Information
Security
Policy
ST IT Cloud

1. Who this policy applies to

ST IT Cloud establishes this Information Security Policy to guide all employees, service providers, and business partners in protecting the company's and its clients' information assets.

Our commitment is to ensure secure, reliable, and integrity-driven digital environments, based on three fundamental principles:

  • Confidentiality: only authorized persons have access to information;
  • Integrity: only approved and traceable changes are permitted;
  • Availability: information must be accessible to authorized persons whenever needed.

Information security is everyone's responsibility. Compliance with this policy ensures business continuity, legal compliance, and the protection of ST IT Cloud's and its partners' reputation.

2. Objective

Maintain the highest standards of security, governance, and compliance, reducing risks and ensuring that our processes, technologies, and people work together to protect data and information assets.

3. Information security governance structure

3.1 Information Security and Compliance Committee (CSIC)

The CSIC is responsible for defining, reviewing, and approving information security guidelines, ensuring annual updates or whenever necessary.

Key responsibilities:

  • Propose adjustments and improvements to standards and procedures;
  • Classify information according to its confidentiality level;
  • Analyze incidents and propose corrective action plans;
  • Coordinate interdepartmental security actions;
  • Ensure the effectiveness of risk management and internal controls.

3.2 Information Security Area

Responsible for implementing and monitoring security guidelines across the organization.

Key responsibilities:

  • Disseminate security policies, standards, and norms;
  • Support internal and external audits;
  • Assess risks and vulnerabilities;
  • Manage access and authentication controls;
  • Support clients and partners on security-related topics;
  • Ensure technological compliance (firewalls, encryption, antivirus, etc.).

3.3 Area Managers

Each system or process has a responsible person who ensures compliance with access and protection standards.

Responsibilities:

  • Control access authorizations and revocations;
  • Keep records updated;
  • Participate in incident investigations;
  • Ensure their teams know and comply with the policy.

3.4 Human Resources

Support in onboarding new employees with a focus on security awareness.

Responsibilities:

  • Incorporate security training in onboarding;
  • Support disciplinary actions when necessary;
  • Ensure terminations include access revocation.

3.5 Dissemination

The Information Security Policy will be made available and communicated to all those involved in ST IT Cloud's operations.

Forms of dissemination:

  • Presentation during hiring process;
  • Availability on internal system;
  • Periodic training;
  • Awareness campaigns.

4. General guidelines

4.1 Legal Compliance

ST IT Cloud complies with LGPD, sector-specific regulatory frameworks, and all applicable legislation. Regular internal audits ensure standards are maintained.

4.2 Information Classification

Information is classified as:

  • Public – no restrictions;
  • Internal – restricted to employees;
  • Confidential – only for specifically authorized persons;
  • Top Secret – maximum protection (client data, trade secrets).

4.3 Identification and Authentication

All system access requires individual identification and multi-factor authentication (MFA).

  • Personal and non-transferable credentials;
  • Passwords with complexity requirements and periodic rotation;
  • Mandatory MFA in critical environments;
  • Automatic lockout after invalid attempts.

4.4 Confidentiality and Integrity

  • Sharing confidential information without authorization is prohibited;
  • All changes in production environments must be approved and traceable;
  • Regular backups with integrity validation;
  • Encryption in transit and at rest for sensitive data.

4.5 Secure Behavior

  • Lock workstations when leaving;
  • Do not install unauthorized software;
  • Report any security incident immediately;
  • Do not use personal devices without authorization.

4.6 Risk Assessment

We conduct periodic risk assessments to identify vulnerabilities, measure impact, and prioritize corrective actions continuously.

4.7 Access Management

  • Principle of least privilege;
  • Periodic access review;
  • Immediate revocation upon termination;
  • Segregation of duties in critical operations.

4.8 Monitoring and Control

We conduct continuous monitoring of environments, logs, and security events, with SIEM tools and automated alerts.

4.9 Training and Awareness

Regular training programs for all employees, covering best practices, phishing, social engineering, and incident response.

4.10 Security Products and Services

Our solutions follow security standards from inception (Security by Design), with code reviews, penetration testing, and continuous validation.