Information Security Policy
SHANNON LIMITED LIABILITY COMPANY (hereinafter, "we" or "the Company") recognizes the importance of the information assets entrusted to us by our customers and the information assets we handle in the course of our work, and we believe that protecting them appropriately is our social responsibility. This policy sets out the basic principles behind our approach to information security.
1. Objective of Information Security
By maintaining the confidentiality, integrity, and availability of information assets, we aim to earn our customers' trust and achieve the continued development of our business. This is the objective of our information security efforts.
2. Scope
This policy applies to all information assets handled by our officers and employees (including subcontractors) and to the information systems that handle those information assets.
3. Legal Compliance
We comply with laws, regulations, contractual obligations, and other social norms relating to information security.
4. Organizational Measures
We clearly define the lines of responsibility for advancing information security and carry out regular reviews and improvements. We provide ongoing information security education and awareness for our officers and employees.
5. Technical Measures
Against risks such as unauthorized access, malware infection, and information leakage, we implement technical measures including authentication, encryption, access control, and log auditing. When using cloud services, we also manage them according to their particular characteristics.
6. Physical Measures
For the devices and storage media used in our work and for our working environment, we implement physical measures to prevent loss, theft, and unauthorized use.
7. Management of Subcontractors
When outsourcing work, we require subcontractors to maintain a level of information security equivalent to our own, and we manage them appropriately through contracts and supervision.
8. Handling of Entrusted Information Assets
We handle source code, credentials, data, and other information assets entrusted to us by customers only within the scope and for the period necessary for our work. After delivery and acceptance are complete, and upon the expiry of the retention period agreed with the customer, we reliably destroy any copies under our control. The timing and method of return or destruction follow the contract or the customer's instructions.
9. Incident Response
If an information security incident occurs, we promptly assess the situation, work to minimize damage and prevent recurrence, and provide appropriate reports to relevant parties and authorities.
10. Continuous Improvement
To respond to information security threats and changes in the business environment, we periodically review this policy and the related controls and pursue continuous improvement.