PL 1021-01 · Rev. 02 · 11/03/2026 · Public use
Information security policy
4MDG – Master Data Governance · ZH Soluções Especialistas LTDA · CNPJ 11.955.326/0001-99. Prepared by Paulo Roberto Viccari de Nobile and approved by Cesar Coelho on 11/03/2026.
1. Objective
This document is a set of standards intended to guide the management of information, protecting and ensuring the pillars of confidentiality, integrity and availability in compliance with the NBR ISO/IEC 27001:2022 standard.
2. Scope of application
This information security policy applies to: any software provided by or under the control of 4MDG; any communications sent or received; any data owned, controlled or processed, including data held in external systems; locations from which data is accessed, including internal and external use; information assets held, processed or stored on our premises or at external locations; information in transit across voice or data networks.
All 4MDG personnel (employees, service providers, third-party representatives or subcontractors and interns) must be familiar with this policy.
Compliance with this policy is mandatory, and failure to comply may lead to disciplinary sanctions.
3. Definitions
Information asset: any data, system, software, hardware, document or physical resource that has value to the organization and requires adequate protection.
Access control: measures to ensure that access to assets is authorized and restricted based on business and security requirements.
Authentication: process of providing assurance that a claimed characteristic of an entity, such as the identity of a user or device, is correct. Authentication is essential to ensure that only authorized individuals or systems can access certain resources or information.
Confidentiality: property that information is not made available or disclosed to unauthorized individuals, entities or processes.
Integrity: property of accuracy and completeness of information.
Availability: property of being accessible and usable on demand by an authorized entity.
Privacy: control over the collection, storage, use and sharing of personal data, in compliance with applicable legislation.
Interested party: person or organization that can affect, be affected by, or perceive itself to be affected by a decision or activity. E.g.: customers, employees, suppliers, shareholders, regulatory bodies, and business partners.
Privacy breach: situation in which personal data is processed inappropriately, resulting in the violation of one or more privacy protection requirements, compromising the confidentiality, integrity or availability of that data.
Information Security Management System (ISMS): consists of policies, procedures, guidelines, associated resources and activities, collectively managed by an organization with the objective of protecting its information assets.
Privacy Information Management System (PIMS): set of policies, processes and controls implemented to manage and protect personal data, ensuring that the organization complies with privacy legislation and that the rights of data subjects are respected in all of the organization's operations.
4.1 Statement
“4MDG is committed to implementing and monitoring its information security controls to ensure the confidentiality, integrity, availability and authenticity of every information asset, meeting the regulations and contractual requirements of its customers, employees, partners and interested external parties, always seeking the continuous improvement of its processes and services.”
4.2 Acceptable use of assets
All employees are responsible for protecting the information and information assets under their responsibility, which must be used in an acceptable manner and in accordance with this and other ISMS-related policies and processes.
4.3 Clear desk, clear screen
Unattended or unused computing devices are protected with a password-controlled screen or locking mechanism, or a similar authentication mechanism (this includes laptops, tablets, smartphones and workstations).
Workstations are locked after a period of inactivity. When you step away, the workstation must be locked using Ctrl-Alt-Del, the "Lock" option, or the Windows key and 'L'. This prevents people from accessing any information they are not authorized to see while the device is unattended.
When accessing confidential information or information containing personal data on a screen, users must ensure that unauthorized people cannot view such information. Computer screens on which confidential or personal information is processed or displayed must be positioned so that they cannot be viewed by unauthorized people.
Confidential or restricted-access information, whether on paper or on electronic storage media, must be protected when not in use, especially when the office is vacated at the end of the working day. Care must also be taken when printing confidential or restricted-access documents to prevent unauthorized disclosure.
No loose papers or exposed notes: notes with passwords, sticky notes with data, or working drafts must be properly disposed of (e.g., shredded) or filed.
Secure storage of removable media: USB drives, external hard drives and similar media must be stored securely after use.
No personal items on the desk: avoid personal objects such as toys, ornaments, food, bags or items unrelated to work.
4.4 Internet use
Internet use must be conscious and aligned with the needs of your work activities and, occasionally, personal ones. Abusive use that may compromise work performance, or that knowingly puts the company's information assets at risk, may result in verbal or formal warnings, depending on the severity.
Internet access on company assets is monitored and controlled, unless there is an explicit need for unrestricted access to perform work activities related to the role. Unrestricted access is authorized by a manager or director.
4.5 Use of email
Using corporate email for personal purposes is inappropriate and is not permitted at any time. The email system provided by 4MDG must be used to send and receive 4MDG information and must not be used in an insulting or offensive manner.
If you receive an inappropriate or abusive email, you must report it immediately to your manager, who will take the appropriate measures. If the sender is known to you, inform them that they must stop sending the material. Emails that appear suspicious, and may be "phishing" or malware attempts, must be reported immediately as an information security incident.
4.6 Use of removable media
Removable media is understood as any type of memory that can be removed, providing portability for the data stored on it. Some examples of removable media are: flash drives, memory cards, external hard drives, among others.
The use of removable media is not permitted by 4MDG. In exceptional situations, authorization must be requested from your immediate manager, and each case will be assessed individually.
4.7 Restrictions on software use and installation
Software is managed and controlled in accordance with company policies regarding asset management and license agreements. All software used on company-managed devices must be installed in accordance with the current internal software licensing guidelines.
Violating the rights of any person or company protected by copyright, trade secret, patent or other intellectual property, or similar laws or regulations, including but not limited to the installation or distribution of "pirated" products or other software products that are not properly licensed, may subject the employee to disciplinary action.
