Cyber Security Group Policy 
AIS Group 

  1. Introduction
    Advanced Info Service Public Company Limited and Subsidiary Companies, as listed here (“Company”), recognize that cyber security is a fundamental foundation for operating telecommunications infrastructure businesses, providing digital services, and building trust among customers, business partners, shareholders, and all stakeholders.

    The Company is committed to protecting its data, information systems, computer systems, networks, applications, information technology infrastructure, digital services, and information assets from cyber threats. This commitment is guided by the principles of confidentiality, integrity, and availability of information and services, as well as the continuous enhancement of the Company’s capabilities to prevent, detect, respond to, recover from, and improve cyber security operations.

    This Policy is established to set out the Company’s enterprise-level approach to cyber security governance and management. It is based on the Company’s Cyber Security Group Policy and is aligned with relevant international and national frameworks, standards, and good practices, including the NIST Cybersecurity Framework (CSF) 2.0 and ISO/IEC 27001:2022. The Policy also supports the Company’s compliance with applicable laws, subordinate laws, regulatory requirements, and standards relevant to the Company’s business operations, including the Cybersecurity Act B.E. 2562 (2019).
    1. Objectives
      This Policy aims to establish the Company’s enterprise-level principles, approach, and framework for managing cyber security in an appropriate and effective manner, in alignment with the Company’s business operations, applicable laws, regulatory requirements, and relevant international standards.

      The Company emphasizes that cyber security shall be integrated as part of corporate governance, risk management, the design and development of digital services, human resource management, third party management, and the appropriate management of relevant information systems, data, and infrastructure.
    2. Scope
      This Policy covers cyber security matters relating to the Company’s data, information systems, computer systems, applications, networks, digital infrastructure, cloud services, and information assets, whether operated internally or involving services, connections, or interactions with third parties.

      This Policy serves as a guideline for directors, executives, employees, personnel, service providers, business partners, contractors, and third parties who connect to, access, use, process, or are otherwise involved with the Company’s data, systems, or information assets, within the scope and conditions determined by the Company.
    3. Security Principles

      The Company conducts its cyber security operations based on the following key principles:

      • Confidentiality – Protecting the confidentiality of information, including personal data, the Company’s information, and information under the Company’s responsibility, by preventing unauthorized access, use, or disclosure.
      • Integrity – Maintaining the accuracy, completeness, and reliability of information by preventing unauthorized alteration, modification, tampering, or destruction.
      • Availability – Supporting authorized users in accessing relevant information, systems, and services in an appropriate, continuous, and reliable manner, as necessary for their use.
    4. Policy Review

      The Company reviews its Cyber Security Group Policy and related documents at least annually or when there are significant changes in laws, regulations, rules, regulatory requirements, or cyber security standards that may affect the Company.

  2. Cyber Security Governance
    The Company establishes an appropriate cyber security governance structure to define direction, policies, roles, responsibilities, and mechanisms for monitoring cyber security performance across the organization.

    The Company defines the roles and responsibilities of committees, system owners, data owners, information technology functions, cyber security functions, data protection functions, and other relevant parties as appropriate, to support effective and auditable cyber security management.
  3. Regulatory and Compliance
    The Company is committed to conducting its cyber security operations in alignment with applicable laws, regulations, rules, regulatory requirements, contractual obligations, and standards relevant to the Company’s business operations at both national and international levels.

    The Company establishes an approach to monitor, review, and assess the impact of changes in applicable laws, requirements, and relevant standards, in order to keep its cyber security policies, standards, processes, and measures appropriate and up to date.

    The Company promotes the proper and appropriate use of data, information systems, computer systems, information assets, and intellectual property in accordance with applicable laws, requirements, and policies determined by the Company.
  4. Human Resource Management
    The Company recognizes the importance of managing cyber security matters related to personnel throughout the employment and engagement lifecycle, including prior to commencement of work, during employment or engagement, and upon termination or change of duties, to ensure that personnel have the knowledge, understanding, and awareness of their cyber security roles and responsibilities.

    Employees, personnel, and relevant parties are required to comply with the Company’s cyber security policies, standards, guidelines, and requirements, and to use the Company’s data, information systems, computer systems, and information assets in an appropriate, secure, and responsible manner in accordance with their roles and responsibilities.

