If you move to, or primarily use Nu from, a different country or region, the Nu entity providing your services may change. As a result, your agreement may transfer to the relevant Nu entity, and different terms may apply, as outlined here.
Security at Nubank is managed by a robust governance structure, led by an executive and supported by specialized teams.This framework ensures that security responsibilities are clearly defined, implemented, and monitored throughout the organization, ensuring that all levels of the company are committed to the security of their data.
Guidelines
Access to systems, resources and other information assets must be granted through valid authentication and based on:
Access must be managed through a lifecycle from creation to deactivation, including periodic reviews for accuracy and adequacy;
Passwords must meet minimum complexity requirements and be unique. Passwords should not be reused, shared, stored in files, or written down anywhere.
Logs and audit trails must be enabled in production environments, protected from unauthorized access and changes, and record:
Tools and processes to monitor and prevent sensitive information from leaving an organization's internal environment without authorization must be implemented;
Security practices must be integrated into all phases of the product development lifecycle, from conception to implementation. This includes architectural reviews, code reviews, and continuous security testing to ensure our products are secure from the start..
A vulnerability lifecycle management process, from identification to remediation, including guidelines for documentation, reporting, and disclosure, must be in place;
Anti-malware detection, prevention, and recovery software solutions or equivalent controls must be implemented to protect the Nubank environment.
Information assets considered critical, which store and/or process sensitive information, must be restricted to segregated areas of the network, with appropriate access control;
Production databases must have sufficient backups to restore systems to operation in the event of data loss or service interruption;
A security assessment must be performed before implementing any new technology, tool or solution into production;
ASecurity assessments of our critical partners and suppliers must be carried out to ensure that they maintain a level of security compatible with our standards, extending security throughout our supply chain;
Information should be classified to assist in the consistent mapping of information assets and establish the appropriate level of protection in its storage, transmission, and use;
The Business Continuity Plan (BCP) aims to ensure that, in a crisis situation, essential and critical processes are properly maintained, thus preserving the continuity of business functions, operations, and critical services. The BCP must be tested annually.
Awareness training should be mandatory and conducted annually, presenting information security principles to help employees recognize risk situations and act correctly;
A continuous monitoring process and a structured incident response plan to quickly identify, contain, mitigate, and remediate cyber threats. To this end, procedures and controls are implemented to prevent and address vulnerabilities, as well as guidelines for recording, analyzing the cause and impact, and assessing the relevance of cybersecurity incidents. In the event of incidents with a significant impact on customers, communication will be transparent, with the provision of necessary guidance.
Consumption and sharing of incident and threat information with other local and global institutions must be done through secure channels;
Nubank's Cybersecurity Policy must be reviewed at least annually.
Security at Nubank is managed by a robust governance structure, led by an executive and supported by specialized teams.This framework ensures that security responsibilities are clearly defined, implemented, and monitored throughout the organization, ensuring that all levels of the company are committed to the security of their data.
Guidelines
Access to systems, resources and other information assets must be granted through valid authentication and based on:
Access must be managed through a lifecycle from creation to deactivation, including periodic reviews for accuracy and adequacy;
Passwords must meet minimum complexity requirements and be unique. Passwords should not be reused, shared, stored in files, or written down anywhere.
Logs and audit trails must be enabled in production environments, protected from unauthorized access and changes, and record:
Tools and processes to monitor and prevent sensitive information from leaving an organization's internal environment without authorization must be implemented;
Security practices must be integrated into all phases of the product development lifecycle, from conception to implementation. This includes architectural reviews, code reviews, and continuous security testing to ensure our products are secure from the start..
A vulnerability lifecycle management process, from identification to remediation, including guidelines for documentation, reporting, and disclosure, must be in place;
Anti-malware detection, prevention, and recovery software solutions or equivalent controls must be implemented to protect the Nubank environment.
Information assets considered critical, which store and/or process sensitive information, must be restricted to segregated areas of the network, with appropriate access control;
Production databases must have sufficient backups to restore systems to operation in the event of data loss or service interruption;
A security assessment must be performed before implementing any new technology, tool or solution into production;
ASecurity assessments of our critical partners and suppliers must be carried out to ensure that they maintain a level of security compatible with our standards, extending security throughout our supply chain;
Information should be classified to assist in the consistent mapping of information assets and establish the appropriate level of protection in its storage, transmission, and use;
The Business Continuity Plan (BCP) aims to ensure that, in a crisis situation, essential and critical processes are properly maintained, thus preserving the continuity of business functions, operations, and critical services. The BCP must be tested annually.
Awareness training should be mandatory and conducted annually, presenting information security principles to help employees recognize risk situations and act correctly;
A continuous monitoring process and a structured incident response plan to quickly identify, contain, mitigate, and remediate cyber threats. To this end, procedures and controls are implemented to prevent and address vulnerabilities, as well as guidelines for recording, analyzing the cause and impact, and assessing the relevance of cybersecurity incidents. In the event of incidents with a significant impact on customers, communication will be transparent, with the provision of necessary guidance.
Consumption and sharing of incident and threat information with other local and global institutions must be done through secure channels;
Nubank's Cybersecurity Policy must be reviewed at least annually.
