This Page is Home
Sustainability
Sustainability Management
Information Security Policy
Information Security Policy

Information Security Policy
The Penta-Ocean Construction Group recognises that, in order to maintain the trust of our customers and society, it is our corporate social responsibility to appropriately protect and manage all information assets held and used in the course of our business activities, while making effective use of such assets. We regard information security as one of our key management priorities and are committed to establishing an appropriate information management framework and continuously enhancing information security in accordance with the following principles.
1. Establishment of an Information Security Management Framework and Compliance with Laws and Regulations
- We appoint a Chief Information Management Officer, establish internal rules and regulations, including the Information Management Regulations, and maintain an effective information security management framework throughout our organisation.
- We comply with all applicable laws and regulations, social norms, and internal rules relating to information security, and appropriately fulfil our contractual obligations concerning information management with customers, business partners, and other stakeholders.
2. Implementation and Continuous Improvement of Information Security Measures
- We appropriately identify and assess risks to all information assets we held and used and, taking into account the latest security threats, vulnerabilities, and cyberattack trends, implement necessary information security measures and continuously improve them.
- We appropriately protect and manage the personal information of customers, employees, and others, as well as our intellectual property and that of third parties, and implement necessary management and preventive measures throughout our business activities to prevent information leakage, infringement of rights, and other security incidents.
- We operate the information systems used in our business safely and reliably. To address increasingly diverse and sophisticated cyber threats and changes in the business environment, we continuously enhance our security infrastructure and monitoring capabilities and implement appropriate organisational, personnel, physical, and technical security measures.
- When using new information technologies, including generative AI, we give due consideration to the confidentiality of information and the protection of intellectual property rights, personal information, and other protected information, and establish the necessary environment and rules to ensure their safe and appropriate use. We also recognise that AI-generated content may contain inaccurate or inappropriate information and therefore conduct appropriate reviews and strive to prevent human rights violations, infringement of rights, and other adverse impacts.
3. Continuous Information Security Education and Training
- Through regular education and training for all executives and employees, we enhance awareness and literacy regarding information security and foster an organisational culture in which each individual acts appropriately and responsibly.
4. Ensuring Information Security throughout the Supply Chain
- We seek the understanding and cooperation of our subcontractors, business partners, and other stakeholders regarding this Policy and work collaboratively with them to maintain and enhance information security throughout the supply chain.
5. Response to Information Security Incidents and Business Continuity
- We establish systems for the prompt reporting of, response to, and recovery from information security incidents. In the event of an incident, we work to prevent the damage from spreading, achieve prompt recovery, and strive to ensure business continuity.
Established on September 17, 2026

