Information Security Policy
The Management of BRIO TEAM recognizes information as a critical business asset and is committed to protecting it through the implementation, maintenance, and continual improvement of an Information Security Management System (ISMS).
The purpose of the ISMS is to establish a consistent framework for managing information security risks, protecting BRIO TEAM’s information assets, supporting the secure delivery of its services, and maintaining the trust of its customers, employees, business partners, suppliers, and other relevant stakeholders.
BRIO TEAM is committed to conducting its activities in compliance with applicable legal, regulatory, contractual, and information security requirements and in alignment with the organization’s business objectives.
Information Security Objectives
BRIO TEAM seeks to identify, assess, manage, and reduce information security risks in a systematic manner, maintaining an appropriate level of risk exposure and protecting the:
* Confidentiality of information, ensuring that it is accessible only to authorized individuals and systems.
* Integrity of information, safeguarding its accuracy, completeness, and reliability.
* Availability of information and systems, ensuring that they are accessible when required by authorized users.
The level of protection applied shall be proportionate to the sensitivity, criticality, business value, and applicable requirements of the information and systems concerned.
Scope
This policy applies to BRIO TEAM within the scope defined for its Information Security Management System and to all individuals and organizations that access, manage, process, store, transmit, or otherwise interact with BRIO TEAM information or information systems.
This includes, as applicable:
* Employees.
* Directors and officers.
* Contractors and consultants.
* Interns and temporary personnel.
* Suppliers and service providers.
* Business partners.
* Customers and authorized customer users.
* Other third parties with authorized access to BRIO TEAM information or systems.
All such parties are expected to comply with applicable information security policies, procedures, standards, contractual requirements, and controls.
Information Security Principles
BRIO TEAM’s Information Security Management System is based on the following principles:
* Minimize information security risks affecting critical business processes, services, systems, and information assets.
* Protect the confidentiality, integrity, and availability of information.
* Apply a risk-based approach to information security decision-making.
* Maintain the trust of customers, employees, business partners, and other stakeholders.
* Support technological innovation while maintaining appropriate security controls.
* Protect technological, informational, and digital assets.
* Establish, maintain, and periodically review information security policies, procedures, standards, and guidelines.
* Promote awareness, accountability, and a strong information security culture throughout the organization.
* Integrate information security requirements into business processes and technological development.
* Maintain appropriate capabilities for incident prevention, detection, response, recovery, and learning.
* Support business continuity and operational resilience.
* Comply with applicable legal, regulatory, contractual, and customer requirements.
* Continually improve the effectiveness of the Information Security Management System.
BRIO TEAM shall define, implement, operate, monitor, review, maintain, and continually improve its Information Security Management System, supported by clear policies and controls aligned with business requirements, identified risks, contractual commitments, and applicable regulatory obligations.
Information Security Responsibilities
Information security responsibilities shall be clearly defined, assigned, communicated, and understood throughout the organization.
Employees, contractors, suppliers, business partners, and other relevant third parties shall be responsible for complying with the information security requirements applicable to their roles and activities.
Access to information and systems shall be granted according to business need, the principle of least privilege, and applicable authorization procedures.
Protection of Information Assets
BRIO TEAM shall protect information that is created, received, processed, transmitted, stored, or otherwise managed through its business processes, technological infrastructure, applications, and services.
Appropriate safeguards shall be implemented to reduce the risk of unauthorized access, disclosure, alteration, destruction, loss, misuse, or unavailability of information.
Controls shall be proportionate to the classification, sensitivity, criticality, and business value of the information concerned.
BRIO TEAM shall also protect information entrusted to it by customers, employees, suppliers, business partners, and other third parties in accordance with applicable contractual, legal, regulatory, and security requirements.
Third-Party and Supplier Security
BRIO TEAM shall identify and manage information security risks associated with suppliers, service providers, contractors, customers, business partners, and other third parties with access to its information, systems, infrastructure, or services.
Appropriate security requirements shall be established based on the nature of the relationship, the information involved, the level of access granted, and the associated risks.
Where services are outsourced, BRIO TEAM shall retain appropriate oversight over the information security risks arising from such services.
