Information Security Management System Based on ISO/IEC 27001:2022
We are committed to protecting the information and information assets owned, managed, or entrusted by our customers, partners, employees and other stakeholders to PT BNI Multifinance.
As a reflection of this commitment, we are fully committed to supporting the implementation and maintenance of the Information Security Management System (ISMS), adhering to the principles and requirements of the international standard ISO/IEC 27001:2022.
To fulfil this commitment, the Management of PT BNI Multifinance has established the following policies:
Maintain information confidentiality by ensuring that information is accessible only to authorized parties.
Maintain information integrity by ensuring that information remains accurate, complete, reliable and protected from unauthorized changes.
Maintain information availability by ensuring that required information, systems and services are available in a timely manner to support operational continuity.
Identify, assess and manage information security risks systematically based on the context, business needs and the Company’s acceptable risk level.
Comply with applicable legal, regulatory, contractual and other requirements related to information security, including but not limited to ISO/IEC 27001:2022, the Personal Data Protection Law, as well as relevant regulations and contractual obligations.
Implement appropriate information security controls across the people, process, technology and workplace environment aspects.
Enhance awareness and competence among all personnel to ensure they understand and fulfil their responsibilities in maintaining information security.
Protect information from various threats, including unauthorized access, use, disclosure, modification, loss, damage or disruption.
Ensure that information security is an integrated part of business processes, information technology management and the Company’s decision-making.
Conduct continuous evaluation and improvement on the effectiveness of the Information Security Management System to ensure it remains relevant to technological developments and information security threats.
Review and evaluate this Information Security Policy periodically or whenever significant changes occur in the business environment, technology, regulations or organizational structure.
This policy applies to all employees, outsourced personnel, consultants, vendors and other business partners who have access to the Company’s information. Every party is required to maintain the confidentiality of the information accessed and actively contribute to supporting the implementation of information security controls within PT BNI Multifinance. Any individual who violates this information security policy, whether intentionally or through negligence, may be subject to disciplinary action in accordance with internal company regulations and/or legal sanctions pursuant to the applicable laws of the Republic of Indonesia (including the ITE Law and the PDP Law).