Our Cybersecurity Programme
Our approach comprises a comprehensive set of risk management framework, policies and standards. These incorporate key regulatory expectations and align with international industry guidance on key areas such as risk management practices, information security and cyber resilience. They are reviewed regularly and approved by relevant risk committee such as the Group Information Security and Digital Risk Management Committee and Board Risk Management Committee.
Information Security and Digital Risk Policy |
This Policy establishes the control expectations from organisational responsibilities to specific information security and digital risk (including technology and cyber risks) domains to manage risk arising from internal and external threats to the Group’s information assets and personnel. These control expectations are stipulated with the intention of ensuring the confidentiality, integrity and availability of the Group’s information assets. |
Acceptable Use Sub-Policy |
This Policy defines the proper conduct and use of the Group’s information assets (encompassing technology equipment, information and software services), as well as communication services. |
Information Classification and Handling Sub-Policy |
This Policy establishes the control expectations for ownership, classification, and handling of information to protect them from unauthorised access and disclosure. |