IT Security Policy

IT'S YOUR DATA

Effective date: January 1st, 2021

 

Public Information Security Policy Statement

 

1. Purpose

At BM Castings, we are committed to safeguarding the confidentiality, integrity, and availability of all physical and digital information assets. This policy defines our overarching commitment to data protection, compliance, and risk management. It ensures that our customers, partners, and stakeholders can trust us with their data.

 

 

2. Scope

This policy applies to all information assets owned, operated, or processed by BM Castings. It governs all employees, contractors, third-party vendors, and systems that access our internal networks and data environments.

 

 

3. Core Security Commitments

We align our security program with international standards, specifically ISO/IEC 27001, to manage risks effectively through the following core pillars:

 

Confidentiality: We ensure that sensitive data is accessible only to authorized individuals.

Integrity: We protect information from unauthorized modification, ensuring data remains accurate and complete.

Availability: We maintain resilient systems so that authorized users have reliable access to information when needed.

 

 

4. Policy Framework & Controls

To achieve our security objectives, we implement robust controls across our organization:

 

Access Control: We enforce the principle of least privilege. Access to data is strictly limited based on business necessity and protected by multi-factor authentication (MFA).

Data Protection: We utilize industry-standard encryption protocols to protect data both in transit and at rest.

Physical & Environmental Security: Our offices and data centers employ strict physical access controls, surveillance, and environmental safeguards to prevent unauthorized entry or disruption.

Vendor Risk Management: We evaluate and monitor third-party suppliers to ensure they maintain security standards equivalent to our own.

Incident Response: We maintain a formal Incident Response Plan to rapidly detect, contain, and remediate potential security events.

Continuous Improvement: We conduct regular internal audits, vulnerability assessments, and management reviews to continually mature our security posture.

 

 

5. Employee Responsibility

Security is a shared responsibility. All BM Castings personnel undergo mandatory, ongoing security awareness training. Staff are required to adhere to acceptable use guidelines, practice clean-desk habits, and immediately report any suspicious activity.

 

 

6. Artificial Intelligence (AI) Governance

We recognize the value of Artificial Intelligence (AI) in driving innovation and efficiency. To mitigate associated data privacy, intellectual property, and security risks, we manage AI adoption under the following guidelines:

 

Data Privacy & IP Protection: Employees and third parties are strictly prohibited from entering proprietary code, client data, or personally identifiable information (PII) into public, unvetted AI models.

Approved Tooling: We maintain an inventory of authorized AI tools and platforms that meet our corporate data protection standards.

Human Oversight: We ensure that AI-generated outputs, decisions, or code are always reviewed by competent personnel before deployment or implementation.

Ethics & Transparency: We strive to use AI responsibly, aiming for transparency in how AI interacts with or processes user data, in alignment with modern frameworks like ISO 42001.

 

 

7. Compliance & Governance

We commit to complying with all applicable legal, regulatory, and contractual obligations regarding data privacy and security. The executive leadership team reviews this policy annually to ensure its ongoing suitability, adequacy, and effectiveness.

 

 

Approved By:
Sergio Mendoza, General Manager

Last Updated: January 2nd, 2026