Information Technology Security, Cybersecurity, and Artificial Intelligence Policy
Fortune Parts Industry Public Company Limited (the “Company”) recognizes the vital importance of Information Technology, Network Systems, and Artificial Intelligence (AI) as essential tools for enhancing organizational efficiency and operational excellence. Furthermore, the Company is committed to driving its business in the digital era by fostering innovation and creating value for all stakeholders, while ensuring the secure, ethical and responsible use of olata, systems, and Artificial Intelligece (AI), thereby supporting the organizatino’s sustainabie growth
the Company has established this Information Technology, Cybersecurity, and Artificial Intelligence Security Policy in compliance with relevant legal requirements and international standards. This policy aims to ensure that the utilization and management of such technologies remain secure, transparent, and reliable.
Objectives
- To establish an operational framework for information technology management, cybersecurity, and the utilization of Artificial Intelligence (AI) technology, in order to protect the Confidentiality, Integrity, and Availability (CIA) of the Company’s data and information assets.
- To prevent and respond to all forms of cyber threats, mitigate risks and impacts on the Company’s information assets to ensure security, and enable continuous business operations in alignment with the Company’s strategic objectives and goals.
- To govern the management of information technology, cybersecurity, and the utilization of Artificial Intelligence (AI) technology in compliance with the Computer-Related Crime Act B.E. 2550 (2007) and its amendments, the Cybersecurity Act B.E. 2562 (2019), the Personal Data Protection Act B.E. 2562 (2019) (PDPA), and other relevant laws and regulations.
- To align Information Technology management, Cybersecurity, and the utilization of Artificial Intelligence (AI) technology with international standards, such as the NIST Cybersecurity Framework, OECD AI Principles, and other relevant international best practices.
- To ensure that such operations align with the Company’s relevant regulations, policies, announcements, and directives, through the integration of information technology, cybersecurity, and Artificial Intelligence (AI) to support business operations and manage risks effectively, in accordance with the principles of Good Corporate Governance.
Scope of the Policy
- This policy applies to the Company’s Board of Directors, executives, and all employees, including entities under the Company’s management control. It further extends to all individuals within the supply chain associated with the organization’s assets and systems. This encompasses all information technology systems, data, digital assets, and any devices connected to the corporate network, regardless of the location or time of use.
- The Company promotes and supports the enhancement of awareness regarding information technology security, cybersecurity, and the utilization of Artificial Intelligence (AI) technology among the aforementioned groups. Any previous announcements, regulations, orders,
or guidelines that are inconsistent with or contradict this policy shall be superseded by this policy.
Definition
- “The Company/Organization” means Fortune Parts Industry Public Company Limited
- “Policy” means the principles concerning information technology security, cybersecurity, and artificial intelligence (AI) established by the Company, approved by the President and CEO, and signed into effect.
- “Guidelines” means the practices concerning information technology security management, cybersecurity, and the use of artificial intelligence (AI) technology that the Company has established and published for users to strictly adhere to.
- “Supply chain” means the network of relationships between the Company, its business partners, contractors of its business partners involved in the operation and management of information technology security, cybersecurity, and artificial intelligence (AI) of the Company, and related businesses under the Company’s management authority.
- “Information” means data, news, records, history, text in documents, computer programs, computer data, images, sounds, symbols, and various signs, whether stored in a format that can directly convey meaning to individuals, or through a computer, or by any other method that makes the recorded information visible.
- “Information system” means a system that collects, stores, processes, and distributes data to produce information that is useful for decision-making and operations of individuals or organizations. This system consists of several key components, including hardware, software, data, people, processes, and networks. Its primary function is to transform raw data into meaningful information to aid in management and achieve organizational goals.
- “Information technology” means technology used in business operations, which includes data or information, operating systems, application systems, database systems, computer and network equipment (hardware), and communication network systems, etc.
- “Information technology security” means protecting information systems and data to maintain confidentiality, integrity, and availability at all times, in order to prevent unauthorized access, alteration, or destruction of data, by employing various administrative, technical, and physical measures to address various threats.
- “Information technology security” means protecting information systems and data to maintain confidentiality, integrity, and availability at all times, in order to prevent unauthorized access, alteration, or destruction of data, by employing various administrative, technical, and physical measures to address various threats.
- “Information technology security” means protecting information systems and data to maintain confidentiality, integrity, and availability at all times, in order to prevent unauthorized access, alteration, or destruction of data, by employing various administrative, technical, and physical measures to address various threats.
- “Cybersecurity” means the measures or actions established to prevent, respond to, and mitigate risks from all forms of cyber threats, both internal and external to the Company, that affect the Company’s business operations, national security, economic security, military security, and internal peace and order.
- “Cyber threat” means any unlawful act or operation using a computer, computer system, or unwanted program with the intention of causing damage or malfunction to a computer system, computer data, or other related data, and which poses a danger affecting the functioning of the computer, computer system, or other related data.
- “Artificial Intelligence (AI)” means technology developed to enable computer processing systems, robots, machines, or various electronic devices to have properties or behaviors similar to humans, according to human-defined objectives, such as learning, perceiving and responding to the environment, reasoning, and problem-solving, etc.
- “Managing Director (MD)” means the individual authorized to approve, implement, and oversee this policy at the corporate level, as well as to consider resource allocation and significant review outcomes.
- “Information Technology Manager” means the individual primarily responsible for managing policies, work plans, control measures, risks, and security incidents, as well as reporting outcomes to executive management.
- “System Owner” means the individual responsible for the assigned work systems or information services, who is tasked with defining business requirements, criticality levels, and risks, as well as approving system access privileges within their scope of responsibility.
- “Data Administrator” means the individual responsible for data classification, ensuring data quality, defining access requirements, data retention, data destruction, and data protection in accordance with applicable laws and the Company’s policies.
