INFORMATION SECURITY
HOW WE ENSURE THE CONFIDENTIALITY OF OUR LANGUAGE AND COMMUNICATION SERVICES
SMG collects, processes, and stores information using an Internal Security System certified to ISO 9001:2015 and ISO 27001:2022 and designed to mitigate the risk of information being compromised, disclosed, or lost in a range of scenarios. The system includes, for example, backup measures, controlled access to operational facilities, and disaster recovery procedures.
The project manager responsible for the client’s project ensures that information is processed in compliance with applicable laws and regulations:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
- National legislation on information security in force in the countries where SMG and the client operate.
- Company protocol: ‘Confidentiality, Business Continuity, and Operational Contingency Plan.’
- Supplementary clauses, as set out in the client’s specifications.
- Provisions for handling information classified as confidential, strictly confidential, secret, and top secret, including, for example, specific Security Clearances and Industrial Security Clearances.
- Confidentiality clauses in personnel contracts.
SMG Languages, which bears full responsibility for protecting the information it receives, guarantees the utmost confidentiality in the provision of its language, translation, and communication services through a dedicated Internal Security System.
This system provides three levels of information and process management, set out below, to be agreed upon with the client according to their specific requirements.
STANDARD SECURITY PROCEDURE – PSO
This standard procedure applies when the client does not require language services subject to a security clearance or the Extraordinary Security Procedure. It provides for the following:
- Access to information and documentation provided by clients (including, for example, translations and supporting documents for interpreters) is restricted to authorized staff who have received appropriate training in data processing and the associated risks.
- Paper-based material is stored in a fireproof safe located in an armored security room.
- Digital material is managed via IT systems accessible only to holders of specific personal access credentials.
- Protection against internet threats, perimeter defense, and endpoint protection is provided by firewalls and antivirus software.
- Multi-level backup strategies (local, external, and remote): three backup systems for documentation and data are in place on dedicated internal servers, external physical media, and remote servers, with virtualization of work environments. This includes rapid data recovery capabilities and Disaster Recovery procedures.
Handling classified information
SMG Languages provides linguistic, translation, and interpreting services supported by systems and procedures that ensure the correct handling of information classified as ‘Confidential,’ ‘Strictly Confidential,’ ‘Secret,’ and ‘Top Secret’ or protected under NATO classifications (‘NATO Restricted,’ ‘NATO Confidential,’ ‘NATO Secret,’ and ‘Cosmic Top Secret’—NR, NC, NS, CTS) or corresponding classifications in other countries.
The security system is described in detail in the ‘Confidentiality, Business Continuity, and Operational Contingency Plan,’ which can be provided to the client upon request.
For the handling of information classified as ‘Strictly Confidential,’ the client may request the services of translators, interpreters, and staff holding a security clearance, as well as the use of a language management facility holding an Industrial Security Clearance.
EXTRAORDINARY SECURITY PROCEDURE
This procedure applies to linguistic, translation, interpretation, and communication services for which the client requires operational measures involving a high level of security. The client should be aware that such measures entail longer lead times and higher costs.
We recommend applying this procedure where the service requires, for example, the handling of information classified as Confidential, Strictly Confidential, Secret, or Top Secret, or other special confidentiality measures.
The main features of this operating procedure are as follows:
- The management of work subject to the extraordinary security procedure falls within the remit of the Extraordinary Security Officers (FSS), who are specifically selected from among our staff.
- The description of the extraordinary security procedure, access to the systems used, and access to the data and information processed are restricted to the FSS. The FSS maintain the confidentiality of the procedures and systems used, the information processed, and the identity of clients receiving services subject to the extraordinary security procedure.
- Information relating to the extraordinary security procedure is shared exclusively with clients upon formal written request.