
ISMS Commitment
Our leadership commitment to risk-focused information security and continual improvement.
Commitment to the ISMS
Sin-Yun is committed to establishing and maintaining its Information Security Management System. We demonstrate leadership by championing the importance of information security through well-designed policies and strategic direction, allowing information security to become ingrained in Sin-Yun’s culture.
Sin-Yun applies the following principles throughout the organisation, including external vendors and suppliers:
- Adopt a risk-focused methodology and establish a risk-aware culture for identifying threats, classifying information assets and remediating weaknesses affecting the confidentiality, integrity and availability of client, employee and company data.
- Comply with applicable regulatory frameworks and reinforce our information security posture by adopting international norms and standards such as ISO/IEC 27001:2022.
- Uphold corporate information security when establishing and maintaining relationships with external parties.
- Create and maintain a strong information-security-conscious culture.
- Satisfy applicable information security requirements.
- Continuously improve the effectiveness of information security training and awareness.
Sin-Yun takes its information security responsibilities seriously. Breaches of ISMS procedures may lead to disciplinary action and may also contravene applicable laws and regulations. Serious breaches that expose Sin-Yun to financial, commercial or reputational risk or loss may be treated as gross misconduct.
ISMS 承诺
Sin-Yun 致力于建立并持续维护信息安全管理体系。我们通过完善的政策和战略方向,强调信息安全的重要性,使信息安全融入公司的文化与日常运营。
Sin-Yun 在整个组织以及外部供应商和合作方中贯彻以下原则:
- 采用以风险为重点的方法,识别威胁、分类信息资产,并修复影响客户、员工及公司数据机密性、完整性和可用性的弱点。
- 遵守适用的监管框架,并采用 ISO/IEC 27001:2022 等国际规范和标准。
- 在建立和维护外部关系时维护公司的信息安全要求。
- 建立并保持高度的信息安全意识文化。
- 满足适用的信息安全要求。
- 持续改进信息安全培训和意识计划的有效性。
Sin-Yun 严肃履行信息安全责任。违反 ISMS 程序可能导致纪律处分,并可能违反适用的法律和法规。