Technological Risk - 2020 ANNUAL REPORT
Technological Risk
The institution performs technological risk management by monitoring Availability and Information Security indicators, as well as the Technological Risk Profile and Information Security methodology, which consists of a technological and information security evaluation of the assets that support the critical processes, considering all the activities of the IT process, based on best practices and international standards, such as ISO 27001, 27002, 27005 and 31000.
On the other hand, a Business Continuity Plan Management System is in place, aiming to ensure the continuity of operations and minimize the impacts of the various potential contingencies. Said plan is based on the Business Impact Analysis methodologies, whose objective is to identify and prioritize the Institution's critical processes for the recovery of services in the event of a contingency, and on Risk Analysis, which aims to estimate the impacts to critical processes, when confronted to different threats, to determine the proper courses of action. These methodologies are based on ISO 22301 and 22317 standards.
During 2020, the SG - PCN Business Continuity Plan Management System was activated for the Pandemic scenario. The teleworking model was operated with technological and control services and tools for the development of banking functions. To date, the availability of services has been maintained within the committed thresholds and there have been no incidents that violate the security of the institution's information.