Acquire Tech Co., Ltd. Information Security Policy
V1.0 - 2023/04/12Purpose
Acquire Tech Co., Ltd. (the “Company”) has established this Information Security Policy (the “Policy”) as the highest guiding principle of its Information Security Management System (“ISMS”). The Policy strengthens information security management and protects the confidentiality, integrity, and availability of Company information assets. It supports the information environment and architecture required for continued business operations, satisfies applicable legal requirements, and reduces the impact of intentional or accidental internal and external incidents.
Objectives
The Company’s information security objective is to ensure the confidentiality, integrity, availability, and compliance of important information and services. Quantitative performance indicators are defined and measured for each level and function to confirm ISMS implementation and determine whether information security objectives have been achieved.
Scope
Taking into account internal and external issues, the needs and expectations of interested parties, and the interfaces and dependencies between Company activities and those of other organizations, this Policy and the ISMS apply to the software development, operations, and operating environment of the FIRST LINE omnichannel service platform. This includes physical office areas, cloud systems, developers, software, operational data, system administration units, and related operating processes.
Applicable Parties and Responsibilities
- All internal personnel, service providers, visitors, and other parties within the applicable scope must comply with this Policy and all ISMS procedures.
- Any conduct that compromises information security may result in legal or administrative liability or disciplinary action under Company rules, depending on its severity.
Policy Coverage
To support and achieve this Policy, the Company establishes requirements for the following areas and regularly evaluates their implementation:
- Information security organization and management review procedures
- Document and record management
- Information security objectives and performance measurement
- Risk management
- Internal information security audits
- Continual improvement
- Human resources security management
- Asset management
- Access control management
- Physical and environmental security management
- Operational security and cryptography
- Communications security management
- System acquisition, development, and maintenance management
- Supplier relationship management
- Information security incident management
- Business continuity management
- Compliance management
Organization and Authority
To ensure effective ISMS operation, the Company defines its information security organization and responsibilities to support and maintain management, implementation, and audit activities.
Implementation Principles
The ISMS follows the Plan, Do, Check, and Act process model. This recurring, progressive approach ensures effective operation and continual improvement.
Review and Evaluation
- This Policy must be reviewed after significant changes and at least once each year to reflect current developments in applicable laws, technology, business, and related departments, and to maintain effective information security operations.
- The Policy will be revised according to review results and takes effect after approval and publication by the person responsible for the Company.
After an ISMS document, including this Policy, is established or revised, the Company will inform internal and external interested parties—including employees, customers, partners, and suppliers—through website announcements, email, communication software, the document management system, or another suitable communication method.