{"id":23537,"date":"2026-06-03T16:21:51","date_gmt":"2026-06-03T19:21:51","guid":{"rendered":"https:\/\/progic.com.br\/politica-de-seguranca-da-informacao\/"},"modified":"2026-09-01T10:45:17","modified_gmt":"2026-09-01T13:45:17","slug":"politica-de-seguranca-da-informacao","status":"publish","type":"page","link":"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/","title":{"rendered":"Information Security Policy"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Purpose<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Progic is committed to protecting your information and personal data, ensuring confidentiality, integrity, and availability, in accordance with legal, contractual, and regulatory requirements, to guarantee business continuity and brand protection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Principles and commitments<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>Comprehensive information protection&nbsp;<\/strong>:&nbsp;Information must be protected throughout its entire lifecycle, ensuring confidentiality, integrity, and availability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>Privacy and protection of personal data<\/strong>&nbsp;: The processing of personal data must comply with legal and contractual requirements, guaranteeing the rights of data subjects and transparency in the company&#8217;s role, whether as a controller or processor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>Security and privacy by design<\/strong>&nbsp;: Information security and data protection should be incorporated from the design stage of technological solutions, systems, and infrastructures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>Control, traceability, and risk management<\/strong>&nbsp;: Access to information must be controlled, monitored, and auditable, with continuous management of threats, vulnerabilities, and incidents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>Resilience and business continuity<\/strong>&nbsp;: Information security must support service continuity and the ability to recover from adverse events.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>Shared responsibility and security culture<\/strong>&nbsp;: Information security is everyone&#8217;s responsibility, supported by awareness, continuous training, and adequate governance, including in the supply chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>Compliance and continuous improvement<\/strong>&nbsp;: Progic is committed to meeting applicable customer, legal, regulatory and normative requirements, as well as pursuing continuous improvement of the Integrated Management System.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Controls Implemented<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Contact with Authorities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Progic maintains an up-to-date list of emergency contacts and relevant authorities, available on SharePoint and physically at headquarters, for consultation and immediate action when necessary.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Contact with Special Interest Groups<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Progic establishes and maintains contact with special interest groups, specialized forums, professional associations, security communities, and relevant vendors to expand its knowledge and keep up-to-date on information related to information security. To do this, it must:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Identify the groups, forums, associations, communities, and specialized sources relevant to the context, technologies, and risks of Progic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Define who will be responsible for monitoring and maintaining the applicable contacts and registrations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Regularly monitor alerts, guidelines, best practices, threats, vulnerabilities, and relevant changes published by these sources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Evaluate the information received and, when applicable, forward it to the responsible areas for handling risks, vulnerabilities, incidents, or improvements in security controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Maintain records of established contacts and relevant information used by Progic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Share external information only with authorized individuals, respecting the company&#8217;s confidentiality, data protection, and communication requirements.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Information Assets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The implemented controls are based on the principle that it is first necessary to identify and manage the information assets (information, equipment, systems, devices, software, responsible parties, etc.) from which the other controls are contextualized. The practices involve:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Inventory the assets relevant to the operation and maintain a designated responsible party throughout their lifecycle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Allow the use of personal equipment for work, when applicable, provided it meets minimum performance, safety, and monitoring requirements and is treated as part of the information security perimeter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Acquire and use equipment, software, and other assets in accordance with approved standards, safety requirements, copyrights, and applicable licensing, prohibiting pirated or unlicensed software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Block removable portable storage media on Progic workstations and prevent the copying of corporate data to removable portable storage media on employee-owned equipment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Perform secure wiping of storage assets before reuse, donation, or disposal, ensuring that corporate or personal data cannot be recovered.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Upon termination of the employment relationship, return Progic&#8217;s assets and remove corporate access, data, and software from personal assets.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Access Control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After identifying the information assets, it is defined who can access them and under what conditions. Access control is one of the fundamental controls for protecting assets and requires:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Grant access based on the principle of least privilege, separating conflicting functions and requiring formal approval before release.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Use unique user identification, prohibit sharing of credentials, and require strong passwords, supplemented by multi-factor authentication when applicable, especially for remote access and administrative accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Apply compensating controls to legacy systems that do not fully support security requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Review access periodically according to the internal schedule, including privileged accounts and administrative access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To have administrative accounts approved by senior management and manage them in a restricted, traceable, and periodically reviewed manner.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Block or adjust access promptly upon termination, contract end, leave of absence, or vacation, except in cases of approved exceptions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Use only an approved virtual private network for external access to the product&#8217;s corporate network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Lock workstations after a period of absence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Use the corporate network, internet, and corporate email in an ethical, professional manner, consistent with the company&#8217;s objectives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Store corporate files only in approved locations, prohibiting the storage of Progic content on your own computer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To enable the monitoring of technological resources for compliance, traceability, and asset protection purposes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Cryptography and Key Management<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once access is defined, sensitive information is protected through encryption and proper key management through:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Use encryption to protect sensitive and confidential information in transit and at rest, through cryptographic mechanisms approved by the company.