{"id":3881,"date":"2026-09-30T16:03:05","date_gmt":"2026-09-30T19:03:05","guid":{"rendered":"https:\/\/engevale.com\/site\/?page_id=3881"},"modified":"2026-09-30T16:54:03","modified_gmt":"2026-09-30T19:54:03","slug":"information-security-policy","status":"publish","type":"page","link":"https:\/\/engevale.com\/site\/en\/information-security-policy\/","title":{"rendered":"Information Security Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"3881\" class=\"elementor elementor-3881\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-83fdb8f e-flex e-con-boxed e-con e-parent\" data-id=\"83fdb8f\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;gradient&quot;,&quot;shape_divider_bottom&quot;:&quot;arrow&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-shape elementor-shape-bottom\" aria-hidden=\"true\" data-negative=\"false\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 700 10\" preserveAspectRatio=\"none\">\n\t<path class=\"elementor-shape-fill\" d=\"M350,10L340,0h20L350,10z\"\/>\n<\/svg>\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d794b1c e-con-full e-flex e-con e-child\" data-id=\"d794b1c\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-461b842 elementor-widget elementor-widget-heading\" data-id=\"461b842\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Information Security Policy<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-3b751f2 e-flex e-con-boxed e-con e-parent\" data-id=\"3b751f2\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-91e8653 elementor-widget__width-initial elementor-widget-mobile__width-inherit elementor-widget elementor-widget-heading\" data-id=\"91e8653\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h5 class=\"elementor-heading-title elementor-size-default\">Information Security Policy<\/h5>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d8e4a5b elementor-widget__width-initial elementor-widget-mobile__width-inherit elementor-widget elementor-widget-heading\" data-id=\"d8e4a5b\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h5 class=\"elementor-heading-title elementor-size-default\">Based on ISO\/IEC 27001 Standards and the Brazilian General Data Protection Law (LGPD) \u2013 Law No. 13,709\/2018<\/h5>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a01282a elementor-widget elementor-widget-text-editor\" data-id=\"a01282a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h5 data-path-to-node=\"3\"><span style=\"color: #7a7a7a;\"><strong>1. Scope<\/strong><\/span><\/h5>\n<p data-path-to-node=\"4\">The Information Security Policy of Engevale Engenharia applies to all employees, service providers, third parties, systems, and processes\u2014including activities performed externally or internally\u2014that utilize the company\u2019s data processing environment or have access to proprietary information.<\/p>\n<p data-path-to-node=\"5\">All users of Engevale Engenharia&#8217;s Information Technology (IT) resources are responsible for maintaining the security, confidentiality, and integrity of corporate data and IT assets.<\/p>\n<p data-path-to-node=\"6\">Any act or omission that results in the following shall be considered a violation of this policy:<\/p>\n<p data-path-to-node=\"7,0,0\"><b data-path-to-node=\"7,0,0\" data-index-in-node=\"0\">a)<\/b> Exposing the company to actual or potential financial losses resulting from the compromise of information security, data breaches, or loss of equipment;<\/p>\n<p data-path-to-node=\"7,1,0\"><b data-path-to-node=\"7,1,0\" data-index-in-node=\"0\">b)<\/b> Involving the unauthorized disclosure, sharing, or use of confidential data, copyright-protected information, business negotiations, patents, or corporate records;<\/p>\n<p data-path-to-node=\"7,2,0\"><b data-path-to-node=\"7,2,0\" data-index-in-node=\"0\">c)<\/b> Utilizing information or systems for unlawful purposes in violation of applicable laws, statutory regulations, or governmental standards.<\/p>\n<p data-path-to-node=\"7,2,0\">\u00a0<\/p>\n<h5 data-path-to-node=\"9\"><span style=\"color: #7a7a7a;\"><strong>2. Information Security Objectives<\/strong><\/span><\/h5>\n<p data-path-to-node=\"10\">To ensure the availability, integrity, confidentiality, legality, authenticity, and auditability of the information assets required for the ongoing operations and business continuity of Engevale Engenharia.