Security at Nubank is managed by a robust governance structure, led by an executive and supported by specialized teams.This framework ensures that security responsibilities are clearly defined, implemented, and monitored throughout the organization, ensuring that all levels of the company are committed to the security of their data.
Guidelines
Access to systems, resources and other information assets must be granted through valid authentication and based on:
Access must be managed through a lifecycle from creation to deactivation, including periodic reviews for accuracy and adequacy;
Passwords must meet minimum complexity requirements and be unique. Passwords should not be reused, shared, stored in files, or written down anywhere.
Logs and audit trails must be enabled in production environments, protected from unauthorized access and changes, and record:
Tools and processes to monitor and prevent sensitive information from leaving an organization's internal environment without authorization must be implemented;
Security practices must be integrated into all phases of the product development lifecycle, from conception to implementation. This includes architectural reviews, code reviews, and continuous security testing to ensure our products are secure from the start..
A vulnerability lifecycle management process, from identification to remediation, including guidelines for documentation, reporting, and disclosure, must be in place;
Anti-malware detection, prevention, and recovery software solutions or equivalent controls must be implemented to protect the Nubank environment.
Information assets considered critical, which store and/or process sensitive information, must be restricted to segregated areas of the network, with appropriate access control;
Production databases must have sufficient backups to restore systems to operation in the event of data loss or service interruption;
A security assessment must be performed before implementing any new technology, tool or solution into production;
ASecurity assessments of our critical partners and suppliers must be carried out to ensure that they maintain a level of security compatible with our standards, extending security throughout our supply chain;
Information should be classified to assist in the consistent mapping of information assets and establish the appropriate level of protection in its storage, transmission, and use;
The Business Continuity Plan (BCP) aims to ensure that, in a crisis situation, essential and critical processes are properly maintained, thus preserving the continuity of business functions, operations, and critical services. The BCP must be tested annually.
Awareness training should be mandatory and conducted annually, presenting information security principles to help employees recognize risk situations and act correctly;
A continuous monitoring process and a structured incident response plan to quickly identify, contain, mitigate, and remediate cyber threats. To this end, procedures and controls are implemented to prevent and address vulnerabilities, as well as guidelines for recording, analyzing the cause and impact, and assessing the relevance of cybersecurity incidents. In the event of incidents with a significant impact on customers, communication will be transparent, with the provision of necessary guidance.
Consumption and sharing of incident and threat information with other local and global institutions must be done through secure channels;
Nubank's Cybersecurity Policy must be reviewed at least annually.
Security at Nubank is managed by a robust governance structure, led by an executive and supported by specialized teams.This framework ensures that security responsibilities are clearly defined, implemented, and monitored throughout the organization, ensuring that all levels of the company are committed to the security of their data.
Guidelines
Access to systems, resources and other information assets must be granted through valid authentication and based on:
Access must be managed through a lifecycle from creation to deactivation, including periodic reviews for accuracy and adequacy;
Passwords must meet minimum complexity requirements and be unique. Passwords should not be reused, shared, stored in files, or written down anywhere.
Logs and audit trails must be enabled in production environments, protected from unauthorized access and changes, and record:
Tools and processes to monitor and prevent sensitive information from leaving an organization's internal environment without authorization must be implemented;
Security practices must be integrated into all phases of the product development lifecycle, from conception to implementation. This includes architectural reviews, code reviews, and continuous security testing to ensure our products are secure from the start..
A vulnerability lifecycle management process, from identification to remediation, including guidelines for documentation, reporting, and disclosure, must be in place;
Anti-malware detection, prevention, and recovery software solutions or equivalent controls must be implemented to protect the Nubank environment.
Information assets considered critical, which store and/or process sensitive information, must be restricted to segregated areas of the network, with appropriate access control;
Production databases must have sufficient backups to restore systems to operation in the event of data loss or service interruption;
A security assessment must be performed before implementing any new technology, tool or solution into production;
ASecurity assessments of our critical partners and suppliers must be carried out to ensure that they maintain a level of security compatible with our standards, extending security throughout our supply chain;
Information should be classified to assist in the consistent mapping of information assets and establish the appropriate level of protection in its storage, transmission, and use;
The Business Continuity Plan (BCP) aims to ensure that, in a crisis situation, essential and critical processes are properly maintained, thus preserving the continuity of business functions, operations, and critical services. The BCP must be tested annually.
Awareness training should be mandatory and conducted annually, presenting information security principles to help employees recognize risk situations and act correctly;
A continuous monitoring process and a structured incident response plan to quickly identify, contain, mitigate, and remediate cyber threats. To this end, procedures and controls are implemented to prevent and address vulnerabilities, as well as guidelines for recording, analyzing the cause and impact, and assessing the relevance of cybersecurity incidents. In the event of incidents with a significant impact on customers, communication will be transparent, with the provision of necessary guidance.
Consumption and sharing of incident and threat information with other local and global institutions must be done through secure channels;
Nubank's Cybersecurity Policy must be reviewed at least annually.
Befreie dein Geld. Das ist Nu.