4.8 Passwords
Passwords and other forms of secret authentication, such as cryptographic keys and pattern locks, used to access devices, networks and systems are for the exclusive use of the user and therefore must not be shared. Likewise, you must not use another person's password.
If you suspect that a password or another form of secret authentication may have been compromised, you must change it immediately on all devices, networks and systems where it is in use and report it to the IT area immediately.
The Password Policy sets out the rules on password compliance and the use of passphrases.
4.9 File storage
To ensure data security and integrity, all employees must store their files exclusively on the organization's Drive.
Storing work files on personal devices, external storage drives or other cloud storage services is prohibited.
Do not use Google/Microsoft Drive sharing permissions to grant access to colleagues or teams. If any sharing is needed, request it from the IT department.
Do not disable any security or backup setting without explicit authorization from the IT department.
4.10 Use of authentication with corporate Microsoft accounts
Do not use your corporate Microsoft account to authenticate on any platform, application, or service that has not been explicitly authorized by the organization.
If you need to use a new platform or service, consult the IT department for evaluation and approval before using your corporate Microsoft account for authentication.
4.11 Use of WhatsApp
WhatsApp use must be limited to quick, non-sensitive communications that do not involve confidential data.
Avoid discussing confidential company information over WhatsApp. Whenever possible, use the organization's internal and secure communication channels for sensitive discussions.
To use WhatsApp in the corporate environment, you must configure backups to run daily and enable two-factor authentication.
4.12 Anti-malware
All company workstations have antivirus software installed and configured to update their signatures automatically. In addition, workstations are scanned periodically to detect and remove malware, malicious or unwanted programs. Uninstalling the antivirus software is strictly prohibited.
4.13 Training and awareness
4MDG recognizes that information protection and compliance with security policies depend largely on the knowledge and secure behavior of its employees. To this end, we maintain an ongoing information security and privacy training and awareness program, comprising the following activities:
Initial training: all new employees, service providers, interns and third parties must attend information security training during the onboarding process.
Periodic training: all active employees must attend information security refresher training at least once a year, or whenever there is a relevant update to the policies or to the identified risks.
Training content: the training covers topics such as good practices for information protection, secure use of systems, password policies, malware protection, data privacy (LGPD), security incident prevention and incident response.
Awareness campaigns: we periodically run internal awareness campaigns, reinforcing good practices and alerting people to new threats or security trends.
Employee obligations: each employee is responsible for attending mandatory training, applying the knowledge acquired in their daily work, and seeking support whenever questions or risk situations arise.
Failure to comply with training and awareness obligations may be considered a violation of this Policy and will be subject to the applicable sanctions.
4.14 Physical security
4MDG adopts physical security measures to protect information assets against unauthorized access, damage, loss or interference.
Access control
The badge is personal and non-transferable. Its use is mandatory to access the building and internal blocks.
Visitors must be previously authorized and identified at the reception desk.
Keep restricted doors and access points closed and locked when unsupervised.
Do not allow unauthorized third parties to access 4MDG rooms.
Visitors must always be accompanied by an employee.
Workstation
Adopt the clear desk and clear screen practice as per item 4.3 of this Policy.
Electronic equipment must be removed from the workstation at the end of activities: take the notebook home, or store it in a locked personal locker.
The locker key must not be shared or copied. In case of loss, notify management immediately.
Do not share workstations without prior authorization.
Use of equipment
Connecting unauthorized personal devices (such as flash drives and external hard drives) to corporate equipment is prohibited.
Keep equipment organized and away from edges to avoid falls and damage.
Physical document security
Any physical document with personal, sensitive or strategic data must be kept in a locked place.
Never discard papers with corporate data without shredding them.
If you notice sensitive documents left exposed, notify the person responsible immediately.
4.15 Information security incident reporting
If you identify an information security incident, you must notify us immediately through the e-mail suporte@4mdg.com.br or open a ticket in the Freshdesk system. In critical and urgent cases, contact us by phone at (11) 96467-2188 with the following information: a detailed description of the incident; date and time of occurrence; systems or data affected; any available evidence (screenshots, logs, error messages).
Maintain the confidentiality of the incident, discussing it only with the authorized people involved in its resolution.
5. Sanctions
Failure by contractors, temporary staff, public parties, partners or outsourced organizations to comply with our information security policy may result in the termination of contracts and relationships, suspension of services and/or the filing of legal proceedings.
Employees who fail to comply with the rules established in this document will be subject to the following sanctions, applied immediately upon the occurrence of the misconduct: 2 verbal warnings; 2 written warnings; 1 suspension of 1 day; 1 suspension of 3 days; 1 suspension of 5 days; dismissal for cause.
The intent is for the above list of penalties to be applied progressively; however, and as permitted by current legislation, when the severity of the act so requires, the penalty will be assessed and applied in proportion to the misconduct committed, even if the previous measure has not been enforced.
The order above may be changed according to the severity of the misconduct.
6. References
ABNT. (2022). NBR ISO/IEC 27001:2022. Rio de Janeiro: ABNT.
Change identification
Rev. 00 · 21/10/2025 — prepared by Paulo Roberto Viccari de Nobile.
Rev. 01 · 10/11/2025 — adjustments to item 4.11 Use of WhatsApp; to the source of the topics in item 4.14 Physical Security, removal of the word identification from the sentence “The badge is personal and non-transferable” and adjustments to the second paragraph of item 4.8 Passwords.
Rev. 02 · 11/03/2026 — adjustments to the information classification and document formatting.
Reproduction of official document PL 1021-01, Rev. 02, classified as public use, issued on 11/03/2026. In case of divergence, the signed version maintained by 4MDG prevails.