Importance

The Company recognizes that information and information systems are vital business assets. Protecting personal data and confidential business information is therefore essential to maintaining stakeholder trust and ensuring business continuity. The Company is committed to strengthening cybersecurity and data protection measures to prevent unauthorized access, disclosure, alteration, misuse, and cyberattacks that could impact its operations, customers, and corporate reputation.

Information Technology Security Policy

Mission

  • Strengthen information security and personal data protection frameworks in compliance with applicable laws, regulations, and internationally recognized standards. 
  • Prevent and mitigate risks arising from cyber threats, information security incidents, and personal data breaches. 
  • Promote cybersecurity and data privacy awareness and enhance employee knowledge and capabilities through ongoing training and engagement programs. 
  • Develop effective information security incident management and incident response processes to ensure timely detection, response, and recovery. 
  • Build and maintain the trust and confidence of customers, business partners, and other stakeholders in the Company’s products, services, and digital platforms.

Targets

  • Achieve zero material personal data breach incidents. 
  • Achieve zero material cyberattack or cybersecurity incidents. 
  • Maintain PDPA and cybersecurity risks within the Company’s approved risk appetite and tolerance levels. 
  • Deliver ongoing cybersecurity and data privacy awareness programs to enhance employees’ knowledge and capabilities.

Key Performance Highlights

Performance Indicators 2023 2024 2025 Target
Number of Material Personal Data Breach Incidents (Cases) 0 0 0 Zero cases
Number of Material Cybersecurity Incidents (Cases) 0 0 0 Zero cases
PDPA Risk Level Within the acceptable risk level Within the acceptable risk level Within the acceptable risk level Maintain within the Company’s approved risk appetite
Cybersecurity Risk Level Within the acceptable risk level Within the acceptable risk level Within the acceptable risk level Maintain within the Company’s approved risk appetite
Governance Structure
Board of Directors Oversees and sets the strategic direction for cybersecurity and personal data protection management to ensure alignment with the Company’s strategy and enterprise risk management framework, including ensuring that appropriate internal control systems are in place and operating effectively.
Audit Committee Oversees the adequacy and effectiveness of internal controls and information technology risk management, reviews audit findings, and provides recommendations to strengthen cybersecurity and personal data protection measures.
Risk Management Committee Oversees and monitors cybersecurity and data protection risks, assesses risk levels, and establishes risk management approaches to prevent and mitigate potential impacts on business operations.
Internal Audit Department Reviews and evaluates the adequacy and effectiveness of internal controls relating to information technology, cybersecurity, and personal data protection, and reports findings and recommendations to the Audit Committee and management.

Management Approach

Process Management Approach
Risk Identification Conduct regular assessments of cybersecurity and data privacy risks.
Protection Implement access controls, password management, and information security control measures to safeguard information assets and personal data.
Monitoring Continuously monitor and review cybersecurity events and information security activities.
Incident Response Establish processes for managing and reporting cybersecurity incidents and personal data breaches, including incident response procedures, business continuity plans, and disaster recovery plans to ensure systematic responses and minimize impacts on stakeholders.
Awareness and Training Communicate and provide regular training to employees on cybersecurity and data protection practices.

Enhancing Awareness of Personal Data Protection and Cybersecurity

Topic Implementation Monitoring and Evaluation
Personal Data Protection (PDPA) Regularly communicate and review personal data protection requirements with relevant stakeholders to ensure compliance with applicable laws and standards. Personal data protection is included as one of the Company’s key risk areas and is monitored through Key Risk Indicators (KRIs), including the number of material personal data breach incidents. Performance is regularly reported to the Board of Directors.
Cybersecurity Provide annual cybersecurity awareness training to employees to enhance knowledge and promote a strong cybersecurity culture across the organization. Cybersecurity is included as one of the Company’s key risk areas and is monitored through Key Risk Indicators (KRIs), including the number of material cybersecurity incidents. Performance is regularly reported to the Board of Directors.

Business Continuity Plan (BCP)

The Company has implemented a Business Continuity Plan (BCP) to prepare for potential disruptions and crisis events that could impact its operations. The plan aims to protect stakeholders, maintain critical business activities, and ensure the rapid recovery of operations. It covers key scenarios, including natural disasters, pandemics, information technology disruptions, and cyber threats, and is regularly reviewed and updated to strengthen organizational resilience and business continuity.

Risk Assessment Business Impact Analysis (BIA) Resource Preparedness Response and Recovery Testing and Review
Risk Assessment Business Impact Analysis (BIA) Resource Preparedness Response and Recovery Testing and Review
Identify, assess, and analyze risks that may affect business operations, and establish appropriate mitigation and risk reduction measures. Analyze the potential impacts of business disruptions to determine the criticality of business processes and establish appropriate recovery priorities and strategies. Prepare the resources required to ensure business continuity, including alternate work locations, personnel, information technology systems, critical data, suppliers, and financial resources. Establish incident response procedures, business continuity plans, and recovery plans to ensure that critical business operations can be restored within an acceptable timeframe. Regularly test, review, and improve the Business Continuity Plan to ensure organizational readiness and the ability to respond effectively to crisis situations and business disruptions.

Relevant Stakeholders

Related Documents

Information Technology Security Policy

Personal Data Protection Policy

Privacy Policy