IR
From Power Plants and Refineries to Aerospace,
we deliver advanced, sustainable engineering solutions across Energy, Chemical, Hydrogen, and Aviation.
Purpose
This policy aims to comply with relevant laws and regulations, such as the Personal Information Protection Act, and to establish the fundamental principles of information security that employees must adhere to in order to protect Caelum Co., Ltd.'s information assets from threats such as damage, alteration, theft, and leakage.
Information Security Policy
Purpose-Bound Use: Personal information and trade secrets shall be used only within the scope necessary for business purposes.
Access Control: Access permissions to information assets shall be granted solely on a need-to-know basis for business execution.
Prohibition of Unauthorized Leakage: Employees shall not remove or disclose the Company’s information assets externally without authorization.
Protective Measures: The Company implements necessary security controls to prevent malware, unauthorized access, and data leaks.
Incident Reporting: Employees who discover an information security incident must promptly report it to the designated department or person in charge.
Revocation of Access: Unnecessary access permissions shall be revoked immediately upon an employee's resignation or job transfer.
Scope of Application
Applicability: This policy applies to all employees of Caelum Co., Ltd.
External Personnel: Necessary information security measures may be applied to external personnel accessing the Company's information assets, based on contract terms and the nature of their work.
Definitions
Information Assets: Refers to documents, data, personal information, trade secrets, intellectual property, information systems, and other tangible or intangible assets owned or managed by the Company for business purposes.
Information Systems: Refers to computers, servers, networks, software, and related equipment used to collect, process, store, and transmit the Company's information.
Information Security Incident: Refers to an event where the confidentiality, integrity, or availability of the Company's information assets is compromised, such as through unauthorized access, leakage, alteration, damage, or loss.
Responsibilities
Designated Personnel: The Company may designate a department or person in charge of executing information security operations.
Employee Compliance: Employees are responsible for protecting the Company’s information assets and complying with relevant laws and internal information security standards.
Policy Review: The Company may review the adequacy of this policy whenever significant changes occur in relevant laws, organizational structures, or the IT environment.