{"id":639,"date":"2025-01-22T17:00:15","date_gmt":"2025-01-22T17:00:15","guid":{"rendered":"http:\/\/10.11.153.111:8082\/?page_id=639"},"modified":"2025-01-22T17:01:13","modified_gmt":"2025-01-22T17:01:13","slug":"politica-de-seguranca-da-informacao","status":"publish","type":"page","link":"https:\/\/care-business.com\/en\/politica-de-seguranca-da-informacao\/","title":{"rendered":"Information Security Policy"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"639\" class=\"elementor elementor-639\" data-elementor-settings=\"{&quot;ha_cmc_init_switcher&quot;:&quot;no&quot;}\" data-elementor-post-type=\"page\">\n\t\t\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-6044769 e-con-full e-flex e-con e-parent\" data-id=\"6044769\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-0589031 e-flex e-con-boxed e-con e-child\" data-id=\"0589031\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-82bef4d e-con-full e-flex e-con e-child\" data-id=\"82bef4d\" data-element_type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-07230b7 e-con-full e-flex e-con e-child\" data-id=\"07230b7\" data-element_type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-eba2e2f e-con-full e-flex e-con e-child\" data-id=\"eba2e2f\" data-element_type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f7da1c6 elementor-widget elementor-widget-heading\" data-id=\"f7da1c6\" data-element_type=\"widget\" data-settings=\"{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Information Security and Privacy Policy<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-ac8151e e-con-full e-flex e-con e-child\" data-id=\"ac8151e\" data-element_type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-9b28409 e-flex e-con-boxed e-con e-parent\" data-id=\"9b28409\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-8cceda5 e-con-full e-flex e-con e-child\" data-id=\"8cceda5\" data-element_type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-60f8355 e-con-full e-flex e-con e-child\" data-id=\"60f8355\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56bcbd2 elementor-widget elementor-widget-text-editor\" data-id=\"56bcbd2\" data-element_type=\"widget\" data-settings=\"{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>INFORMATION SECURITY AND PRIVACY POLICY<\/p><p>1. OBJECTIVE<br \/>CARE establishes its Information Security and Privacy Policy as an integral part of its<br \/>corporate management system, aligned with good market practices and international standards<br \/>accepted and the relevant Brazilian legislation, with the aim of guaranteeing adequate levels of protection to<br \/>information and personal data operated by the organization, its customers and employees under its control<br \/>responsibility.<\/p><p>2. PURPOSE<\/p><p>\u2022 This policy aims to:<br \/>\u2022 Establish Information Security and Privacy guidelines and standards that allow<br \/>CARE employees adopt safe behavior standards;<br \/>\u2022 Provide guidance on the adoption of controls and processes to meet Security requirements<br \/>Information and Privacy of Personal Data;<br \/>\u2022 Safeguard CARE information, ensuring basic confidentiality requirements,<br \/>integrity and availability;<br \/>\u2022 Prevent possible incidents and legal liability involving the institution, employees,<br \/>customers, suppliers and partners;<br \/>\u2022 Minimize the risks of financial losses, market losses, customer confidence losses or other impacts<br \/>negative impact on CARE&#039;s business as a result of security breaches.<\/p><p>3. POLICY<br \/>This policy applies to all CARE employees, suppliers and partners who have access<br \/>to CARE&#039;s personal information and data and\/or make use of computing resources included in the<br \/>internal infrastructure.<\/p><p>3.1. It is CARE&#039;s Policy:<br \/>\u2022 Develop, implement and fully follow security policies, standards and procedures<br \/>of information, ensuring that the basic requirements of confidentiality, integrity and<br \/>availability of information and personal data operated at CARE are achieved through<br \/>the adoption of controls against threats from both external and internal sources<br \/>internal;<br \/>\u2022 Make security policies, standards and procedures available to all interested parties<br \/>and authorized parties, such as: Employees, contracted third parties, suppliers and, where<br \/>relevant, customers.<br \/>\u2022 Ensure education and awareness about information security practices and<br \/>data privacy adopted by CARE for Employees, contracted third parties,<br \/>suppliers and, where relevant, customers.<br \/>\u2022 Fully meet information security and data privacy requirements<br \/>applicable personal data or required by regulations, laws and\/or contractual clauses;<\/p><p>\u2022 Fully handle information security incidents and data privacy<br \/>personal data, ensuring that they are properly recorded, classified, investigated,<br \/>corrected, documented and, where necessary, communicating to the appropriate authorities;<br \/>\u2022 Ensure business continuity through adoption, deployment, testing and improvement<br \/>continuous continuity and disaster recovery plans;<br \/>\u2022 Continuously improve Information Security and Privacy Management through<br \/>definition and systematic review of security objectives at all levels of the organization.<\/p><p>4. ROLES AND RESPONSIBILITIES<br \/>4.1. Information Security Steering Committee \u2013 CGSI<br \/>The Information Security Management Committee \u2013 CGSI is hereby established, with the participation of,<br \/>at least one Technology Director, one Information Technology Manager and at least two<br \/>members with knowledge in information technology, both with infrastructure support and<br \/>with systems.