Information Security Policy

Information Security Policy
Based on ISO/IEC 27001 Standards and the Brazilian General Data Protection Law (LGPD) – Law No. 13,709/2018
1. Scope

The Information Security Policy of Engevale Engenharia applies to all employees, service providers, third parties, systems, and processes—including activities performed externally or internally—that utilize the company’s data processing environment or have access to proprietary information.

All users of Engevale Engenharia’s Information Technology (IT) resources are responsible for maintaining the security, confidentiality, and integrity of corporate data and IT assets.

Any act or omission that results in the following shall be considered a violation of this policy:

a) Exposing the company to actual or potential financial losses resulting from the compromise of information security, data breaches, or loss of equipment;

b) Involving the unauthorized disclosure, sharing, or use of confidential data, copyright-protected information, business negotiations, patents, or corporate records;

c) Utilizing information or systems for unlawful purposes in violation of applicable laws, statutory regulations, or governmental standards.

 

2. Information Security Objectives

To ensure the availability, integrity, confidentiality, legality, authenticity, and auditability of the information assets required for the ongoing operations and business continuity of Engevale Engenharia.

 

3. IT Department Mission

The IT Department is responsible for governing the information security framework, safeguarding organizational data, and coordinating, developing, and executing initiatives to ensure confidentiality, integrity, availability, legality, authenticity, and auditability.

 

4. General Employee Obligations

All personnel must regard information as a vital business asset, handling it with the same degree of care, diligence, and professionalism applied to the company’s other critical resources.

Department managers and supervisors are responsible for establishing classification criteria for the information generated within their respective areas, categorized as follows:

a) Public

b) Internal

c) Confidential

d) Restricted

 

5.1. Definitions

a) Public Information: Information accessible by any user, including clients, vendors, contractors, and the general public.

b) Internal Information: Exclusively intended for internal company personnel. Unauthorized disclosure may adversely impact corporate reputation.

c) Confidential Information: Accessible strictly to authorized employees and verified partners. Unauthorized disclosure may cause financial, operational, or reputational damage to the company or third parties.

d) Restricted Information: Strictly limited to expressly designated personnel. Unauthorized disclosure may cause severe operational disruption or compromise enterprise strategy.

 

5.2. Safeguards

Managers and supervisors must direct their teams to:

a) Prevent the unauthorized circulation of confidential or restricted information;

b) Avoid leaving documents, reports, or physical media unattended in easily accessible locations;

c) Enforce a strict “Clean Desk Policy”, ensuring that work stations and common areas remain free of sensitive documents at the end of each work period.

 

6. Employee Personal Data

Engevale Engenharia commits to processing and storing only personal data strictly necessary for operational execution. All personal data is classified as confidential and handled exclusively for the specific purposes for which it was collected.

This data shall not be shared with third parties, except where required for legitimate business operations, and subject to ensuring that such third parties adhere to equivalent confidentiality and data protection standards.

Employees are strictly prohibited from storing personal data on corporate assets without explicit Executive Authorization. Where authorized, the company assumes no liability for the security, custody, or content of such personal files.

 

7. Onboarding, Offboarding, and Internal Mobility

The Human Resources Department must formally notify the IT Department of all employee onboarding, terminations, transfers, internships, and temporary staffing changes.

The IT Department is responsible for:

a) Provisioning, modifying, or de-provisioning system access;

b) Generating and managing access credentials;

c) Aligning permissions according to assigned job functions (Role-Based Access Control).

The hiring of any employee, intern, or temporary contractor is contingent upon express, documented agreement to this Information Security Policy.

 

8. Transfers and Promotions

In the event of an employee transfer or promotion, HR must notify the IT Department to ensure user access permissions are formally reviewed and re-aligned with the requirements of the new role.

 

9. Software and Application Usage

The installation and use of unlicensed software on company assets is strictly prohibited. The IT Department conducts periodic compliance audits.

The deployment of unauthorized software may result in disciplinary action and personal liability for the user, in accordance with this policy and applicable intellectual property legislation.

