top of page
Asimar%20Logo_edited.jpg

              บริษัท  เอเชียน มารีน เซอร์วิสส์ จำกัด (มหาชน)

   ASIAN MARINE SERVICES PUBLIC COMPANY LIMITED

Information and Communication Security Policy

 

  1. Purpose

  1. To establish policies, guidelines, requirements, and operating procedures to ensure that executives, officers, system administrators, and external personnel working with Asian Marine Services Public Company Limited understand the importance of information security and safety and comply with them appropriately.

  2. To build confidence in the organization’s information security, ensuring that it is accessible only by authorized persons (Confidentiality), is accurate and complete (Integrity), and is available for utilization (Availability).

  3. To disseminate this policy to officers and information users of Asian Marine Services Public Company Limited for strict compliance.

  1. Scope

  1. Establish a written information security policy with guidelines, requirements, and operational procedures for maintaining information security, in compliance with applicable laws, and international standard principles of information security.

  2. Provide information, information technology systems, information technology equipment, premises and environments related to information, and the development and maintenance of information systems, along with anything related to information, with appropriate and sufficient security, and with clearly defined access controls based on the principles of appropriate and secure operational needs.

  3. Provide a data backup system, a data recovery system, and a backup system to substitute primary information technology systems in case of emergency. The backup system must be readily available, and an emergency preparedness plan should be in place.

  4. Conduct regular information risk assessments aligned with the IT department’s risk management approach.

  5. Ensure that inspections and corrective actions are carried out when security breaches occur, implement preventive measures to prevent recurrence, and maintain clear records and reports.

  6. Provide users with information on policies, guidelines, standards, and regulations related to information security, whereby users must adhere to and strictly comply with them

 

Information Access Control Policy

Asian Marine Services Public Company Limited maintains controls over the use and access of information and information systems, in order to define control measures against unauthorized access to information and information systems, protect against physical and network-based intrusions, and safeguard against programs that could damage data or disrupt operations, and to be able to accurately verify and track the authentication of individuals accessing organizational information or information systems, based on the following principles:

  1. Confidentiality: Allowing only authorized personnel to access information, and maintaining access control so that confidential information will not be disclosed to unauthorized persons.

  2. Integrity: Maintaining the accuracy and completeness of data, and controlling errors so that data is not modified, deleted, or changed by unauthorized persons.

  3. Availability: Allowing only authorized users to be able to access data according to the agreed time. Responsible parties must control the system from disruption, maintain continuous operational performance, and prevent anything from causing the system to stop functioning.

Objectives of Information Access Control

  1. To establish guidelines, requirements, and procedures to ensure that executives, officers, system administrators, and external personnel working with the organization understand the importance of using and accessing the organization’s information and information systems.

  2. To build confidence in the organization’s information security, ensuring that it is accessible only by authorized persons (Confidentiality), is accurate and complete (Integrity) and is available for utilization (Availability).

  3. To allow tracking of user access to various information systems.
     

Guidelines

  1. Provide written guidelines and operating procedures for the use and access of information and information systems, in compliance with applicable laws, principles, and international standard principles of information security.

  2. Provide information, information technology systems, information technology equipment, premises and environments related to information, and the development and maintenance of information systems, along with anything related to information, with appropriate and sufficient security, and with clearly defined access controls based on the principles of appropriate and secure operational needs.

  3. Provide guidelines for software development that govern access control and data usage rights within the system, extending to operating system-level access controls, and encompassing information use across all parts of the user’s computer.

  4. Provide guidelines for controlling access to computers and information equipment.

  5. Provide guidelines for controlling access to the network server room or internet data center, including information technology equipment, allowing entry only for authorized personnel.

  6. Provide users with knowledge of policies, requirements, guidelines, regulations, and operating procedures concerning the use of data and information systems. Users must strictly adhere to and comply with them.

All right Reserved © 2016 by Asimar

bottom of page