Information Security Policy
Statement from Management
Grupo Tecnophone recognises information as an essential asset for the delivery of its services and undertakes to protect it systematically, in proportion to the risks and in alignment with the needs of the business, its clients and other relevant interested parties.
This Policy sets out the principles, commitments and general guidelines through which Grupo Tecnophone directs and manages information security. Its purpose is to protect the confidentiality, integrity and availability of information, sustain the continuity of services and build trust among clients, employees and other interested parties.
Scope
Grupo Tecnophone develops and operates enterprise technology and communication solutions, including SMS messaging services, API integrations, OTP authentication and monitoring and management capabilities for corporate operations. The organisation also has software development, IT support, administration, infrastructure and security functions, and manages sensitive client information, operational data and internal systems.
Management Commitments
The Management of Grupo Tecnophone undertakes the following commitments as the governing framework of the Information Security Management System (ISMS):
- Protect information: preserving its confidentiality, integrity and availability in accordance with its criticality, the risks identified, business requirements and the needs of interested parties.
- Manage security risks: through a systematic process of identification, analysis, evaluation, treatment and monitoring of risks, taking into account threats, vulnerabilities, assets, processes, people and technological dependencies.
- Comply with applicable requirements: including legal, regulatory and contractual obligations and other commitments relating to information security and personal data protection. In particular, consideration shall be given to the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) in force, its applicable regulations and the requirements undertaken with clients and suppliers.
- Control access: applying need-to-know and least-privilege criteria, appropriate authentication, periodic review of permissions and segregation of duties to the extent feasible for the organisation’s structure.
- Ensure continuity and resilience: establishing backup, recovery, availability and contingency response measures commensurate with the criticality of the services and with clients’ continuity expectations.
- Manage security incidents: promoting the detection, reporting, assessment, response, recovery and learning in relation to security events and incidents, including communication to the relevant parties where appropriate.
- Embed security into technology and development: considering security requirements throughout the life cycle of systems, applications, APIs, configurations, changes and integrations, and applying protection measures commensurate with technological risks.
- Build awareness and accountability: ensuring that people understand their security responsibilities, receive relevant training and act in accordance with the policies, procedures and controls defined.
- Continually improve the ISMS: evaluating its performance, the effectiveness of controls, audit results, incidents, indicators, management reviews and changes in context, in order to maintain its suitability, adequacy and effectiveness.
Information security objectives
Information security objectives shall be defined and reviewed in a planned manner, shall be consistent with this Policy and, where applicable, shall be measurable through indicators and targets. The planning of objectives shall consider as a minimum:
- the reduction and treatment of relevant information security risks;
- the protection of information and the control of access;
- the availability, backup, recovery and continuity of critical services;
- the effective prevention and management of incidents;
- compliance with legal, regulatory and contractual requirements;
- the improvement of the performance and maturity of the ISMS.
Information Security Management System document of Grupo Tecnophone. Classification: public use.