- Home
- Information Security Policy
INFORMATION SECURITY MANAGEMENT POLICY
Apex Equipment Co., Ltd. Information Security Management Policy Statement
POLICY STATEMENT
SECTION
01
Information Security and Customer Data Protection
Apex Equipment Co., Ltd. places great importance on information security and customer data protection and is committed to establishing, implementing, maintaining, and continually improving its information security management system to ensure the Confidentiality, Integrity, and Availability of the Company’s Information Assets, while safeguarding the rights and interests of employees, business partners, and customers.
SECTION
02
Alignment with the Information Security Management Principles of ISO 27001
The Company follows the information security management principles of ISO 27001 in managing electronic data, paper documents, information systems, network equipment, and related services. Information security risks are reduced through measures including Information Asset inventory, Risk Assessment, Access Control, Data Backup, Incident Reporting, Business Continuity Management, and education and training.
INFORMATION SECURITY MANAGEMENT MEASURES
Information Security Management Measures
01
Access Control
Implement the Principle of Least Privilege to reduce the risks of data leakage and misuse.
02
Data Backup and Recovery
Perform regular backup and recovery testing to ensure data availability.
03
Incident Reporting Mechanism
Establish an incident reporting process for abnormal events to strengthen timely response capabilities.
04
Education and Training
Strengthen employees’ information security awareness and ensure effective implementation of day-to-day information security management.
SECTION
03
Organization-Wide Implementation of Information Security Requirements
The Company requires all employees, outsourced service providers, and business partners to comply with applicable information security requirements and to implement the Principle of Least Privilege, personal data protection, and abnormal incident reporting mechanisms. For critical systems and data, the Company regularly performs backup and recovery testing and conducts Business Continuity exercises to ensure a rapid response and timely restoration of operations in the event of a major incident.
CONTINUAL IMPROVEMENT
Continual Improvement for a Trusted and Secure Service Environment
The Company regularly reviews the effectiveness of its information security management and continually strengthens its information security protection capabilities in accordance with regulatory requirements, changes in business operations, technological developments, and Risk Assessment results, thereby providing customers with a stable, reliable, and secure service environment.