<\/p>\n<p data-path-to-node=\"10\">\u00a0<\/p>\n<h5 data-path-to-node=\"12\"><span style=\"color: #7a7a7a;\"><strong>3. IT Department Mission<\/strong><\/span><\/h5>\n<p data-path-to-node=\"13\">The IT Department is responsible for governing the information security framework, safeguarding organizational data, and coordinating, developing, and executing initiatives to ensure confidentiality, integrity, availability, legality, authenticity, and auditability.<\/p>\n<p data-path-to-node=\"13\">\u00a0<\/p>\n<h5 data-path-to-node=\"15\"><span style=\"color: #7a7a7a;\"><strong>4. General Employee Obligations<\/strong><\/span><\/h5>\n<p data-path-to-node=\"16\">All personnel must regard information as a vital business asset, handling it with the same degree of care, diligence, and professionalism applied to the company&#8217;s other critical resources.<\/p>\n<p data-path-to-node=\"19\">Department managers and supervisors are responsible for establishing classification criteria for the information generated within their respective areas, categorized as follows:<\/p>\n<p data-path-to-node=\"20,0,0\"><b data-path-to-node=\"20,0,0\" data-index-in-node=\"0\">a)<\/b> Public<\/p>\n<p data-path-to-node=\"20,1,0\"><b data-path-to-node=\"20,1,0\" data-index-in-node=\"0\">b)<\/b> Internal<\/p>\n<p data-path-to-node=\"20,2,0\"><b data-path-to-node=\"20,2,0\" data-index-in-node=\"0\">c)<\/b> Confidential<\/p>\n<p data-path-to-node=\"20,3,0\"><b data-path-to-node=\"20,3,0\" data-index-in-node=\"0\">d)<\/b> Restricted<\/p>\n<p data-path-to-node=\"20,3,0\">\u00a0<\/p>\n<h5 data-path-to-node=\"21\"><span style=\"color: #7a7a7a;\"><strong>5.1. Definitions<\/strong><\/span><\/h5>\n<p data-path-to-node=\"22,0,0\"><b data-path-to-node=\"22,0,0\" data-index-in-node=\"0\">a) Public Information:<\/b> Information accessible by any user, including clients, vendors, contractors, and the general public.<\/p>\n<p data-path-to-node=\"22,1,0\"><b data-path-to-node=\"22,1,0\" data-index-in-node=\"0\">b) Internal Information:<\/b> Exclusively intended for internal company personnel. Unauthorized disclosure may adversely impact corporate reputation.<\/p>\n<p data-path-to-node=\"22,2,0\"><b data-path-to-node=\"22,2,0\" data-index-in-node=\"0\">c) Confidential Information:<\/b> Accessible strictly to authorized employees and verified partners. Unauthorized disclosure may cause financial, operational, or reputational damage to the company or third parties.<\/p>\n<p data-path-to-node=\"22,3,0\"><b data-path-to-node=\"22,3,0\" data-index-in-node=\"0\">d) Restricted Information:<\/b> Strictly limited to expressly designated personnel. Unauthorized disclosure may cause severe operational disruption or compromise enterprise strategy.<\/p>\n<p data-path-to-node=\"22,3,0\">\u00a0<\/p>\n<h5 data-path-to-node=\"23\"><span style=\"color: #7a7a7a;\"><strong>5.2. Safeguards<\/strong><\/span><\/h5>\n<p data-path-to-node=\"24\">Managers and supervisors must direct their teams to:<\/p>\n<p data-path-to-node=\"25,0,0\"><b data-path-to-node=\"25,0,0\" data-index-in-node=\"0\">a)<\/b> Prevent the unauthorized circulation of confidential or restricted information;<\/p>\n<p data-path-to-node=\"25,1,0\"><b data-path-to-node=\"25,1,0\" data-index-in-node=\"0\">b)<\/b> Avoid leaving documents, reports, or physical media unattended in easily accessible locations;<\/p>\n<p data-path-to-node=\"25,2,0\"><b data-path-to-node=\"25,2,0\" data-index-in-node=\"0\">c)<\/b> Enforce a strict &#8220;Clean Desk Policy&#8221;, ensuring that work stations and common areas remain free of sensitive documents at the end of each work period.<\/p>\n<p data-path-to-node=\"25,2,0\">\u00a0<\/p>\n<h5 data-path-to-node=\"27\"><span style=\"color: #7a7a7a;\"><strong>6. Employee Personal Data<\/strong><\/span><\/h5>\n<p data-path-to-node=\"28\">Engevale Engenharia commits to processing and storing only personal data strictly necessary for operational execution. All personal data is classified as confidential and handled exclusively for the specific purposes for which it was collected.