Information Security Policy
INFORMATION SECURITY MANAGEMENT SYSTEM (ISMS)
The information being an asset that is exposed to risks and threats in a technological environment of constant change, and whose occurrence can generate a significant economic impact for In Motion and associated organizations, the implementation of an ISMS has been considered relevant to protect against information assets appropriately.
This policy is aimed at In Motion collaborators, its Suppliers, information assets of the company and its clients that are under administration or with evolutionary support applying the respective controls based on risk management and the respective information classification .
INFORMATION SECURITY POLICY
"At In Motion we are aware that Information Security is a fundamental component for meeting business objectives, being one of the pillars of the Digital Transformation Process and thus guaranteeing compliance with the principles of Reliability, Availability and Integrity."
"That is why we assume the commitment to develop, maintain and continuously improve an information security management model aligned to the needs of our clients and the current legal regulations on the protection and security of information."
The Organization chooses to implement the ISO / IEC 27001: 2013 Standard and its dissemination among its collaborators, applying the virtuous circle methodology of continuous improvement to the system.
INFORMATION SECURITY OBJECTIVES
As objectives of Information Security it is necessary to:
- Manage Risks at an acceptable level through the maintenance of an Information Security Management System (ISMS) and its respective controls.
- Comply with the security directives set forth in the ISO27001: 2013 Information Security Standard, in which In Motion and its clients are interested in having these controls.
- Implement the corresponding Controls as a result of the risk analysis carried out on the information assets and which are part of the applicability statement.
- Establish a Training and Awareness Plan in information security management that helps all the people involved to know and fulfill the defined management activities and to participate proactively in security management.