Information Security Policy

Information Security Policy

Organization: OMNI GAME LABS PTE. LTD.

Effective Date: 02/02/2026

Version: 1.0

Approved by: Zack

1. Purpose This Information Security Policy establishes the high-level framework for protecting the confidentiality, integrity, and availability of the Company's information assets. It demonstrates senior management commitment to information security and provides the foundation for the Information Security Management System (ISMS).

The policy aims to:

Safeguard company intellectual property (e.g., game source code, designs, algorithms), player data (e.g., accounts, behavioral analytics, payment information), and business operations from unauthorized access, disclosure, alteration, or destruction.

Ensure business continuity for mini-game development, publishing, and live services in a fast-paced, cloud-based environment.

Minimize risks from cyber threats, data breaches, service disruptions, or compliance failures.

Comply with applicable laws and regulations, international standards, and industry expectations for gaming/software companies.

Foster a security-aware culture across all employees, contractors, and partners.

2. Scope This policy applies to:

All information assets owned, managed, or processed by the Company, including digital (source code, databases, cloud infrastructure) and non-digital (documents, intellectual property).

All locations and environments: office, remote work, cloud platforms (e.g., AWS/GCP/Azure), development workstations, CI/CD pipelines, game servers, backend services, and third-party tools.

All personnel: employees, contractors, temporary staff, management, and third parties with access to Company information.

All processes: game development (Unity/Unreal), publishing, player data handling, monetization, analytics, and administrative functions.

Exclusions: Player client-side devices (handled via app stores/auto-updates), but the Company monitors and mitigates related risks where feasible.

3. Policy Statement we committed to protecting information assets as a core business priority. Senior management endorses and supports the establishment, implementation, maintenance, and continual improvement of an ISMS in accordance with ISO/IEC 27001:2022.

We will:

Identify, assess, and treat information security risks on an ongoing basis.

Implement appropriate controls to protect assets commensurate with their value and risk level.

Ensure compliance with legal, regulatory, contractual, and internal requirements.

Provide resources, training, and awareness programs to enable secure behaviors.

Promote accountability at all levels, with consequences for non-compliance.

Continually monitor, measure, and improve security performance.

4. Key Principles and Objectives

Confidentiality: Information is accessible only to authorized individuals (e.g., protect unreleased game IP and player PII).

Integrity: Information remains accurate and complete (e.g., prevent tampering with game data or monetization flows).

Availability: Information and services are accessible when needed (e.g., maintain uptime for live mini-games).

Security objectives (reviewed annually):

Achieve zero critical data breaches involving player personal information.

Maintain 99.9% availability for production game services.

Ensure 100% of new code/features undergo security review prior to release.

Train 100% of staff annually on security awareness.

5. Roles and Responsibilities

Senior Management / Board: Demonstrate leadership; approve policy and ISMS; allocate resources; review performance via management reviews.

CISO / Security Lead (or designated role): Own ISMS implementation; conduct risk assessments; coordinate controls; report to management.

Department Heads / Team Leads: Ensure team compliance; integrate security into workflows (e.g., secure coding in development).

All Employees & Contractors: Follow policies/procedures; report incidents/suspicions promptly; complete mandatory training.

Third Parties / Vendors: Comply with contractual security requirements; subject to due diligence and monitoring.

6. High-Level Controls and Commitments The Company will implement controls aligned with ISO 27001 Annex A (2022), including but not limited to:

Risk assessment and treatment (Clause 6).

Asset management and classification.

Access control (least privilege, MFA).

Cryptography (encryption in transit/at rest).

Physical and environmental security.

Operations security (patch/vulnerability management, logging).

Communications security (network segmentation, secure APIs).

System acquisition, development, and maintenance (secure SDLC).

Supplier relationships.

Incident management and business continuity.

Compliance and internal audits.

Specific topic policies (e.g., Data Protection, Patch Management, Network Security, Vulnerability Management) provide detailed implementation.

7. Compliance and Enforcement

All personnel must comply with this policy and supporting procedures.

Violations may result in disciplinary action, up to and including termination or legal proceedings.

The Company will conduct regular internal audits, risk reviews, and management reviews.

Breaches involving personal data will be reported to relevant authorities (e.g., Personal Information Protection Commission in Japan) as required.

8. Exceptions

Exceptions require documented justification, risk assessment, compensating controls, and approval by senior management (e.g., CISO/CTO).

Exceptions are time-limited (max 90 days unless renewed) and tracked.

9. Review and Update

This policy is reviewed at least annually, or following significant changes (e.g., new regulations, major incidents, cloud migrations, business expansion).

Updates are approved by senior management and communicated to all relevant parties.

10. Acknowledgment By continuing employment or engagement with us, individuals acknowledge receipt, understanding, and commitment to comply with this policy.