":"2026-01-21T18:38:11+00:00","breadcrumb":{"@id":"https:\/\/www.iccbrazil.com\/en\/politica-ti\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":[["https:\/\/www.iccbrazil.com\/en\/politica-ti\/"]]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.iccbrazil.com\/en\/politica-ti\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.iccbrazil.com\/en\/"},{"@type":"ListItem","position":2,"name":"POL\u00cdTICA DE SEGURAN\u00c7A DA INFORMA\u00c7\u00c3O E TECNOLOGIA"}]},{"@type":"WebSite","@id":"https:\/\/www.iccbrazil.com\/en\/#website","url":"https:\/\/www.iccbrazil.com\/en\/","name":"ICC Brazil","description":"Innovative solutions  for animal health and  nutrition market","publisher":{"@id":"https:\/\/www.iccbrazil.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.iccbrazil.com\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.iccbrazil.com\/en\/#organization","name":"ICC Brazil","url":"https:\/\/www.iccbrazil.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.iccbrazil.com\/en\/#\/schema\/logo\/image\/","url":"","contentUrl":"","caption":"ICC Brazil"},"image":{"@id":"https:\/\/www.iccbrazil.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/ICCBrazil","https:\/\/www.linkedin.com\/company\/iccbrazil"]}]}},"_links":{"self":[{"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/pages\/5305"}],"collection":[{"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/comments?post=5305"}],"version-history":[{"count":9,"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/pages\/5305\/revisions"}],"predecessor-version":[{"id":5320,"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/pages\/5305\/revisions\/5320"}],"wp:attachment":[{"href":"https:\/\/www.iccbrazil.com\/en\/wp-json\/wp\/v2\/media?parent=5305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}