Information Security Policy – SRN Sound Proof Co., Ltd.


1. Purpose and Scope

    SRN Sound Proof Co., Ltd. (SRN) adheres to the Japanese manufacturing philosophy of "Monozukuri", which focuses on stable and highest quality manufacturing to meet the demands of customers in the global automotive industry. Information security is therefore not merely a technical measure, but a strategic pillar for maintaining the Stability of Production and Supply Chain Trust, in accordance with the corporate vision focused on quality and on-time delivery.

    Scope: This policy applies to all levels of employees, contractors, and external parties conducting business with us, covering all information assets and operational systems, including:

  • Digital Infrastructure: Main website (www.srnsoundproof.com), SRN Data Transfer system, and SRN Connect system.
  • Technical Data: Production data and intellectual property transferred from parent companies in Japan and Europe.
  • Personal Data: Employee and partner data governed by the PDPA.

    Legal and Regulatory Compliance: To comply with the Computer-Related Crime Act and JAMA/JAPIA standards, all employees must strictly follow the regulations. Any violation will result in the following impacts (Non-compliance impact):

  • Criminal Impact: Imprisonment and fines under the Computer Act for unauthorized system access or data destruction.
  • Civil Impact: Claims for damages in case of personal data breaches (PDPA) or trade secrets violation.
  • Disciplinary Impact: Disciplinary action according to company rules, ranging from warnings to termination of employment.

    Security controls start with clear access rights, which act as a key defense line in the next section.

2. Access Control & Technical Security

    Identity and Access Management is the core of preventing risks from data theft and impacts on production stability.

    Password Policy Standards:

  • Password Change: Mandatory password change every 90 days to reduce data leak risks.
  • Complexity: Must contain unpredictable characters and must absolutely not be shared with others.
  • MFA: Mandatory Multi-factor Authentication for all external system access (Remote Access) under the JAMA/JAPIA guidelines.

    Approved Software List:

System Category Approved Software/System List Usage Requirements
Productivity & Cloud Microsoft 365, SRN Connect For internal communication and document management
Data Transmission SRN Data Transfer The only system allowed for data transfer with partners
Production Control Standard IATF 16949 software For quality control and production planning
Prohibited Games, pirated software, system tweaking tools Strictly prohibited from installation or use

    The above access measures will be effective when employees understand how to classify the importance of the data they hold.

3. Data Classification & Transmission

    To allocate security resources cost-effectively, SRN has defined Data Classification levels in accordance with ITA.005 standards and practical security regulations.

    Confidentiality Levels and Visual Marking: Employees must indicate confidentiality levels with a Red Stamp (S, A, B) at the top right corner of documents, both physical and digital:

  • Level S (Top Secret): Top secret data with severe impact on company stability (Stamp S).
  • Level A (High Confidential): Highly critical data, accessible only to authorized personnel (Stamp A).
  • Level B (Confidential/Internal): Confidential data used for internal operations (Stamp B).
  • Level Public: Data that can be released to the public without impact.

    Important Prohibitions (Ref: ITA.003):

  • Social Network Prohibition: Accessing all types of social media via company computers is prohibited, including Line, Facebook, TikTok, Instagram, Threads, YouTube, Telegram, OnlyFans, BlueSky, Pantip, and ClubHouse, to prevent cyber threats and maintain work focus.
  • Personal Content: Do not store family photos, celebrity photos, pornographic media, or personal financial transaction data (credit card numbers) on company servers or computers.
  • Data Sanitization: Data sent via SRN Data Transfer must always undergo Scanning and Sanitization to clean files from malware prior to transmission.
4. Incident Management & BCP

    To guarantee production security, SRN has integrated physical and cyber emergency response plans in accordance with the standards.

    BCP Operational Steps in Case of Power Outage/Surge:

  • Inspect (15 minutes): Employees must immediately check for damage in their area within the first 15 minutes.
  • Backup: If the outage exceeds 15 minutes, proceed to backup critical data immediately.
  • Notify: Inform the responsible officer or building administrator right away.
  • Shutdown: properly shut down servers and network equipment to prevent damage.
  • Report: Report the results to supervisors following the Command Chain.

    10 Priority Security Measures: Following the requirements, the company enforces these measures:

  1. MFA for Remote Access: Enforce Multi-factor Authentication.
  2. Web Gateway: Inspect secure website access.
  3. Email Gateway: Filter spam and malware emails.
  4. SOC: Manage security via the Security Operations Center.
  5. EDR: Monitor and respond to endpoint threats.
  6. Awareness: Continuously build employee awareness.
  7. Vulnerability Management: Inspect and manage vulnerabilities.
  8. Patching: Keep software constantly updated.
  9. Next-gen Anti-Virus: Utilize highly effective anti-virus systems.
  10. BCP: Establish a business continuity plan to handle cyber-attacks.
5. Governance & Responsibility

    To ensure policy enforcement complies with the law (Section 18 of the Computer Act), the company has appointed a working committee (Ref: ITA.002 announcement) as follows:

  • HR Manager: Oversees usage discipline, employee confidentiality, and NDA signing.
  • IT Supervisor: Responsible for defensive techniques and enforcement of technical security measures.
  • IT Officer: Operates system audits and provides technical support during emergencies.

    Core Authorities: The committee has the authority to coordinate and hand over digital evidence to officials when there's reasonable belief of an offense, and is responsible for regularly auditing internal computer system access rights.

6. Policy Lifecycle & Awareness

    This policy must be reviewed at least once a year or whenever there are significant organizational structural changes.

    Executive Checklist:

  • [ ] Are 90-day Passwords and MFA fully enforced on all critical systems?
  • [ ] Have 100% of employees signed the Non-Disclosure Agreement (NDA) and acknowledged the policy?
  • [ ] Has the Backup system been tested for readiness according to the BCP?
  • [ ] Is Data Classification visually marked with S, A, B stamps correctly according to standards?

    SRN Sound Proof Co., Ltd. affirms our commitment to maintaining information security standards to protect the value of "Monozukuri" and the trust of our partners in the automotive industry continuously.

    Announced on January 1, 2025