    The Company promotes appropriate communication, education, and cyber security awareness activities to encourage personnel to participate in protecting the Company’s data, systems, services, and information assets from cyber threats.
  5. Third Party Management
    The Company requires service providers, business partners, contractors, and third parties that connect to, access, use, process, or are otherwise involved with the Company’s data, information systems, computer systems, or information assets to comply with relevant cyber security requirements.

    The Company manages cyber security risks associated with third parties throughout the business relationship lifecycle, including prior to procurement, during service provision or engagement, and upon termination or change of services. This is to ensure that the use of services, connections, or access to the Company’s data and systems is conducted in an appropriate and secure manner.

    The Company monitors and reviews compliance with relevant requirements as appropriate, in order to reduce risks that may affect the Company’s data, systems, services, customers, and stakeholders.
  6. Cyber Security Risk Management
    The Company establishes an approach to identify, assess, manage, and monitor cyber security risks on an ongoing basis, taking into consideration the business context, the criticality of data, information systems, computer systems, applications, infrastructure, services, and potential impacts on the Company, customers, and stakeholders.

    The Company manages cyber security risks to an appropriate level and in alignment with the Company’s risk appetite by defining controls, risk mitigation measures, monitoring activities, and risk reviews as appropriate.

    Cyber security risk management is integrated as part of the Company’s governance and enterprise risk management, supporting decision-making, prioritization of activities, and the continuous enhancement of the Company’s cyber security posture.
  7. Asset Management
    The Company establishes appropriate management of information assets, covering identification, inventory, assignment of ownership or accountability, and management of information assets throughout their life cycle.

    Information asset management shall take into consideration the criticality, sensitivity, and risks associated with data, information systems, computer systems, devices, infrastructure, and related resources, in order to define appropriate protection measures.

    Employees, personnel, and relevant parties are required to use the Company’s information assets for business purposes and comply with the Company’s cyber security policies, standards, guidelines, and requirements.
  8. Management of Technical Vulnerabilities
    The Company recognizes the importance of managing technical vulnerabilities in information systems, computer systems, applications, infrastructure, networks, and related devices in order to reduce risks from cyber threats and support the appropriate security of the Company’s systems and services.

    The Company establishes an approach for secure system configuration (System Hardening), vulnerability assessment, penetration testing, and patch management, taking into consideration the level of risk, system criticality, and potential impacts on business operations, customers, and stakeholders.

    The Company monitors, prioritizes, and manages the remediation of vulnerabilities or security weaknesses in accordance with the processes determined by the Company, in order to help reduce the likelihood of cyber security incidents and continuously enhance the security of its systems.
  9. Physical and Equipment Security
    The Company establishes physical and equipment security measures for data, information systems, computer systems, infrastructure, and critical services of the Company to prevent unauthorized access, use, alteration, damage, loss, or disruption to services.

    Such measures cover the protection of working areas, areas critical to service provision, equipment, supporting systems, and related environments, taking into consideration the criticality of data, systems, and services, in order to support security, availability, and continuity of business operations.
  10. Access Control Management
    The Company requires access to its data, information systems, computer systems, applications, networks, and information technology resources to be granted based on the need-to-know basis and the principle of least privilege, in order to prevent unauthorized access or use.

    The Company establishes an approach for identity and access management, password and authentication information management, remote access, network access control, and access to source code, taking into consideration roles and responsibilities, business needs, and the level of risk associated with the relevant data or systems.

    The Company performs the assignment, approval, review, update, and revocation of access rights in accordance with the processes determined by the Company, to ensure that access rights remain appropriate and up to date.
  11. Endpoint Security Management
    The Company establishes appropriate measures to protect endpoint devices and computer usage environments, in order to support secure access to the Company’s data, information systems, applications, and digital services.

    Such measures cover the secure use of devices and working areas, protection against malicious software, proper and lawful use of software for business purposes (Software Licensing), and the management of risks associated with mobile devices, working outside the Company’s premises, and remote working (Mobile Computing and Teleworking).

    Employees and relevant parties are required to use the Company’s devices, systems, and information assets in accordance with the Company’s cyber security policies, standards, and requirements, in order to help reduce risks to the Company’s data, systems, and services.
  12. Change Management
    The Company requires changes related to its information systems, computer systems, applications, networks, infrastructure, and digital services to be appropriately assessed, planned, approved, implemented, and monitored in order to control risks and reduce potential impacts on business operations, systems, services, customers, and stakeholders.

