SUMMARY
- OBJECTIVE
- APPLICATION AND SCOPE
- REFERENCE AND COMPLEMENTARY DOCUMENTS
- Reference Documents
- Complementary Documents
- DEFINITIONS
- RESPONSIBILITY AND AUTHORITY
- DESCRIPTION
- Principles
- Guidelines
- REGISTRATIONS
- ANNEXES
- OBJECTIVE
Establishing Transpetro's Information Security Policy
- APPLICATION AND SCOPE
It applies to Petrobras Transporte S.A. – TRANSPETRO and its equity interests (Transpetro Bel 09 S.A. –TRANSBEL and Transpetro International B.V. - TIBV), taking into account the specificities of each company.
Policy approved by Transpetro's Board of Directors - Minutes CA 308, of October 28, 2021.
Policy approved by Transbel's Board of Executive Officers - Certificate No. 14, Item 03, Agenda 003.
Policy approved by the TIBV Executive Board - WR MB TIBV No. 05-2022 of 04/04/2022.
- REFERENCE AND COMPLEMENTARY DOCUMENTS
-
- Reference documents
PL-0SPB-00019 Petrobras INFORMATION SECURITY POLICY
-
- Additional documents
Not applicable
- DEFINITIONS
Confidentiality: the property by which it is ensured that information is not available or disclosed to an unauthorized or unaccredited person, system, body or entity;
Availability: the property by which it is ensured that information is accessible and usable on demand by an individual or a certain duly authorized system, body or entity;
Integrity: the property by which it is ensured that information has not been modified or destroyed in an unauthorized or accidental manner;
Authenticity: the property by which it is ensured that information has been produced, dispatched, modified or destroyed by a specific individual, piece of equipment, system, body or entity.
- AUTHORITY AND RESPONSIBILITY
Not applicable
- DESCRIPTION
-
- Principles
- The company handles information in compliance with business requirements, the relevant regulations and the pillars of Information Security: Confidentiality, Availability, Integrity and Authenticity.
- The company maintains a comprehensive and systemic view of information security in its businesses, processes and relationships.
- Principles
-
- Guidelines
The Company must:
-
-
- Maintaining Information Security governance, defining activities, roles and responsibilities;
- Promote the culture of Information Security, disseminating it effectively and continuously;
- Apply technological and administrative measures aimed at Information Security and Cyber Security, in line with the prioritization from the Corporate Risk Analysis, and may even disconnect non-compliant units and locations from the Petrobras corporate network. Always observing that cyber security is an essential part of information security;
- Providing the necessary resources to maintain technological and administrative Information Security measures;
- Adopt Information Security requirements in processes and technologies, right from the start;
- Provide the means to identify, prevent and deal with Information Security incidents.
-
Company employees must:
-
-
- Use, classify and protect information ethically and securely, in accordance with current standards;
- Report possible Information Security incidents through a specific channel.
-
- REGISTRATIONS
Not applicable
- ANNEXES
Not applicable