Information Security Policy

Evergreen Shipping Agency (Europe) GmbH

1. Purpose

This management measures are specified to enable all staff to be able to uphold the requirements of the company on information security; to reduce the probability of information incidents caused by malicious, negligent or lack of awareness of information security; to ensure data is processed correctly and in compliance with applicable legal and regulatory requirements, including the General Data Protection Regulation (GDPR) but not limited, and relevant local data protection laws, and to ensure the safety and security of information systems, equipment and network.

Through information security management measures, we can demonstrate the determination and support of Management in information security and facilitate personnel in following said measures to reduce the possible impact and allow the continuation of business after any information security incident. To improve the information security management system whilst protecting the rights and interests of the company and its customers.

2. Scope

This policy applies to:

3. Objectives

4. Information Security Organization

5. Risk Management

6. Access Control

7. Data Protection

8. IT Security & Network Protection

9. Incident Management

10. Business Continuity

11. Awareness & Training

12. Third-Party Security

13. Compliance

14. Continuous Improvement