- “System Administrator” means the individual responsible for system and infrastructure maintenance, user accounts, security configurations, data backups, event logging, and technical troubleshooting in accordance with approved privileges.
The main practices of the policy.
- The company will manage information technology security, cybersecurity, and the use of artificial intelligence in accordance with the guiding principles of government laws and regulations, the company’s relevant policies, and internationally recognized standards such as ISO/IEC 27001, NIST Cybersecurity Framework, and OECD AI Principles, etc.
- The Company has established guidelines regarding information security, cybersecurity, and the use of artificial intelligence (AI) to ensure that all stakeholders adhere to them in preventing threats and mitigating intruder risks in the use of the Company’s information technology, cybersecurity, and AI.
- The Company has established guidelines regarding information technology security, cybersecurity, and the use of artificial intelligence (AI) technology to support business development and manage risks appropriately and comprehensively, as follows:3.1 Establish a systematic management structure for information technology security, cybersecurity, and the utilization of Artificial Intelligence (AI) technology, by clearly defining individual roles and responsibilities. These include the Managing Director (MD), Information Technology Manager, System Owner, Data Administrator, System Administrator, Supervisors, Users, and the Internal Audit Department, to ensure that governance, approval, implementation, auditing, and improvement processes are executed effectively.
3.2 Establish risk identification, risk assessment, and the determination ofacceptable risk levels including risk management for information technology, cybersecurity, and the utilization of Artificial Intelligence (AI) technology. This is achieved by conducting surveys and maintaining an inventory of IT-related assets, while assessing risks that may impact the security of systems and data, to enable protective planning tailored to the risk levels and to effectively respond to potential future cyber threats.
3.3 Focus on utilizing control measures to prevent unauthorized access to or use of data, as well as preventing data loss or destruction, through the adoption of appropriate technologies,
such as Access Control, Endpoint Protection, and data encryption, alongside providing continuous training to enhance employee awareness of information technology, cybersecurity, and the utilization of Artificial Intelligence (AI) technology.3.4 Establish systems and processes for monitoring and detecting anomalies, managing information security breaches, or potential cyber threats within information technology systems in real-time, using tools capable of cyber threat analysis and early warning.
This enables timely response and risk management, minimizes potential impact on the organization, and continuously improves processes for efficiency. The system should be able to limit the scope, resolve, mitigate, and remedy impacts, as well as recover business operations and information assets in a timely manner.3.5 Establish guidelines and response plans for cyber threats and the utilization of Artificial Intelligence (AI) technology, covering threat levels, notification processes, investigation, impact containment, system recovery, and reporting. The IT Manager shall serve as the primary coordinator, collaborating with system owners, data custodians, and system administrators
3.6 Establish a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP) to enable the organization to resume operations quickly and continuously following a cyber threat.
This includes a process for regular review and revision of the recovery plans, and systematically incorporating lessons learned from past incidents to improve management practices. - The Company establishes guidelines for the utilization of Artificial Intelligence (AI) technology in alignment with ethical standards, legal frameworks, and appropriate practices, ensuring auditability in accordance with the OECD AI Principles.
- The Company mandates regular awareness-raising processes regarding information technology security, cybersecurity, and the responsible utilization of Artificial Intelligence (AI) technology for the Board of Directors, executives, Company personnel, entities under the Company’s management control, as well as stakeholders across the supply chain
Policy Governance and Review
The Company designates responsible individuals for the governance of and compliance with this policy as follows:
- Managing Director (MD): Approves and implements the policy; ensures the provision of adequate resources, reviews risk assessment results, monitoring results, of the significant incidents; and approves improvement guidelines that have a corporate-level impact.
- Information Technology Manager: Serves as the process owner for the information security management process; develops work plans, Standard Operating Procedures (SOPs), forms, evidence registries, risk management plans, and communication plans; and reports status updates to the Managing Director (MD).
- System Owner: Defines the scope and security requirements of the system; assesses and accepts associated risks; approves system access; reviews user privileges; and participates in the testing of system backup and recovery plans.
- Data Administrator: Develops and reviews data classification; defines requirements for data usage, disclosure, retention, and destruction; controls critical data inventories; and supports compliance with personal data protection laws.
- System Administrator: Configures and controls systems in accordance with approved authorizations; manages user accounts, performs data backups, applies patches, reviews event logs, and immediately reports anomalies to the Information Technology Manager.
- Supervisors: Clarify, promote, and monitor users under their supervision to ensure compliance with the Information Technology Security Policy, as well as issue warnings or initiate disciplinary actions in accordance with the Company’s regulations upon detecting any improper or inappropriate practices.
- Users: Must study, understand, and strictly comply with the Company’s Information Technology Security Policy; cooperate in safeguarding computer systems and information; remain vigilant in protecting the Company’s data; and immediately report any loss of equipment or critical data, intrusions, theft, destruction, information theft, or any incidents that could potentially cause damage to the Company.
- Internal Audit Department: Establishes and executes audits of management, operations, and practices related to information security as necessary, as well as reports audit findings and monitors corrective actions to ensure completion in accordance with the plan.
- Mandate that this policy, related guidelines, and associated documentation be reviewed at least once a year, or upon significant changes in laws, technology, threats, organizational structure, or audit findings. The Information Technology Manager shall compile the review outcomes and submit them to the Managing Director (MD) for consideration and approval.
Penalties
Any individual who violates, breaches, or fails to comply with this policy will be subject to disciplinary action in accordance with the Company’s working regulations. Furthermore, if such action constitutes a violation of applicable laws, the individual may also be subject to legal penalties.
Therefore, this announcement is made for acknowledgment and strict compliance by all concerned. Announced on July 1, 2026.
![]()
