How we protect our clients' information and the personal data we process.
1. Team members must use strong, unique passwords, renewed every 90 days or as specified by the client.
2. Two-factor authentication (2FA) may be enabled for access to critical systems, as defined by the client.
3. Users, passwords and equipment are for personal, non-transferable use; under no circumstances may they be assigned or lent.
4. Equipment and users must have only the access required to perform their duties.
5. Equipment will be used exclusively for tasks related to the client’s project.
6. If the equipment used to perform the contracted duties is provided directly by a client, the direct installation of additional software or applications is not allowed. Any additional installation must be arranged with the client.
7. All client information must be stored only in the repository defined by the client.
8. Local backups must be avoided; use the client’s or KAP’s official storage platforms.
9. Confidential information must be transferred using the mechanisms defined by the client on the internet (SharePoint, OneDrive, Dropbox, Google Drive, etc.).
10. Company information must not be used for personal purposes or for purposes other than those required to perform one’s duties.
11. Equipment must have up-to-date antivirus software and an enabled intrusion detection system.
12. Installed protections must not be manually disabled.
13. Avoid placing the equipment in dusty, humid or excessively hot places or in direct sunlight.
14. Avoid knocks or sudden movements when handling the equipment. If it is a laptop, store it in a padded case when transporting it.
15. Clean the outside of the equipment with a soft, dry cloth to remove dust and dirt.
16. Avoid spilling liquids on the equipment. If this happens, immediately disconnect the equipment from the power supply and dry it with a soft, dry cloth.
17. Make sure the equipment’s ventilation slots are not obstructed to prevent overheating.
18. Use a voltage regulator or a UPS (Uninterruptible Power Supply) to protect the equipment from voltage fluctuations.
19. Disconnect the equipment from the power supply and from the telephone or network line during electrical storms to avoid lightning damage.
20. If you use a laptop, do not leave the battery constantly connected to the power supply. Charge it when necessary and disconnect it when it reaches an adequate level.
21. Avoid forcing the keys, mouse or screen. If cleaning is necessary, use appropriate products and avoid abrasive cleaners.
22. The use of public or unsecured Wi-Fi networks must be avoided.
23. When the project requires it, connection will be made through the client’s or KAP’s VPN.
24. Equipment must lock automatically after 5 minutes of inactivity or according to the policies configured by the client on the equipment.
25. When traveling or working remotely, the equipment must remain under the user’s direct custody.
26. Any loss or theft must be reported immediately to the Project Manager, who will in turn report it to the client.
27. The containment protocol and remote data lock will be activated if the equipment allows it.
28. The condition of the equipment will be reviewed.
29. The equipment will be formatted and/or restored to its original state if required by the client.
30. A Return Certificate will be signed.
31. Every user who starts working on behalf of KAP, whether under a direct contract or through a partnership, must complete the onboarding training and the annual Security Policy certification.
Note: Failure to comply with any of the Security Policies established by KAP or by the client, as well as any other non-conformity of the contracted service, may result in a formal warning recorded in the personnel file.
Likewise, failure by KAP personnel to report a security incident is grounds for a formal warning recorded in the personnel file.