Information Security Policy of PT CRIF Lembaga Informasi Keuangan

 

Purpose

The Information Security Policy of PT CLIK aims to:

  1. protect information and information assets from information security threats and risks;
  2. maintain the confidentiality, integrity, and availability of information;
  3. support the continuity of PT CLIK’s operational activities and services;
  4. fulfill relevant legal requirements, laws and regulations, and contractual obligations; and
  5. enhance the trust of customers and interested parties in PT CLIK’s information security management.
Scope

This policy applies to the management of information and information assets used in PT CLIK’s operational activities and service provision, including personnel, processes, technology, and third parties related to the management of or access to PT CLIK’s information.

PT CLIK’s Commitment

In implementing information security, PT CLIK is committed to:

  1. Implementing and maintaining an Information Security Management System (ISMS) that refers to ISO/IEC 27001:2022;
  2. Systematically managing information security risks by considering business needs, threats, vulnerabilities, and impacts on information and services;
  3. Fulfilling legal, regulatory, and contractual requirements relevant to information security;
  4. Protecting information based on the level of security needs and associated risks;
  5. Enhancing the awareness and competence of personnel in maintaining information security;
  6. Implementing appropriate safeguards for information, systems, technology, processes, and resources used in operational activities;
  7. Managing and handling information security incidents in a timely manner and in accordance with their level of risk and impact;
  8. Managing information security risks related to third parties involved in service provision or information management;
  9. Conducting regular monitoring, evaluation, and audits of information security implementation;
  10. Conducting management reviews of the effectiveness of the Information Security Management System;
  11. Considering the needs and expectations of interested parties in information security management; and
  12. Carrying out continuous improvement and enhancement of the Information Security Management System.
Responsibility

Information security is the shared responsibility of all PT CLIK personnel and related parties who have access to, or responsibility for, information and information assets.

PT CLIK’s management is committed to providing the direction, resources, and support necessary to ensure that information security is implemented effectively and in alignment with the Company’s business objectives.

Compliance and Continuous Improvement

PT CLIK periodically evaluates the implementation of information security through monitoring, risk assessment, audits, management reviews, and corrective actions.

The results of these evaluations are used as a basis for improving the effectiveness of the Information Security Management System and ensuring that its implementation remains relevant to changes in risk, business needs, regulatory requirements, technology, and the needs and expectations of interested parties.