Access Control Policy
1. Objective
El objetivo de esta política es establecer los principios y procedimientos para garantizar un acceso seguro y controlado a los sistemas de información y plataformas corporativas de la organización.
Email marketing: With your permission, we may send you emails about our store, new products, and other updates to our software.
2. Scope
The purpose of this Policy is to establish the principles and procedures necessary to ensure secure and controlled access to the organization’s information systems and corporate platforms.
3. Covered Controls
This Policy covers the following ISO/IEC 27002:2022 controls:
5.15 Access control
5.16 Identity management
5.17 Authentication information
5.18 Access rights
4. Responsibilities
- Area Manager: Responsible for requesting access to corporate platforms.
- Human Resources Department: Responsible for requesting and validating the personal information of new employees to verify their identity and background before granting access to corporate platforms.
- Information Security Team: Responsible for establishing and maintaining this Policy.
- Users: Responsible for using information systems and corporate platforms securely and in accordance with established policies and procedures.
5. Policy
Access to information systems and corporate platforms shall be based on the “need-to-know” principle and the principle of “least privilege.”
The Area Manager shall be responsible for requesting access to the TTLock platform, email, cloud services, and other corporate platforms in accordance with the established Onboarding Process.
The Human Resources Department shall be responsible for requesting and validating the personal information of new employees prior to their hiring, in order to verify their identity and background before granting them access to the platforms.
Visitor access shall be managed in accordance with the Visitor Protocol available at the following link: Visitor Protocol.
The creation of customer accounts and identities on the platforms shall be carried out in accordance with the new customer configuration procedure available at the following link: [Active][v2] Procedure for Setting Up a New Customer.
Access credentials and authentication information shall be provided by email or through the formal communication channel specified in the customer’s service agreement. Access roles and profiles shall be established to define the access privileges assigned to each user.
Technical controls, such as strong passwords and data encryption, shall be implemented to protect information systems and corporate platforms.
Periodic reviews of user access and privileges shall be conducted to ensure that they remain necessary and appropriate.
Where accounts with access rights or privileges that do not comply with this Policy are identified, corrective action shall be taken or the User Account Deletion Protocol shall be applied, as appropriate.
An audit log of user access and activities shall be maintained for security and compliance purposes.
6. Policy Effective Period
This Policy shall remain in effect for one year from the date of its most recent approval. After this period, it shall be periodically reviewed and updated to ensure that it remains aligned with the organization’s needs and with changes in applicable laws and regulations.
7. Reviews
One of the responsibilities of Gauss Control’s Information Security Committee is to reassess the organization’s information security policies. This reassessment shall be conducted at least once every two years, or whenever a significant change in technology, personnel, or any other event warrants a review, in order to ensure the policies’ continued suitability, adequacy, efficiency, and effectiveness.