Purpose
This policy defines the principles for protecting customer and company information used in Advange’s managed IT services across Asia Pacific.
Our objectives are to protect confidentiality, integrity, and availability, support service continuity, and maintain customer trust.
Scope
This policy applies to the Advange entities and delivery teams that formally adopt it for their Asia Pacific operations. Each participating entity must document its covered services, locations, and accountable management.
Services in scope
- Help Desk Services
- IT Infrastructure Operations Services
(Including network operations, Microsoft 365 / workplace operations, SOC / security operations, cloud operations, SASE operations, etc.) - 120 Lower Delta Road #12-02 Cendex Centre Singapore 169208
Furthermore, this policy applies to our officers and employees (regardless of employment type), as well as to personnel of business contractors and partner companies who access our information assets.
Information Security Principles
In our company, "information security" refers to maintaining and ensuring the following three elements.
- Confidentiality
Limit access to authorized people with a legitimate business need. - Integrity
Protect information and systems against unauthorized changes, loss, or damage. - Availability
Maintain access to information and services in line with agreed business and recovery requirements.
Furthermore, this policy applies to our officers and employees (regardless of employment type), as well as to personnel of business contractors and partner companies who access our information assets.
Regional and Local Responsibilities
Regional coordination must support clear ownership and consistent practices across locations. It does not replace the responsibilities of individual legal entities or service owners.
- Accountable Management
Approve the applicable policy scope, provide resources, and review security performance. - Security Leads
Coordinate risk assessments, security controls, incident handling, and improvement activities. - Service Owners
Apply security requirements to delivery processes, access permissions, changes, and customer commitments. - Employees and Partners
Follow approved procedures, protect information, and promptly report suspected incidents.
Risk Management and Security Controls
Security risks must be assessed for the services, systems, information, and locations involved. Controls must reflect the assessed risk and applicable obligations.
Assessments must be reviewed when significant changes affect services, technology, suppliers, or business operations.
- Access Management
Grant permissions according to job responsibilities and business need. Review access regularly and update it when roles change or personnel leave. - Operational Security
Use documented procedures for configuration changes, monitoring, patching, and other activities within the agreed service scope. - Information Handling
Protect information during collection, use, storage, sharing, retention, and disposal. - Supplier and Partner Access
Define security responsibilities and access conditions before third parties handle customer or company information. - Physical Security
Protect facilities and equipment used to deliver services within the applicable scope.
Information Handling Across Locations
Regional collaboration must respect the requirements governing where information is stored, accessed, and processed.
Before enabling access or transfers across locations or borders, the responsible teams must assess applicable legal requirements, contractual restrictions, and customer approvals.
Access must be limited to authorized personnel and supported by appropriate controls and records. A shared regional delivery model does not automatically authorize unrestricted access to customer information.
Incident Management
Personnel must promptly report suspected or confirmed information security incidents through designated channels.
Responsible teams must assess severity and business impact, preserve relevant evidence, and coordinate investigation and response.
Containment actions must follow agreed procedures and authority. Customer communications and any required notifications must follow applicable obligations and contractual arrangements.
Regional handovers must identify the incident owner, actions taken, outstanding risks, and next steps.
Service Continuity
- Service teams must identify critical dependencies and document responsibilities for responding to disruptions.
- Recovery arrangements must reflect the agreed service scope and business requirements. Relevant procedures must be reviewed and tested as appropriate.
- Where delivery spans several locations, teams must maintain clear escalation contacts and handover arrangements.
Training and Awareness
Personnel must receive security guidance relevant to their responsibilities at onboarding and through regular refresher activities.
Training must help teams recognize risks, handle information appropriately, follow access controls, and report incidents. Guidance should be understandable to the personnel and locations concerned.
Compliance and Assurance
- Each participating entity must identify and comply with the laws, regulations, and contractual requirements applicable to its operations.
- Security objectives and controls must be reviewed through appropriate management oversight, assessments, and corrective actions.
- Any reference to ISO/IEC 27001 certification applies only to the entities, locations, and services listed in the relevant certificate. Certification must not be presented as automatically covering all Asia Pacific operations.
Continual Improvement
Audit findings, incidents, service reviews, and changes in risk must inform improvements to information security management.
Improvement actions must have clear owners and follow-up arrangements. Relevant lessons should be shared across regional teams while respecting confidentiality and access restrictions.
Policy Review
This policy must be reviewed at least annually and following significant changes to services, organizational responsibilities, legal requirements, or the threat environment.
Each adopting entity must record its approval, effective date, policy owner, and revision history.
- Date established:September 1, 2023
- Last revised:July 24, 2026
- ADVANGE PTE Ltd:Group President, Advange Shiyu Zheng