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Prohibit the use of unauthorized cryptographic technology.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To protect cryptographic keys against unauthorized access, improper alteration, loss, and unauthorized destruction, restricting access to them to formally designated individuals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Renew keys at the intervals defined by Progic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Obtain authorization from management for key changes that impact critical transactions and services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Prohibit credentials, passwords, application programming interface keys, or secrets directly in the source code, applying secrets management practices in the applicable documents.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Information Transfer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After defining who can access the information and how it is protected, Progic defines how it can be shared internally or externally, establishing the following rules:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Use only official tools approved by Progic for professional transfers, or \u201cAuthorized Systems\u201d. The use of personal accounts or non-approved transfer tools to send, store, or share company files and information is prohibited.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Conduct external transfers in accordance with the authorization matrix applicable to the information classification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Recurring transfers mapped in transaction records or current contracts should be considered previously authorized.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Obtain specific authorization for new recipients, new flows, or transfers not foreseen in the routine, validating personal data flows with the Data Protection Officer when applicable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Use a corporate virtual private network for technical transfers, administrative connections, or scenarios that require a secure tunnel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Request and document technical exceptions from the Information Technology department.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Backup<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With the assets identified and protected, availability and recovery controls come into play, including backups and restores. The practices should:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Maintain automatic and periodic backups for all critical assets, with a frequency defined according to criticality, data volatility, and an acceptable Recovery Point Objective for the business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Store backups in a physical location separate from production and protect them with encryption at rest, restricted access control, and measures against unauthorized alteration, such as versioning or immutability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Maintain backups for the defined retention period, consistent with Progic&#8217;s legal and operational requirements, and periodically verify their integrity and restorability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Protect backups containing personal data to the same extent that data is protected in production.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Re-execute deletions of personal data after restoration, when applicable and technically feasible, unless legally required.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Logs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Log records provide traceability, monitoring, and evidence of previous controls. They serve to detect deviations and support investigations. For this, it is necessary to:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Configure critical systems, web applications, and infrastructure services to generate logs of relevant events, including user activity, system errors, security transactions, and operations involving personal data, where applicable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Synchronize the system clocks with a single, reliable time source.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Protect records against unauthorized access, tampering, forgery, and loss.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Avoid storing sensitive data in plain text, such as passwords, financial information, or other details that could increase the risk of exposure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Define record retention according to legal, regulatory, and business requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Analyze records regularly to identify anomalies, support investigations, and demonstrate the effectiveness of controls.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerability Management<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vulnerability management implements continuous controls to improve and protect the already identified, protected, and monitored environment. Here, Progic completes the technical risk management cycle by requiring:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Follow a continuous cycle of vulnerability detection, assessment, treatment, and measurement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Classify vulnerabilities by risk level and prioritize treatment according to technical severity, impact on security, privacy, and environmental exposure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Address high or critical vulnerabilities according to a defined timeframe, and do not maintain critical vulnerabilities in production without a formal remediation plan.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Address critical vulnerabilities through emergency public exploitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Correct, monitor, or formally accept medium or low vulnerabilities according to the timeframe and cycle defined for the risk level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Test fixes in a staging environment before production.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Formalize, through the technical area manager, the justification and the palliative mitigation plan for accepting medium-level risks that cannot be corrected within the timeframe.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Obtain formal approval from the Board of Directors\/Senior Management to accept high or critical risks, assuming responsibility for the residual risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Assess security vulnerabilities in systems, integrations, and third-party partnerships.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Secure Software Development<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Secure software development incorporates information security and privacy requirements throughout the entire solution lifecycle, from conception to discontinuation. This requires:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Integrate security and privacy requirements and controls into the planning, design, implementation, testing, deployment, maintenance, and discontinuation phases of the software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Record all product changes, including features, improvements, refinements, and bug fixes, and assess their security risks during planning and prioritization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Apply privacy by default, minimizing the processing of personal data and using only the data necessary for each purpose.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Maintain segregated Development, Staging, and Production environments, preventing direct changes by developers in Production, except for formally authorized and audited emergency access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Prohibit the use of real personal data in Development and Testing environments, using synthetic or anonymized data instead; any exceptions must be formalized and approved by the Data Protection Officer, applying the same security controls as in Production.