Information Security Management System (ISMS) Policy 

ISMS 27001 Xenber

We, at Xenber Sdn Bhd, are committed to protecting confidentiality, integrity, and availability of information assets to ensure business continuity, minimize information security risks, and comply with legal, regulatory, and contractual obligations.  

 We have established, implement, maintain, and continually improve an Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 requirements.  

Our ISMS framework will support the organization’s strategic objectives and ensure that information security is embedded in all processes.  

  • eXpress commitment in complying with applicable legal, regulatory, and contractual information security requirements.   
  • Ensure periodic risk assessments to identify, evaluate, and treat information security risks proportionately.  
  • Nurture culture of confidentiality, integrity, and availability (CIA) of information through appropriate security controls and risk mitigation measures.  
  • Build and maintain clearly defined information security responsibilities, and ensure all personnel receive regular and appropriate security awareness and training.  
  • Establish measurable information security objectives, monitor performance, and drive continual improvement.  
  • Review of the ISMS will be performed periodically by management to ensure its effectiveness, adequacy and alignment with business goals and stakeholder expectations.  

 

Signed by,       

CISO

Date: 1st April 2026