Switch Language

1.    General Provisions

1.1.    Objective

To establish the Information Security and Privacy Management System Policy of Brigard & Urrutia Abogados S.A.S. and allied and subordinate companies, ensuring that:

  • It is appropriate to the purpose and strategic objectives of the Firms.
  • It provides the basis for the establishment of measurable and achievable objectives related to information security and privacy.
  • It includes the commitment to protect information assets against cyber threats.
  • It includes the commitment to the continual improvement of the Information Security and Privacy Management System through internal audits, management reviews, and corrective actions.
  • It clearly defines the scope of the policy, indicating the areas, processes, and information assets covered.
  • It establishes specific roles and responsibilities for the implementation and maintenance of the policy.
  • It emphasizes the importance of performing periodic risk assessments to identify and mitigate threats, including emerging cyber threats.
  • It highlights the need for training and awareness programs for all employees.CFM, SMJ, MCJ, JRV, AIC

1.2.    Scope

This document contains the Policy adopted by Brigard & Urrutia Abogados S.A.S. and allied and subordinate companies for the Information Security and Privacy Management System and is directed to all employees, Support Units, High Performance Teams (EAR), providers, and contractors of the Firms.

1.3.    Definitions

  • Information Asset: Refers to any information or element related to its processing (systems, media, persons) that has value for the organization.
  • Threat: Potential cause of an unwanted incident, which may result in damage to a system or to the organization.
    Confidentiality: Property that determines that information is not available nor disclosed to unauthorized individuals, entities, or processes.
  • Security Control: Measure that modifies risk. Security controls may include policies, procedures, guidelines, practices, or organizational structures.
  • Personal Data: Any information, linked or that may be associated with one or more identified or identifiable natural or legal persons.
  • Availability: Property that information is accessible and usable upon request by an authorized entity.
  • Risk Management: Coordinated activities to direct and control an organization with respect to risk.
  • Security Incident: An adverse event in a computing environment that compromises the confidentiality, integrity, or availability of information. It is a violation of an information security policy, acceptable use policy, or security best practices.
  • Information: Set of data, already processed and ordered for its comprehension, that provides new knowledge to an individual or system about a subject, matter, phenomenon, or specific entity.
  • Integrity: Property of safeguarding the accuracy and complete state of assets.
  • Continual Improvement: Permanent action carried out in order to increase the capacity to meet requirements and optimize performance.
  • Privacy: Sphere of private life that one has the right to protect from any intrusion.
  • Risk: Effect of uncertainty on objectives.
  • Vulnerability: Weakness of an asset or group of assets that can be exploited by one or more threats.

1.4.    Responsibilities

This document is generated and updated by the Information Security Officer, approved by the Senior Management Representative in charge of the General Secretariat and Compliance Officer; the document will be reviewed by the Information Security and Privacy Working Group and in case observations are presented, the respective adjustments will be made.
It is the responsibility of all personnel of Brigard & Urrutia Abogados S.A.S. and allied and subordinate companies to follow the parameters specified in this policy.
It is the responsibility of the Information Security Officer to verify compliance in all areas of the Firms.

Below, the responsibilities for policy compliance are established.

  • Senior Management:
    • Provide leadership, support, and resources for the implementation, maintenance, and improvement of the ISMS.
    • Ensure that information security is aligned with the strategic objectives of the organization.
       
  • Information Security and Privacy Working Group
    • Disseminate and promote compliance with the Information Security and Privacy policy in their respective teams.
    • Implement security controls and monitor their effectiveness.
    • Perform internal audits and security reviews.
    • Coordinate the response to security incidents, including the management of specialized resources such as computer forensic experts when the technical analysis requires it.
       
  • General Secretariat and Compliance Officer – Senior Management Representative
    • Ensure legal and regulatory compliance in data protection.
    • Act as point of contact for data protection authorities and interested parties.
    • Supervise the implementation of specific controls for data protection.
       
  • Information Security Officer
    • Develop, maintain, and update the information security and privacy policy.
    • Supervise the implementation of the Information Security and Privacy Management System.
    • Coordinate risk assessments and manage security incidents.
    • Promote the culture of security and privacy.
       
  • Employees
    • Identify and report risks and possible information security incidents.
    • Comply with Information Security and Privacy policies and procedures.
       
  • Providers and Contractors
    • Comply with the information security and privacy requirements established in the contracts.
      Implement controls commensurate with risk levels.
       
  • IT Management 
    • Apply and implement controls that allow maintaining the security of networks, systems, and applications.
    • Apply patches, monitor vulnerabilities, and manage access.

2.    Guiding Principles

  • Confidentiality: Information can only be accessed by authorized persons.
  • Integrity: Information must be maintained complete, accurate, and without improper alterations.
  • Availability: Information must be available for those who need it, when they need it.
  • Privacy: Personal data must be processed in accordance with the law, guaranteeing the rights of data subjects.
  • Ethical and legal compliance: The practice of law must respect both applicable legislation and the deontological principles of law.

3.    Policy

3.1.    Information Security and Privacy Management System Policy

With the purpose of fulfilling the mission of being at the forefront to simplify the complex, add value to our environment, transform the legal industry, and leave a lasting legacy, Brigard & Urrutia Abogados S.A.S. and allied and subordinate companies have adopted an Information Security and Privacy Management System.

This system supports the work of its multidisciplinary team of lawyers specialized in the various areas of Business Law, and aims to ensure the adequate management of information-associated risks during the development of its operations, thus guaranteeing confidentiality, integrity, availability, and privacy and protection against cyber threats.

In this context, the Firms commit to:

  1. Preserve the confidentiality, integrity, availability, and privacy of information, recognizing it as a strategic asset for service delivery and decision-making.
  2. Protect information and its technological infrastructures, as part of a risk management strategy, business continuity, and information security and privacy culture.
  3. Identify, analyze, treat, and monitor risks that affect information, guaranteeing compliance with legal, contractual, regulatory, and business requirements, and contributing to the sustainability and competitiveness of the Firms.
  4. Foster and maintain a culture of security, through continuous training programs in good security and privacy practices that contribute to minimizing the probability of occurrence and the eventual impact of information security and privacy incidents.
  5. Strengthen the digital resilience of critical services, through the implementation, maintenance, and execution of the Business Continuity Plan (BCP).
  6. Guarantee the adequate processing of personal data, in accordance with Ley 1581 de 2012 and ISO/IEC 27701.
  7. Continually improve the SGSPI, strengthening controls, auditing processes, managing incidents in a timely manner, and reducing their impact.

This Policy is of mandatory compliance for all employees, providers, and contractors of Brigard & Urrutia Abogados S.A.S. and allied and subordinate companies. Non-compliance will be considered an information security incident and a violation of the Internal Work Regulations, and will be treated in accordance with the disciplinary procedures and policies of the Firms. See Chapter “Scale of faults and disciplinary sanctions” in the Internal Work Regulations of Brigard & Urrutia Abogados S.A.S., Brigard & Castro S.A.S and that of the allied and subordinate companies as applicable.

4.    References

  • ISO/IEC 27000: Information Security Management System (ISMS) - Overview and vocabulary.
  • ISO/IEC 27001: Requirements for the implementation of the Information Security Management System (ISMS).
  • ISO/IEC 27002: Code of practice for information security management.
  • ISO/IEC 27701: Extension to ISO/IEC 27001 and ISO/IEC 27002, Requirements for the implementation of an Information Privacy Management System.
  • Ley 1581 de 2012: The Personal Data Protection Law recognizes and protects the right of all persons to know, update, and rectify information that has been collected about them in databases or files that are susceptible to processing by the Firms and that are of a public or private nature.