GOVERNANCE
Information Security Promotion Measures
Information Security Policy and Organization
Pan Ocean’s information security organization is responsible for creating and reporting security plans, checking and monitoring information security activities, and overall security operations of the company. The Chief Information Security Officer (CISO) and the Chief Privacy Officer (CPO) are responsible for stable security system operations. We are a member of the CISO Council, and we have inhouse staff dedicated to information technology and information protection. Recently, we have introduced a range of solutions for privacy and established a stable information security system by taking advantage of professional maintenance services.
Building the Information Security Infrastructure
-
Technical security
We employ a range of technical security solutions to protect ourselves from external attacks such as hacking, malware, and ransomware and prevent information leaks from our internal networks and systems, including firewalls and web firewalls, document encryption, and database access control. We have upgraded security patches for our servers and workstations regularly in order to further strengthen the security system.
-
Administerial security
We systemically manage and monitor the security policy and regulations. This involves establishing and revising detailed guidelines and updating them regularly for improvements. We also conduct user security drills (participate in KISA simulation tests) to improve employees’ ability to respond to cybersecurity breaches and to raise security awareness.
-
Privacy Protection Activities
As the risk of personal information infringements increases, we are carrying out the following activities to improve the level of personal information protection.
- Establishment and reporting of personal information protection activities and improvement plans
- Implementation of personal information protection training
- Activities to secure personal information safety
- Sign up for personal information liability insurance
-
Information Security Disclosure
In 2022, we started disclosing key information regarding security details on our information security disclosure portal.
In 2023, we focused on new investing in SIEM(Security Event and Incident Management) and replacing the WAF(Web Application Firewall), DLP(Data Loss Prevention)
We continuously subscribe to personal information liability insurance.- KRW 666 million