<br \/>4.2. It is the responsibility of the CGSI:<br \/>\u2022 Analyze, review and propose the approval of security-related policies and standards<br \/>of information;<br \/>\u2022 Ensure the availability of the resources necessary for effective Management of<br \/>Information Security;<br \/>\u2022 Ensure that information security and data privacy activities are<br \/>executed in accordance with the PSIP;<br \/>\u2022 Promote the dissemination of PSIP and take the necessary actions to disseminate a<br \/>culture of information security and privacy of personal data in the environment<br \/>CARE<\/p><p>5. PRINCIPLES OF USE OF AI<br \/>All AI solutions must be designed and implemented with robust mechanisms for<br \/>security to protect data against unauthorized access, leaks, and improper modifications<br \/>and other types of cyberattacks. AI models must be trained and validated in such a way that<br \/>minimize risks to the integrity and confidentiality of information.<\/p><p>The use of AI must be carried out in compliance with current data protection legislation, such as<br \/>the General Data Protection Law (LGPD) and the General Data Protection Regulation (GDPR), when<br \/>applicable. The processing of personal data by AI must be done transparently, ensuring<br \/>the appropriate consent of data subjects, whenever necessary.<\/p><p>6. CLASSIFICATION AND TREATMENT OF INCIDENTS<br \/>Every information security incident must be classified according to its criticality and impact,<br \/>and handled in accordance with established procedures. Reporting critical incidents<br \/>must be immediately reported to the CGSI, and containment and mitigation actions must be initiated immediately.<\/p><p>7. SANCTIONS AND PUNISHMENTS<\/p><p>Violations of this policy or other security standards, even by omission, will be subject to<br \/>penalties ranging from verbal warnings to dismissal for just cause for CLT employees,<br \/>and immediate termination of contracts for third parties or suppliers. The CGSI is responsible for analyzing<br \/>each infraction and decide on the punishments.<\/p><p>In cases of violation that involve illegal activities or damage to the organization, the offender will be<br \/>held accountable and subject to appropriate legal action. The application of sanctions and punishments will be carried out<br \/>according to the analysis of the Information Security Management Committee, and the<br \/>severity of the infraction, effect achieved and recurrence, and the CGSI may pass on the information of<br \/>infraction to the immediate Manager who will apply the penalty when the serious offense is identified.<\/p><p>In the case of third-party contractors or service providers, the CGSI must analyze the occurrence and<br \/>deliberate on the implementation of sanctions and punishments in accordance with the terms set out in the contract;<\/p><p>In the case of violations that involve illegal activities, or that may result in damage to<br \/>Organization, the offender will be held responsible for the damages, and the measures will be applied<br \/>relevant judicial decisions.<\/p><p>6. OMISSIONS<br \/>Omitted cases will be evaluated by the Information Security Management Committee for later<br \/>deliberation.<br \/>The guidelines established in this policy and in other security standards and procedures do not apply to<br \/>are exhausted due to continuous technological evolution and the constant emergence of new threats. This<br \/>form, it does not constitute an enumerative list, and it is the obligation of the user of CARE information to adopt,<br \/>whenever possible, other security measures in addition to those provided here, with the aim of guaranteeing<br \/>protection of personal information and data.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-f93c63d e-con-full e-flex e-con e-child\" data-id=\"f93c63d\" data-element_type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-6b817c2 e-flex e-con-boxed e-con e-parent\" data-id=\"6b817c2\" data-element_type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;_ha_eqh_enable&quot;:false,&quot;ekit_has_onepagescroll_dot&quot;:&quot;yes&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-90666c2 elementor-widget elementor-widget-spacer\" data-id=\"90666c2\" data-element_type=\"widget\" data-settings=\"{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Pol\u00edtica de Seguran\u00e7a da Informa\u00e7\u00e3o e Privacidade POL\u00cdTICA DE SEGURAN\u00c7A DA INFORMA\u00c7\u00c3O E PRIVACIDADE 1. OBJETIVOA CARE estabelece sua Pol\u00edtica de Seguran\u00e7a da Informa\u00e7\u00e3o e Privacidade, como parte integrante do seusistema de gest\u00e3o corporativo, alinhada \u00e0s boas pr\u00e1ticas do mercado, \u00e0 normas internacionalmenteaceitas e a legisla\u00e7\u00e3o brasileira pertinente, com o objetivo de garantir n\u00edveis adequados [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"elementor_header_footer","meta":{"footnotes":""},"class_list":["post-639","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/pages\/639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/comments?post=639"}],"version-history":[{"count":4,"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/pages\/639\/revisions"}],"predecessor-version":[{"id":643,"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/pages\/639\/revisions\/643"}],"wp:attachment":[{"href":"https:\/\/care-business.com\/en\/wp-json\/wp\/v2\/media?parent=639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}