General Policy

Effective date: 1 January 2024

General Information Security Policy

PT Amboro Integrasi Teknologi Inovasi is committed to safeguarding information security as one of the organisation’s principal assets by operating an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 and the applicable laws and regulations.

In applying it, PT Amboro Integrasi Teknologi Inovasi establishes the following principles:

1. Protection of Information

CATEGORY

Maintaining the confidentiality, integrity, and availability of the information and information assets managed by the organisation.

2. Compliance and Governance

CATEGORY

Operating the ISMS in accordance with ISO/IEC 27001:2022, the applicable laws and regulations, and the information security policies and procedures in force.

3. Management Commitment

CATEGORY

Top Management demonstrates leadership and commitment in implementing and continually developing the ISMS.

4. Awareness and Responsibility

CATEGORY

Raising information security awareness, knowledge, and skills among employees and related parties. All parties are responsible for safeguarding information assets and complying with the information security provisions in force.

5. Risk Management

CATEGORY

Identifying, assessing, and managing information security risks, taking into account the vulnerabilities and threats to the organisation’s assets and processes.

6. Security Incident Reporting

CATEGORY

Any vulnerability or threat with the potential to disrupt information security must be reported to the Chief Information Security Officer (CISO) or the ISMS Team.

7. Monitoring and Evaluation

CATEGORY

Leaders are responsible for monitoring and evaluating the effectiveness of the information security policy within their respective work units.

8. Enforcement and Continual Improvement

CATEGORY

Breaches of the information security policy may be subject to action under the provisions in force. The organisation is committed to continually improving its implementation of the ISMS.

Technical policies and procedures relating to information security are established separately, with reference to the principles set out in this policy.