<\/p>\n<p data-path-to-node=\"29\">This data shall not be shared with third parties, except where required for legitimate business operations, and subject to ensuring that such third parties adhere to equivalent confidentiality and data protection standards.<\/p>\n<p data-path-to-node=\"30\">Employees are strictly prohibited from storing personal data on corporate assets without explicit Executive Authorization. Where authorized, the company assumes no liability for the security, custody, or content of such personal files.<\/p>\n<p data-path-to-node=\"30\">\u00a0<\/p>\n<h5 data-path-to-node=\"32\"><span style=\"color: #7a7a7a;\"><strong>7. Onboarding, Offboarding, and Internal Mobility<\/strong><\/span><\/h5>\n<p data-path-to-node=\"33\">The Human Resources Department must formally notify the IT Department of all employee onboarding, terminations, transfers, internships, and temporary staffing changes.<\/p>\n<p data-path-to-node=\"34\">The IT Department is responsible for:<\/p>\n<p data-path-to-node=\"35,0,0\"><b data-path-to-node=\"35,0,0\" data-index-in-node=\"0\">a)<\/b> Provisioning, modifying, or de-provisioning system access;<\/p>\n<p data-path-to-node=\"35,1,0\"><b data-path-to-node=\"35,1,0\" data-index-in-node=\"0\">b)<\/b> Generating and managing access credentials;<\/p>\n<p data-path-to-node=\"35,2,0\"><b data-path-to-node=\"35,2,0\" data-index-in-node=\"0\">c)<\/b> Aligning permissions according to assigned job functions (Role-Based Access Control).<\/p>\n<p data-path-to-node=\"36\">The hiring of any employee, intern, or temporary contractor is contingent upon express, documented agreement to this Information Security Policy.<\/p>\n<p data-path-to-node=\"36\">\u00a0<\/p>\n<h5 data-path-to-node=\"38\"><span style=\"color: #7a7a7a;\"><strong>8. Transfers and Promotions<\/strong><\/span><\/h5>\n<p data-path-to-node=\"39\">In the event of an employee transfer or promotion, HR must notify the IT Department to ensure user access permissions are formally reviewed and re-aligned with the requirements of the new role.<\/p>\n<p data-path-to-node=\"39\">\u00a0<\/p>\n<h5 data-path-to-node=\"41\"><span style=\"color: #7a7a7a;\"><strong>9. Software and Application Usage<\/strong><\/span><\/h5>\n<p data-path-to-node=\"42\">The installation and use of unlicensed software on company assets is strictly prohibited. The IT Department conducts periodic compliance audits.<\/p>\n<p data-path-to-node=\"43\">The deployment of unauthorized software may result in disciplinary action and personal liability for the user, in accordance with this policy and applicable intellectual property legislation.<\/p>\n<p data-path-to-node=\"43\">\u00a0<\/p>\n<h5 data-path-to-node=\"45\"><span style=\"color: #7a7a7a;\"><strong>10. Access Controls and Password Policy<\/strong><\/span><\/h5>\n<p data-path-to-node=\"46,0,0\"><b data-path-to-node=\"46,0,0\" data-index-in-node=\"0\">a)<\/b> Each user must maintain unique, individualized login credentials;<\/p>\n<p data-path-to-node=\"46,1,0\"><b data-path-to-node=\"46,1,0\" data-index-in-node=\"0\">b)<\/b> The temporary password issued by the IT Department must be changed upon initial logon;<\/p>\n<p data-path-to-node=\"46,2,0\"><b data-path-to-node=\"46,2,0\" data-index-in-node=\"0\">c)<\/b> Passwords must be rotated every 45 (forty-five) calendar days;<\/p>\n<p data-path-to-node=\"46,3,0\"><b data-path-to-node=\"46,3,0\" data-index-in-node=\"0\">d)<\/b> Direct supervisors are responsible for detailing and justifying the necessary access permissions required for their team members&#8217; roles to the IT Department.<\/p>\n<p data-path-to-node=\"46,3,0\">\u00a0<\/p>\n<h5 data-path-to-node=\"48\"><span style=\"color: #7a7a7a;\"><strong>11. Data Storage and File Sharing<\/strong><\/span><\/h5>\n<p data-path-to-node=\"49\">Local file sharing directly between workstations is strictly prohibited. All corporate data must be stored on centralized network servers with role-based access control enforced via Active Directory (AD).<\/p>\n<p data-path-to-node=\"50\">The IT Department performs periodic structural audits to verify compliance with centralized data storage protocols.