Information Security & Cyber Security Policy
Through this policy, Banco Sumitomo Mitsui Brasileiro S.A. (“SMBCB”) aims to minimize its risks and demonstrate due diligence to its stakeholders.
SMBCB is committed to ensuring that information security risks that may impact its business are properly managed. To this end, it adopts a formal risk management approach, including identification, assessment, mitigation, monitoring, and compliance with applicable regulatory requirements.
Principles
This policy is based on the following principles:
- Confidentiality
- Integrity
- Availability
- Compliance
Protection Against Unauthorized Access
The policy establishes controls to address the following threats:
- Prevention, detection, and response to security incidents
- Continuity of critical operations in case of incidents
- Compliance with applicable laws, rules, and regulations
This policy applies to all employees, third parties, and users with access to systems and information, covering all technological and informational assets of the institution.
Management Structure and Controls
The institution adopts formal processes for:
- Information security and cybersecurity risk management
- Access control based on the principle of least privilege
- Classification and protection of information according to its sensitivity
- Continuous monitoring and traceability of access
- Vulnerability management and asset protection
Incident Management
Structured processes are maintained for:
- Identification, logging, and handling of incidents
- Assessment of operational and reputational impacts
- Timely communication to management and competent authorities, when applicable
Business Continuity
The institution ensures operational resilience in adverse scenarios through its business continuity program, which includes:
- Identification of critical processes
- Recovery and contingency plans
- Periodic effectiveness testing
Cybersecurity
Cybersecurity management includes:
- Monitoring of threats and emerging risks
- Preventive, detective, and corrective controls
- Structured incident response
- Continuous improvement of security practices
Third Parties and Cloud Services
The institution adopts controls for:
- Vendor risk assessment
- Definition of contractual security requirements
- Data protection in outsourced services
- Compliance with regulatory requirements applicable to cloud computing
Governance
Information security governance is based on defined responsibilities among:
- Senior management (oversight and approval)
- Security function (management and monitoring)
- Business areas (control and appropriate use)
- Users (compliance with guidelines)
Compliance and Monitoring
The institution ensures:
- Adherence to financial sector and data protection regulations
- Continuous monitoring of implemented controls
- Periodic audits
- Regular review of the policy and processes
Statement
The institution maintains an information security and cybersecurity environment compatible with its size, complexity, and risk profile, ensuring the protection of its assets, the continuity of its services, and the trust of clients, partners, and regulators.