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Store source code in centralized official repositories with version control and restricted access as needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Maintain repositories of source code and critical development process artifacts covered by backup and restore routines.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Adopt secure coding practices to mitigate common vulnerabilities, including input validation, encryption of sensitive data, strong authentication where applicable, and proper error and log handling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Generate logs that support traceability, fault detection, and investigations, avoiding unnecessary personal data, and perform automatic code scanning in the continuous integration and continuous delivery pipeline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Allow the use of enterprise artificial intelligence for productivity only with mandatory human review of the code before commit, prohibiting the use of personal or free artificial intelligence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Acknowledge that all source code, documentation, and developed models are the exclusive property of Progic, prohibiting their distribution, copying, or external use without express authorization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Responsibility<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Senior Management defines and communicates the Information Security Policy, ensuring alignment with the strategy, adequate resources, and effectiveness of the Integrated Management System (IMS).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The information security and infrastructure team implements, operates, and maintains information security controls, such as system protection, access management, monitoring, vulnerability treatment, and service continuity support, following established policies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Employees and third parties must comply with the Information Security Policy, use technological resources securely, protect the information under their responsibility, and report security or privacy incidents or events immediately.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Communication and availability<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This policy is communicated internally and made available to stakeholders on the company&#8217;s official website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its review occurs periodically to ensure its continued suitability and relevance to the company&#8217;s strategy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Purpose Progic is committed to protecting your information and personal data, ensuring confidentiality, integrity, [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-23537","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Information Security Policy - Progic<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Information Security Policy - Progic\" \/>\n<meta property=\"og:description\" content=\"Purpose Progic is committed to protecting your information and personal data, ensuring confidentiality, integrity, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/\" \/>\n<meta property=\"og:site_name\" content=\"Progic\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/progic\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-01T13:45:17+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/politica-de-seguranca-da-informacao\\\/\",\"url\":\"https:\\\/\\\/progic.com.br\\\/en\\\/politica-de-seguranca-da-informacao\\\/\",\"name\":\"Information Security Policy - Progic\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/#website\"},\"datePublished\":\"2026-06-03T19:21:51+00:00\",\"dateModified\":\"2026-09-01T13:45:17+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/politica-de-seguranca-da-informacao\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/progic.com.br\\\/en\\\/politica-de-seguranca-da-informacao\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/politica-de-seguranca-da-informacao\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"In\u00edcio\",\"item\":\"https:\\\/\\\/progic.com.br\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Information Security Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/progic.com.br\\\/en\\\/\",\"name\":\"Progic\",\"description\":\"Conectamos pessoas. Simples assim.\",\"publisher\":{\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/progic.com.br\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/#organization\",\"name\":\"Progic\",\"url\":\"https:\\\/\\\/progic.com.br\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/progic.com.br\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/1-logo-progic-77x36-1.png\",\"contentUrl\":\"https:\\\/\\\/progic.com.br\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/1-logo-progic-77x36-1.png\",\"width\":77,\"height\":36,\"caption\":\"Progic\"},\"image\":{\"@id\":\"https:\\\/\\\/progic.com.br\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/progic\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/progic\\\/\",\"https:\\\/\\\/www.instagram.com\\\/progic_tv\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@progictec\",\"https:\\\/\\\/open.spotify.com\\\/show\\\/2zB5c7Np33JFtvAvtrfoad?si=4f34223d51ee4784\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Information Security Policy - Progic","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/","og_locale":"en_US","og_type":"article","og_title":"Information Security Policy - Progic","og_description":"Purpose Progic is committed to protecting your information and personal data, ensuring confidentiality, integrity, [&hellip;]","og_url":"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/","og_site_name":"Progic","article_publisher":"https:\/\/www.facebook.com\/progic","article_modified_time":"2026-09-01T13:45:17+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/","url":"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/","name":"Information Security Policy - Progic","isPartOf":{"@id":"https:\/\/progic.com.br\/en\/#website"},"datePublished":"2026-06-03T19:21:51+00:00","dateModified":"2026-09-01T13:45:17+00:00","breadcrumb":{"@id":"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/progic.com.br\/en\/politica-de-seguranca-da-informacao\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"In\u00edcio","item":"https:\/\/progic.com.br\/en\/"},{"@type":"ListItem","position":2,"name":"Information Security Policy"}]},{"@type":"WebSite","@id":"https:\/\/progic.com.br\/en\/#website","url":"https:\/\/progic.com.br\/en\/","name":"Progic","description":"Conectamos pessoas. Simples assim.","publisher":{"@id":"https:\/\/progic.com.br\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/progic.com.br\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/progic.com.br\/en\/#organization","name":"Progic","url":"https:\/\/progic.com.br\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/progic.com.br\/en\/#\/schema\/logo\/image\/","url":"https:\/\/progic.com.br\/wp-content\/uploads\/2024\/03\/1-logo-progic-77x36-1.png","contentUrl":"https:\/\/progic.com.br\/wp-content\/uploads\/2024\/03\/1-logo-progic-77x36-1.png","width":77,"height":36,"caption":"Progic"},"image":{"@id":"https:\/\/progic.com.br\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/progic","https:\/\/www.linkedin.com\/company\/progic\/","https:\/\/www.instagram.com\/progic_tv\/","https:\/\/www.youtube.com\/@progictec","https:\/\/open.spotify.com\/show\/2zB5c7Np33JFtvAvtrfoad?si=4f34223d51ee4784"]}]}},"_links":{"self":[{"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/pages\/23537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/comments?post=23537"}],"version-history":[{"count":4,"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/pages\/23537\/revisions"}],"predecessor-version":[{"id":23878,"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/pages\/23537\/revisions\/23878"}],"wp:attachment":[{"href":"https:\/\/progic.com.br\/en\/wp-json\/wp\/v2\/media?parent=23537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}