
Information
Security
Policy
ST IT Cloud
1. Who this policy applies to
ST IT Cloud establishes this Information Security Policy to guide all employees, service providers, and business partners in protecting the company's and its clients' information assets.
Our commitment is to ensure secure, reliable, and integrity-driven digital environments, based on three fundamental principles:
- Confidentiality: only authorized persons have access to information;
- Integrity: only approved and traceable changes are permitted;
- Availability: information must be accessible to authorized persons whenever needed.
Information security is everyone's responsibility. Compliance with this policy ensures business continuity, legal compliance, and the protection of ST IT Cloud's and its partners' reputation.
2. Objective
Maintain the highest standards of security, governance, and compliance, reducing risks and ensuring that our processes, technologies, and people work together to protect data and information assets.
3. Information security governance structure
3.1 Information Security and Compliance Committee (CSIC)
The CSIC is responsible for defining, reviewing, and approving information security guidelines, ensuring annual updates or whenever necessary.
Key responsibilities:
- Propose adjustments and improvements to standards and procedures;
- Classify information according to its confidentiality level;
- Analyze incidents and propose corrective action plans;
- Coordinate interdepartmental security actions;
- Ensure the effectiveness of risk management and internal controls.
3.2 Information Security Area
Responsible for implementing and monitoring security guidelines across the organization.
Key responsibilities:
- Disseminate security policies, standards, and norms;
- Support internal and external audits;
- Assess risks and vulnerabilities;
- Manage access and authentication controls;
- Support clients and partners on security-related topics;
- Ensure technological compliance (firewalls, encryption, antivirus, etc.).
3.3 Area Managers
Each system or process has a responsible person who ensures compliance with access and protection standards.
Responsibilities:
- Control access authorizations and revocations;
- Keep records updated;
- Participate in incident investigations;
- Ensure their teams know and comply with the policy.
3.4 Human Resources
Support in onboarding new employees with a focus on security awareness.
Responsibilities:
- Incorporate security training in onboarding;
- Support disciplinary actions when necessary;
- Ensure terminations include access revocation.
3.5 Dissemination
The Information Security Policy will be made available and communicated to all those involved in ST IT Cloud's operations.
Forms of dissemination:
- Presentation during hiring process;
- Availability on internal system;
- Periodic training;
- Awareness campaigns.
4. General guidelines
4.1 Legal Compliance
ST IT Cloud complies with LGPD, sector-specific regulatory frameworks, and all applicable legislation. Regular internal audits ensure standards are maintained.
4.2 Information Classification
Information is classified as:
- Public – no restrictions;
- Internal – restricted to employees;
- Confidential – only for specifically authorized persons;
- Top Secret – maximum protection (client data, trade secrets).
4.3 Identification and Authentication
All system access requires individual identification and multi-factor authentication (MFA).
- Personal and non-transferable credentials;
- Passwords with complexity requirements and periodic rotation;
- Mandatory MFA in critical environments;
- Automatic lockout after invalid attempts.
4.4 Confidentiality and Integrity
- Sharing confidential information without authorization is prohibited;
- All changes in production environments must be approved and traceable;
- Regular backups with integrity validation;
- Encryption in transit and at rest for sensitive data.
4.5 Secure Behavior
- Lock workstations when leaving;
- Do not install unauthorized software;
- Report any security incident immediately;
- Do not use personal devices without authorization.
4.6 Risk Assessment
We conduct periodic risk assessments to identify vulnerabilities, measure impact, and prioritize corrective actions continuously.
4.7 Access Management
- Principle of least privilege;
- Periodic access review;
- Immediate revocation upon termination;
- Segregation of duties in critical operations.
4.8 Monitoring and Control
We conduct continuous monitoring of environments, logs, and security events, with SIEM tools and automated alerts.
4.9 Training and Awareness
Regular training programs for all employees, covering best practices, phishing, social engineering, and incident response.
4.10 Security Products and Services
Our solutions follow security standards from inception (Security by Design), with code reviews, penetration testing, and continuous validation.