<\/p>\n<p data-path-to-node=\"50\">\u00a0<\/p>\n<h5 data-path-to-node=\"52\"><span style=\"color: #7a7a7a;\"><strong>12. Backup and Disaster Recovery<\/strong><\/span><\/h5>\n<p data-path-to-node=\"53\">The company maintains automated daily backups of critical systems and core infrastructure servers. Backup images are securely stored in protected environments with restricted administrative access.<\/p>\n<p data-path-to-node=\"54\">On a monthly basis, the IT Department executes data restoration validation tests to ensure backup integrity and recoverability.<\/p>\n<p data-path-to-node=\"54\">\u00a0<\/p>\n<h5 data-path-to-node=\"55\"><strong><span style=\"color: #7a7a7a;\">12.1. Local Desktop Storage<\/span><\/strong><\/h5>\n<p data-path-to-node=\"56\">Local endpoint data storage is strictly discouraged. Under exceptional circumstances, the IT Department will provide specific protocols for periodic data backups. Critical operational and business data must reside exclusively on corporate servers.<\/p>\n<p data-path-to-node=\"56\">\u00a0<\/p>\n<h5 data-path-to-node=\"58\"><strong><span style=\"color: #7a7a7a;\">13. Data Security and Database Integrity<\/span><\/strong><\/h5>\n<p data-path-to-node=\"59\">The administration, maintenance, and defense of enterprise databases remain the exclusive responsibility of the IT Department, encompassing patching, structural updates, and server infrastructure maintenance.<\/p>\n<p data-path-to-node=\"59\">\u00a0<\/p>\n<h5 data-path-to-node=\"61\"><strong><span style=\"color: #7a7a7a;\">14. Intellectual Property<\/span><\/strong><\/h5>\n<p data-path-to-node=\"62\">All materials, engineering designs, technical documentation, developments, software code, and workflows created by personnel during the course of their employment are the exclusive intellectual property of Engevale Engenharia.<\/p>\n<p data-path-to-node=\"62\">\u00a0<\/p>\n<h5 data-path-to-node=\"64\"><strong><span style=\"color: #7a7a7a;\">15. Internet Access Policy<\/span><\/strong><\/h5>\n<p data-path-to-node=\"65\">Internet connectivity is provided exclusively for business purposes. Incidental personal use is restricted and subject to monitoring by the IT Department, which reserves the right to restrict access to websites incompatible with corporate activities.<\/p>\n<p data-path-to-node=\"66\">Software downloads and installations from web sources require prior explicit authorization from the IT Department.<\/p>\n<p data-path-to-node=\"66\">\u00a0<\/p>\n<h5 data-path-to-node=\"68\"><strong><span style=\"color: #7a7a7a;\">16. Corporate Email Policy<\/span><\/strong><\/h5>\n<p data-path-to-node=\"69\">Corporate email infrastructure is strictly intended for official business communication, upholding ethical standards, legal obligations, and the institutional reputation of Engevale Engenharia.<\/p>\n<p data-path-to-node=\"70\">The following practices are prohibited:<\/p>\n<p data-path-to-node=\"71,0,0\"><b data-path-to-node=\"71,0,0\" data-index-in-node=\"0\">a)<\/b> Transmitting offensive, defamatory, or unlawful communications;<\/p>\n<p data-path-to-node=\"71,1,0\"><b data-path-to-node=\"71,1,0\" data-index-in-node=\"0\">b)<\/b> Routing corporate operations through external webmail services within the company network.<\/p>\n<p data-path-to-node=\"71,1,0\">\u00a0<\/p>\n<h5 data-path-to-node=\"73\"><strong><span style=\"color: #7a7a7a;\">17. Procurement of IT Assets, Applications, and Systems<\/span><\/strong><\/h5>\n<p data-path-to-node=\"74\">The IT Department is responsible for scoping and evaluating all software, hardware, and infrastructure procurement, forwarding technical specifications directly to the Procurement Department.<\/p>\n<p data-path-to-node=\"75\">All technology acquisitions require formal prior review and technical clearance from the IT Department.<\/p>\n<p data-path-to-node=\"75\">\u00a0<\/p>\n<h5 data-path-to-node=\"77\"><strong><span style=\"color: #7a7a7a;\">18. Corporate Laptop Management<\/span><\/strong><\/h5>\n<p data-path-to-node=\"78\">Laptops provided by the company must be operated in strict compliance with corporate security protocols. The designated user is personally responsible for safeguarding the physical asset and maintaining the confidentiality of stored data.<\/p>\n<p data-path-to-node=\"79\">In the event of theft, loss, or hardware compromise, the incident must be reported immediately to the IT Department.