ANNUAL INTEGRATED REPORT 2021 slide image

ANNUAL INTEGRATED REPORT 2021

29 ANNUAL INTEGRATED REPORT 2021 | AXTEL INFORMATION SECURITY FRAMEWORK AND PROCESSES Cybersecurity culture: employee awareness and training Cyber resilience: risk management and business continuity Cyber defense: vulnerability, identity and access management, technical compliance Incident response Safety by design Reviews: monitoring of indicators, audits, certifications, pentest Continuous improvement CUSTOMER DATA PRIVACY Our Privacy Notice¹ addresses Axtel's commitment to the protection of personal data and privacy in communications, one of the greatest challenges for our industry. We ensure compliance with current regulations in Mexico and reaffirm our commitment to the right to privacy and data protection of our customers, suppliers and employees. For this reason, we take several administrative, physical, and technical security measures to help us prevent losses, damage, alterations, and leaks. The personal data we use comes directly from the holder and/or through physical, electronic or face- to-face means, as well as from authorized public sources, and we treat it according to the type of holder. We do not transfer sensitive personal, property, or financial data for secondary purposes unless the holder gives their consent. In 2021, we received no complaints regarding violations of customer privacy, or about data breaches or data related to personally identifiable information (PII²). We did not suffer any monetary losses as a result of legal proceedings associated with user privacy. We adhered to the best practices defined in international standards such as ISO 27001, ISO 22301, ISO 31000, The American Institute of Certified Public Accountants (AICPA), Service Organization Controls (SOC) for Cybersecurity, National Institute of Standards and Technology (NIST), FIRST, PCI-DSS and SSAE-18. In addition, we conduct internal and third-party reviews, audits, vulnerabilities, penetration tests, drills, as well as working meetings with the stakeholders of each business process to identify the most relevant risks. We have therefore defined plans for their timely remediation. 1 Visit our Privacy Notice at: https://www.axtelcorp.mx/aviso-de-privacidad/ 2 PII. Personal Identifiable Information.
View entire presentation