Information Security Policy
Xilnex Holdings Sdn Bhd is committed to protecting the confidentiality, integrity, availability, and privacy of its information assets and business processes. This commitment helps minimise disruptions, safeguard operations, and ensure the delivery of secure and reliable solutions to our customers.
Xilnex upholds the following information security principles:
Confidentiality
Only authorised individuals can access sensitive data.
Integrity
Information is accurate and protected from unauthorised modification.
Availability
Information is accessible to authorised users when needed.
Through the implementation of the Information Security Management System (ISMS), Xilnex aims to:
- Protect information assets from internal and external, deliberate and accidental threats.
- Comply with applicable legal, regulatory, and contractual requirements.
- Establish a framework for setting, reviewing, and achieving ISMS objectives.
- Satisfy applicable requirements related to information security.
- Promote information security awareness and competence among all employees.
- Continually improve the effectiveness of the ISMS in support of business objectives.
Xilnex Roles and Responsibilities
Top Management
Provides leadership, direction, resources, and commitment to establish, implement, maintain, satisfy, and continually improve the ISMS in accordance with ISO/IEC 27001:2022.
Information Security Compliance Officer (ISCO)
Responsible for implementing, operating, monitoring, and maintaining the ISMS, including the development and enforcement of information security policies and controls.
Employees / Contractors / Third Parties
Are required to comply with this policy and related procedures and contribute to maintaining a secure information environment.
This policy is maintained as documented information, communicated within the organisation, and made available to relevant interested parties as appropriate.
