1. Information is a primary asset in the business conducted by PT. Wook Global Technology. Therefore, confidentiality, integrity, and availability of information must be managed properly to ensure its security.
2. The implementation of the information security management system at PT. Wook Global Technology adheres to the ISO/IEC 27001:2022 standard and complies with applicable laws and regulations.
3. The top management of PT. Wook Global Technology consistently demonstrates leadership and commitment to implementing the information security management system within the organization.
4. The information security policy must be communicated to all employees and relevant third parties through existing communication channels so that it is easily understood and adhered to.
5. PT. Wook Global Technology will continuously strive to enhance awareness, knowledge, and skills regarding information security among internal employees and related external parties, as well as continuously improve the Information Security Management System (ISMS).
6. The company conducts assessments and manages risks related to information security based on vulnerabilities and threats to each asset and process.
7. If there are vulnerabilities and threats that may potentially compromise information security, all relevant parties are required to report them to PT. Wook Global Technology.
8. All leaders at every level are responsible for monitoring and evaluating the effectiveness of this policy's implementation across all departments/units under their supervision.
9. All employees are responsible for safeguarding and protecting the security of information assets and complying with the established information security policies and procedures.
10. Any violations of this policy and other related policies will result in administrative sanctions, such as revocation of system access rights and/or other disciplinary actions in accordance with applicable regulations.
11. More technical policies and procedures will be developed separately and established by referring to the principles set forth in this policy statement.