    Change management shall take into consideration cyber security requirements, system availability, service continuity, and the prevention of potential impacts arising from changes, in accordance with the processes and conditions determined by the Company.
  13. Application Security Management
    The Company establishes an approach for the secure development, management, and use of applications by considering cyber security requirements throughout the application life cycle, including design, development, testing, deployment, and maintenance.

    Such approach covers application security requirements, secure coding, separation of development, test, and production environments, as well as the management of risks associated with outsourced development, Application Programming Interface (APIs), and third party components.

    The Company emphasizes that its applications and digital services shall be designed, developed, and enhanced with consideration of security, privacy, reliability, and service availability, based on the level of risk and criticality of the relevant systems.
  14. Data Security Management
    The Company recognizes the importance of protecting the data of the Company, customers, business partners, employees, and stakeholders. The Company establishes an approach for managing data security in an appropriate manner, taking into consideration the criticality, sensitivity, risks, and relevant requirements associated with such data.

    Such approach covers data classification and handling, data encryption, protection of data at rest, protection of data in transit, data backup and restoration, information disposal, and the appropriate use of data for system testing, in order to prevent unauthorized access, disclosure, alteration, loss, or destruction of data.

    The Company manages data security throughout the data life cycle to maintain the confidentiality, integrity, and availability of data, and to support compliance with applicable laws, regulatory requirements, and standards relevant to the Company’s business operations.
  15. Infrastructure Security Management
    The Company establishes an approach for managing the security of information technology infrastructure, networks, cloud systems, supporting systems, and related environments that support the Company’s services and business operations, in order to ensure that systems and services are appropriately secure, reliable, and available.

    Such approach covers cloud security management, network security management, and logging and monitoring of events related to systems and services, taking into consideration the level of risk, system criticality, and requirements determined by the Company.

    The Company implements, monitors, and reviews infrastructure security measures as appropriate, in order to reduce risks from cyber threats and support the continuity of services provided to customers and stakeholders.
  16. Artificial Intelligence Security Management
    The Company establishes an approach for the secure, responsible, and compliant use, development, and management of artificial intelligence, in alignment with applicable laws, regulatory requirements, data policies, and relevant standards.

    Such approach covers the management of risks associated with the use of artificial intelligence, the protection of data used in AI-related systems or services, access control, appropriate use, and the prevention of potential impacts on the Company, customers, and stakeholders.

    The Company promotes appropriate governance over the use of artificial intelligence to support the adoption of such technology in business operations in a secure, transparent, reliable, and governed manner, in accordance with the governance principles determined by the Company.
  17. Awareness, Education and Training
    The Company promotes cyber security awareness, knowledge, understanding, and responsibility among employees, personnel, and relevant parties as appropriate, to support the secure performance of duties and the secure use of the Company’s data, information systems, computer systems, and information assets.

    The Company provides appropriate communication, education, and cyber security training, taking into consideration roles, responsibilities, job functions, and relevant risks, to support personnel in preventing, detecting, reporting, and responding to cyber security risks or incidents in an appropriate manner.

    The Company fosters a cyber security culture across the organization, recognizing that cyber security is a shared responsibility of everyone and an essential component in protecting the Company’s data, systems, services, customers, and stakeholders.
  18. Cyber Security Incident Management
    The Company establishes processes for monitoring, detecting, reporting, assessing, responding to, containing the impact of, and recovering from cyber security incidents in an appropriate manner, in order to reduce potential impacts on the Company’s data, information systems, computer systems, services, customers, and business operations.

    Cyber security incidents that occur or are likely to occur shall be managed in accordance with their severity, impact, and the processes determined by the Company. Coordination with relevant parties shall also be carried out as appropriate to ensure effective incident response and alignment with applicable requirements.

    The Company uses the outcomes of incident management, testing, and lessons learned to continuously improve its controls, response processes, and readiness to address cyber threats.
  19. Business Continuity Management
    The Company recognizes the importance of maintaining the continuity of business operations, critical services, information systems, computer systems, infrastructure, data, and resources necessary to provide services to customers and stakeholders. The Company establishes an approach for preparedness, response, and recovery in the event of incidents that may affect the Company’s operations.

    The Company considers cyber security risks as part of business continuity management, in order to support the availability and appropriate recoverability of critical systems, data, and services, and to reduce potential impacts on business operations, customers, and stakeholders.

    The Company reviews and improves its business continuity management approach related to cyber security as appropriate, to ensure alignment with changes in cyber threats, technology, business, laws, regulatory requirements, and relevant standards.

 

Last Update Date : 31 July 2026