1. Protection of Information
CATEGORYMaintaining the confidentiality, integrity, and availability of the information and information assets managed by the organisation.
Effective date: 1 January 2024
PT Amboro Integrasi Teknologi Inovasi is committed to safeguarding information security as one of the organisation’s principal assets by operating an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 and the applicable laws and regulations.
In applying it, PT Amboro Integrasi Teknologi Inovasi establishes the following principles:
Maintaining the confidentiality, integrity, and availability of the information and information assets managed by the organisation.
Operating the ISMS in accordance with ISO/IEC 27001:2022, the applicable laws and regulations, and the information security policies and procedures in force.
Top Management demonstrates leadership and commitment in implementing and continually developing the ISMS.
Raising information security awareness, knowledge, and skills among employees and related parties. All parties are responsible for safeguarding information assets and complying with the information security provisions in force.
Identifying, assessing, and managing information security risks, taking into account the vulnerabilities and threats to the organisation’s assets and processes.
Any vulnerability or threat with the potential to disrupt information security must be reported to the Chief Information Security Officer (CISO) or the ISMS Team.
Leaders are responsible for monitoring and evaluating the effectiveness of the information security policy within their respective work units.
Breaches of the information security policy may be subject to action under the provisions in force. The organisation is committed to continually improving its implementation of the ISMS.
Technical policies and procedures relating to information security are established separately, with reference to the principles set out in this policy.