 

10. Access Controls and Password Policy

a) Each user must maintain unique, individualized login credentials;

b) The temporary password issued by the IT Department must be changed upon initial logon;

c) Passwords must be rotated every 45 (forty-five) calendar days;

d) Direct supervisors are responsible for detailing and justifying the necessary access permissions required for their team members’ roles to the IT Department.

 

11. Data Storage and File Sharing

Local file sharing directly between workstations is strictly prohibited. All corporate data must be stored on centralized network servers with role-based access control enforced via Active Directory (AD).

The IT Department performs periodic structural audits to verify compliance with centralized data storage protocols.

 

12. Backup and Disaster Recovery

The company maintains automated daily backups of critical systems and core infrastructure servers. Backup images are securely stored in protected environments with restricted administrative access.

On a monthly basis, the IT Department executes data restoration validation tests to ensure backup integrity and recoverability.

 

12.1. Local Desktop Storage

Local endpoint data storage is strictly discouraged. Under exceptional circumstances, the IT Department will provide specific protocols for periodic data backups. Critical operational and business data must reside exclusively on corporate servers.

 

13. Data Security and Database Integrity

The administration, maintenance, and defense of enterprise databases remain the exclusive responsibility of the IT Department, encompassing patching, structural updates, and server infrastructure maintenance.

 

14. Intellectual Property

All materials, engineering designs, technical documentation, developments, software code, and workflows created by personnel during the course of their employment are the exclusive intellectual property of Engevale Engenharia.

 

15. Internet Access Policy

Internet connectivity is provided exclusively for business purposes. Incidental personal use is restricted and subject to monitoring by the IT Department, which reserves the right to restrict access to websites incompatible with corporate activities.

Software downloads and installations from web sources require prior explicit authorization from the IT Department.

 

16. Corporate Email Policy

Corporate email infrastructure is strictly intended for official business communication, upholding ethical standards, legal obligations, and the institutional reputation of Engevale Engenharia.

The following practices are prohibited:

a) Transmitting offensive, defamatory, or unlawful communications;

b) Routing corporate operations through external webmail services within the company network.

 

17. Procurement of IT Assets, Applications, and Systems

The IT Department is responsible for scoping and evaluating all software, hardware, and infrastructure procurement, forwarding technical specifications directly to the Procurement Department.

All technology acquisitions require formal prior review and technical clearance from the IT Department.

 

18. Corporate Laptop Management

Laptops provided by the company must be operated in strict compliance with corporate security protocols. The designated user is personally responsible for safeguarding the physical asset and maintaining the confidentiality of stored data.

In the event of theft, loss, or hardware compromise, the incident must be reported immediately to the IT Department.

 

19. Managerial and Supervisory Governance

Managers and operational supervisors are tasked with authorizing, monitoring, and regularly auditing access privileges granted to their direct reports, verifying continuous alignment with operational responsibilities.

 

20. Telecommunications Systems

The utilization of corporate telephony infrastructure is subject to oversight by the IT Department, which may produce monthly utilization and expense reports disaggregated by departmental extension.

 

21. Endpoint Protection (Antivirus)

All files originating from external sources or networks must undergo automated antivirus scanning prior to ingestion. The IT Department enforces endpoint protection policies to ensure all connected devices maintain active, definitions-updated antivirus engines.

 

22. Disciplinary Actions and Sanctions

Non-compliance with this Information Security Policy may lead to disciplinary measures scaled according to infraction severity, recurrence, and operational impact, including:

a) Formal verbal or written warnings;

b) Temporary employment suspension;

c) Revocation or restriction of system privileges;

d) Civil liability proceedings and administrative actions;

e) Termination of employment for cause or immediate contract revocation;

f) Formal referral to regulatory authorities or law enforcement agencies, where legally warranted.

 

Sanctions are enforced following due inquiry, guaranteeing full procedural rights to defense and adversarial proceedings (contraditório e ampla defesa), in compliance with Brazilian labor law, the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018), and applicable statutory regulations.