Personnel Security
BRIO TEAM shall implement appropriate measures to reduce information security risks associated with personnel and other individuals with authorized access to information or systems.
Information security responsibilities shall apply throughout the relevant relationship lifecycle, including onboarding, changes in responsibilities, and termination or offboarding.
All personnel shall be expected to protect confidential information, credentials, systems, and other information assets entrusted to them.
Physical and Infrastructure Security
BRIO TEAM shall apply appropriate safeguards to the facilities, infrastructure, systems, cloud environments, devices, and technological resources supporting its operations.
Controls shall be designed to reduce the risk of unauthorized physical or logical access, damage, interference, theft, loss, or disruption.
Access Control
BRIO TEAM shall implement access controls for information, applications, systems, cloud services, and network resources.
Access shall be authorized according to legitimate business requirements and shall follow principles including:
* Need-to-know.
* Least privilege.
* Individual accountability.
* Appropriate authentication.
* Periodic access review.
* Timely modification or revocation of access when responsibilities change or access is no longer required.
Additional authentication controls may be applied according to the sensitivity and risk level of the system or information concerned.
Secure Development and Information Systems Lifecycle
Information security shall be integrated into the lifecycle of BRIO TEAM’s information systems, applications, technological services, and product development activities.
Security requirements shall be considered, as appropriate, during design, development, testing, implementation, operation, maintenance, modification, and decommissioning.
BRIO TEAM shall seek to identify and address security vulnerabilities and risks throughout the technology lifecycle.
Security Operations
BRIO TEAM shall operate its technological environments in a manner designed to preserve the confidentiality, integrity, availability, and resilience of its systems and information.
Appropriate operational controls may include, according to risk and technical requirements:
* Monitoring and logging.
* Backup and recovery.
* Vulnerability management.
* Change management.
* Configuration management.
* Access management.
* Malware and threat protection.
* Network security controls.
* Security monitoring and alerting.
Information Security Incident Management
BRIO TEAM shall maintain processes for the identification, reporting, assessment, management, containment, investigation, resolution, and review of information security incidents and events.
Security weaknesses, suspected incidents, and abnormal activities shall be reported through established channels.
Lessons learned from security events and incidents shall be used to strengthen controls and continually improve the organization’s security posture.
Where required, BRIO TEAM shall notify affected customers, authorities, or other relevant parties in accordance with applicable legal, regulatory, and contractual obligations.
Business Continuity and Operational Resilience
BRIO TEAM shall maintain appropriate measures to support the availability and resilience of its critical business processes, information systems, and services.
Information security considerations shall be incorporated into business continuity, backup, disaster recovery, and operational resilience planning.
Controls and recovery capabilities shall be defined according to the potential impact of disruptions and the criticality of the affected processes and systems.
Compliance
BRIO TEAM shall identify and comply with applicable:
* Legal requirements.
* Regulatory requirements.
* Contractual obligations.
* Customer security requirements.
* Privacy and data protection obligations.
* Intellectual property requirements.
* Information security standards and internal policies adopted by the organization.
Compliance with information security requirements shall be periodically reviewed and, where appropriate, supported by audits, assessments, monitoring, and corrective actions.
Awareness and Security Culture
BRIO TEAM shall promote an organizational culture in which information security is understood as a shared responsibility.
Employees and other relevant personnel shall receive appropriate information security awareness, guidance, and training according to their roles and responsibilities.
The organization shall seek to ensure that personnel understand relevant risks, policies, responsibilities, and expected security practices.
Continual Improvement
BRIO TEAM is committed to the continual improvement of its Information Security Management System.
The effectiveness of the ISMS shall be evaluated through appropriate mechanisms, which may include:
* Risk assessments.
* Security reviews.
* Internal and external audits.
* Security monitoring.
* Incident analysis.
* Management reviews.
* Corrective and preventive actions.
* Feedback from customers and other stakeholders.
* Changes in technology, threats, business operations, and applicable requirements.
This policy shall be reviewed periodically and whenever significant changes occur in BRIO TEAM’s business, technological environment, risk profile, regulatory context, or information security requirements.