<\/p>\n<p data-path-to-node=\"79\">\u00a0<\/p>\n<h5 data-path-to-node=\"81\"><strong><span style=\"color: #7a7a7a;\">19. Managerial and Supervisory Governance<\/span><\/strong><\/h5>\n<p data-path-to-node=\"82\">Managers and operational supervisors are tasked with authorizing, monitoring, and regularly auditing access privileges granted to their direct reports, verifying continuous alignment with operational responsibilities.<\/p>\n<p data-path-to-node=\"82\">\u00a0<\/p>\n<h5 data-path-to-node=\"84\"><strong><span style=\"color: #7a7a7a;\">20. Telecommunications Systems<\/span><\/strong><\/h5>\n<p data-path-to-node=\"85\">The utilization of corporate telephony infrastructure is subject to oversight by the IT Department, which may produce monthly utilization and expense reports disaggregated by departmental extension.<\/p>\n<p data-path-to-node=\"85\">\u00a0<\/p>\n<h5 data-path-to-node=\"87\"><strong><span style=\"color: #7a7a7a;\">21. Endpoint Protection (Antivirus)<\/span><\/strong><\/h5>\n<p data-path-to-node=\"88\">All files originating from external sources or networks must undergo automated antivirus scanning prior to ingestion. The IT Department enforces endpoint protection policies to ensure all connected devices maintain active, definitions-updated antivirus engines.<\/p>\n<p data-path-to-node=\"88\">\u00a0<\/p>\n<h5 data-path-to-node=\"90\"><strong><span style=\"color: #7a7a7a;\">22. Disciplinary Actions and Sanctions<\/span><\/strong><\/h5>\n<p data-path-to-node=\"91\">Non-compliance with this Information Security Policy may lead to disciplinary measures scaled according to infraction severity, recurrence, and operational impact, including:<\/p>\n<p data-path-to-node=\"92,0,0\"><b data-path-to-node=\"92,0,0\" data-index-in-node=\"0\">a)<\/b> Formal verbal or written warnings;<\/p>\n<p data-path-to-node=\"92,1,0\"><b data-path-to-node=\"92,1,0\" data-index-in-node=\"0\">b)<\/b> Temporary employment suspension;<\/p>\n<p data-path-to-node=\"92,2,0\"><b data-path-to-node=\"92,2,0\" data-index-in-node=\"0\">c)<\/b> Revocation or restriction of system privileges;<\/p>\n<p data-path-to-node=\"92,3,0\"><b data-path-to-node=\"92,3,0\" data-index-in-node=\"0\">d)<\/b> Civil liability proceedings and administrative actions;<\/p>\n<p data-path-to-node=\"92,4,0\"><b data-path-to-node=\"92,4,0\" data-index-in-node=\"0\">e)<\/b> Termination of employment for cause or immediate contract revocation;<\/p>\n<p data-path-to-node=\"92,5,0\"><b data-path-to-node=\"92,5,0\" data-index-in-node=\"0\">f)<\/b> Formal referral to regulatory authorities or law enforcement agencies, where legally warranted.<\/p>\n<p data-path-to-node=\"92,5,0\">\u00a0<\/p>\n<p data-path-to-node=\"93\">Sanctions are enforced following due inquiry, guaranteeing full procedural rights to defense and adversarial proceedings (<i data-path-to-node=\"93\" data-index-in-node=\"122\">contradit\u00f3rio e ampla defesa<\/i>), in compliance with Brazilian labor law, the Brazilian General Data Protection Law (LGPD, Law No. 13,709\/2018), and applicable statutory regulations.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Information Security Policy Information Security Policy Based on ISO\/IEC 27001 Standards and the Brazilian General Data Protection Law (LGPD) \u2013 Law No. 13,709\/2018 1. Scope The Information Security Policy of Engevale Engenharia applies to all employees, service providers, third parties, systems, and processes\u2014including activities performed externally or internally\u2014that utilize the company\u2019s data processing environment or [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-3881","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/pages\/3881","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/comments?post=3881"}],"version-history":[{"count":4,"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/pages\/3881\/revisions"}],"predecessor-version":[{"id":3885,"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/pages\/3881\/revisions\/3885"}],"wp:attachment":[{"href":"https:\/\/engevale.com\/site\/wp-json\/wp\/v2\/media?parent=3881"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}