Security Management System
Ubie, Inc. obtained ISMS certification in October 2020 and has established and is operating our information security management as follows.
CEO
Our CEO is responsible for implementing the company's overall strategy, including information security and privacy protection, and has ultimate responsibility for promoting and executing the company's information security controls.
While the ultimate responsibility for information security and privacy rests with the CEO, the day-to-day operation of our information security management is delegated to two bodies, the Information Security Committee and the Personal Information Management Committee, with appointed heads in each committee responsible for operationalizing our commitment to earn and maintain the trust of our customers and stakeholders.
Information Security Committee
The Information Security Committee was established to deliberate and report on important matters concerning the protection of the Company's information assets, and to implement and promote various measures for the protection of information assets.
The Information Security Committee has the following responsibilities
- Management of the information security management program
- Enhance our information security management program to ensure that we continue to meet the expectations of our customers, stakeholders, and regulators
- Establish information security policies and various internal safety management standards and guidelines
- Provide and conduct information security training
- Conduct risk assessments to identify risks and provide recommendations and strategies to mitigate identified risks
- Maintain a good cybersecurity posture through review and ongoing monitoring