Information Security Policy
Protecting the data of partner institutions and clients to a clinical-grade standard.
01Policy objectives
Text to be migrated from the current version on icryobank.com.
02Privacy policy
Text to be migrated from the current version on icryobank.com.
03Information security management framework
Text to be migrated from the current version on icryobank.com.
- 3.1Management principles
- 3.2Compliance standards
04Technical security measures
Text to be migrated from the current version on icryobank.com.
- 4.1Network security
- 4.2Data encryption
- 4.3System security
05Access control and identity management
Text to be migrated from the current version on icryobank.com.
- 5.1User authentication
- 5.2Permission management
06Data protection and backup
Text to be migrated from the current version on icryobank.com.
- 6.1Data classification
- 6.2Backup strategy
07Incident response and monitoring
Text to be migrated from the current version on icryobank.com.
- 7.1Security monitoring
- 7.2Incident handling process
08Personnel security
Text to be migrated from the current version on icryobank.com.
- 8.1Staff training
- 8.2Third-party management
09Disaster recovery plan
Text to be migrated from the current version on icryobank.com.
- 9.1Business continuity
- 9.2Testing and drills
10Compliance and audit
Text to be migrated from the current version on icryobank.com.
- 10.1Internal audit
- 10.2External certification
11Notification and communication
Text to be migrated from the current version on icryobank.com.
- 11.1Security incident notification
- 11.2Points of contact
12Policy maintenance
Text to be migrated from the current version on icryobank.com.
The implementation of this policy is reflected in ISO/IEC 27001:2022, ISO/IEC 27701:2019 and the Ministry of Digital Affairs SecPaaS Grade A rating.