Effective: July 20, 2026
1. Management responsibility
Management establishes and continuously improves the information security framework.
2. Legal and contractual compliance
We comply with laws, regulations and contractual obligations related to information security.
3. Risk management
We identify information assets and implement technical and organizational measures based on risk assessment.
4. Access management
We prevent unauthorized access through least privilege, authentication and logging.
5. Incident response
When an incident occurs, we promptly assess impact, contain the issue, restore operations and prevent recurrence.
6. Training and improvement
We continuously conduct employee training, audits and reviews.
Contactsupport@first-step.co.th
