Cybersecurity Policy
Gauss Control considers information and associated systems to be critical assets that must be protected to ensure the proper functioning of the company. The Cybersecurity Policy is intended to effectively manage the security of information processed by information systems, as well as the assets involved in those processes.
This Policy aims to ensure the confidentiality, integrity, availability, and privacy of information and to comply with applicable laws and regulations at all times, while maintaining a balance between risk levels and the efficient use of resources, based on proportionality criteria. This Cybersecurity Policy applies to all employees, executives, and directors of all companies that form part of the organization, including investee companies over which it exercises effective control, within the limits established by applicable regulations. To this end, we establish the following principles:
- Ensure that Gauss Control’s Information and Telecommunications Systems maintain an appropriate level of cybersecurity and resilience.Garantiza que los Sistemas de Información y Telecomunicaciones de que dispone Gauss Control, posean el adecuado nivel de ciberseguridad y resiliencia.
- Raise awareness among all employees, contractors, and collaborators regarding cybersecurity risks and ensure that they have the knowledge, skills, experience, and technological capabilities required to support the Group’s cybersecurity objectives.
- Potencia las capacidades de prevención, detección, reacción, análisis, recuperación, respuesta, investigación y coordinación frente a las nuevas amenazas.
Promote the implementation of appropriate cybersecurity and resilience mechanisms for systems and operations managed by third parties providing services to Gauss Control. - Establish procedures and tools that enable the organization to adapt quickly to changing technological conditions and emerging threats.
- Collaborate with relevant government agencies and authorities to improve the company’s cybersecurity, ensure compliance with applicable legislation, and contribute to improving cybersecurity at the international level.
The following controls are proposed for implementation across different stages and areas of the company:
1. Prevention
1.1 Access Management
- Establish role-based access control policies.
- Implement multi-factor authentication for users with access to the platform.
- Establish procedures for reviewing and revoking access privileges according to job responsibilities.
1.2 Protection Against Brute-Force Attacks
- Limit the number of login attempts.
- Implement automatic blocking measures in case of failed attempts.
- Monitor and record unauthorized access attempts.
1.3. Network Security
- Use firewalls to control network traffic.
- Encrypt communication between users and the platform.
- Establish trusted zones and access restrictions based on IP addresses.
1.4. Updates and Patches
- Keep all systems and applications up to date.
- Perform vulnerability testing after each update.
- Establish a process for applying critical security patches urgently.
1.5. Personal Device Usage Policy
- Require antivirus, data encryption, and screen lock on personal devices.
- Ban jailbreaking/rooting on mobile devices.
- Definir requisitos para acceder a información corporativa.
1.6. Define requirements for accessing corporate information.
- Establish classification levels according to the criticality of the information.
- Define guidelines for the proper handling and storage of information.
1.7. Physical and Environmental Security
- Implement physical access controls for critical areas.
- Consider environmental threats and implement business continuity plans.
2. Detection
Detection focuses on implementing mechanisms to identify malicious activities and anomalies across systems and networks. Some of the tools used include Intrusion Detection Systems (IDS), log analysis, network traffic monitoring, vulnerability scanning, among others. This makes it possible to identify early indicators of compromise.
2.1. Continuous Monitoring
- Implement real-time security monitoring tools.
- Configure alerts to detect unusual traffic patterns.
- Perform regular log analysis to identify potential threats.
2.2. Behavioral Analysis
- Use behavioral analysis solutions to detect anomalous activities.
- Establish behavioral thresholds and alerts for potential deviations.
2.3. Security Scans and Audits
- Perform periodic security scans on the platform.
- Conduct security audits to identify potential vulnerabilities.
- Schedule security assessments after significant changes.
3. Resolution
3.1. Incident Response Plan
- Develop and maintain a detailed incident response plan.
- Define roles and responsibilities in the event of a threat to availability.
- Conduct regular drills to ensure the effectiveness of the plan.
3.2. Disaster Recovery
- Establish backup and recovery procedures to minimize downtime.
- Store backups in secure and accessible locations.
3.3. Collaboration with Authorities and External Experts
- Collaborate with the relevant authorities in the event of a serious incident.
- Maintain contact with external cybersecurity experts.
3.4. Continuous Improvement
- Regularly assess and review the effectiveness of security measures.
- Update the policy and procedures based on lessons learned.
3.5. Training and Awareness
- Implement regular campaigns to educate personnel on security policies and best practices.
- Conduct phishing simulations and training sessions.
3.6. Vulnerability Management
- Establish processes to continuously identify, prioritize, and remediate vulnerabilities.
- Conduct periodic security assessments and ethical hacking exercises.
3.7. Supply Chain Security
- Define security requirements for suppliers and partners.
- Assess third-party risks and conduct regular audits.
3.8. Incident Communication Plan
- Define channels and responsible parties for reporting incidents internally.
- Establish criteria for escalating and communicating serious incidents.