2020 Annual Report
2020 ANNUAL REPORT
OUR ESG STRATEGY
MEGACABLE.
360° CYBERSECURITY STRATEGY
Cybersecurity is a fundamental matter in the digital era. The increase in cybercrimes and incidents has become a major
problem that must be addressed through a strategy and a team that specializes in this area. This is why, at Megacable, we
have policies, procedures, certifications and a Cybersecurity Department that is tasked with developing a security framework
to safeguard information and protect critical infrastructure, under the premise of identifying security standards and guidelines
that can be applied in every area within the Organization.
The following are some of the actions that we have taken that are aligned with the industry-accepted standards that govern
our operations:
Network Security
Geolocation policies for perimeter equipment.
Controlled access.
Malware Protection
Administration of Privileges
User profiles.
Mismanagement reports (lending of ID).
Incident Response Plan
We also have an incident response plan that allows us to
monitor and detect problems, contain them, and resolve
them without affecting our operations. Based on a protocol
and working basis, we are capable of resolving any IT
security incident that may happen within the Company.
Response Plan
This plan encompasses 6 general stages that describe how
to act in the event of a security incident:
Off-site Working
Updated signatures on all devices.
•
Maintaining same security policies.
Risk Management Model (Committee)
^
Policies and standards.
Ⓡ
Analysis & Monitoring
Current moment and trends.
Incident Management
•
On-time support for reports.
Preparation
Stage
Identification
Stage
Containment
Stage
Payments via Internet
In order to offer security to all our customers who make
payments via our website, we have implemented strict
security measures that include PCI DSS certification
(Payment Card Industry Security Standards Council),
focusing on networks, systems and other equipment that
can process transactions made using bank cards (credit
and debit).
The purpose of PCI-DSS and PA-DSS standards is to
demonstrate to credit and debit card processors around the
world (such as Visa, Discover and AMEX, among others)
that the data is being processed correctly and securely, in
addition to stating that their commercial and IT operations
can be audited.
Employee Training
We constantly offer training opportunities to our
employees in order to respond to any IT security incident
that may arise.
Based on frameworks such as:
Detection of anomalies.
CED
Eradication
Stage
Recovery
R
NIST
1°
5°º
2º
COBIT
0%
3º
Stage
Continuous improvement
Stage
SGSI
ISO
1
2
B
3
C
ISO 27701
Auditoría
22
22View entire presentation