Maxis Berhad - Annual Report 2014 - page 75

Overview
Our
Business
Strategic
Review
Corporate
Governance
Financial
Statements
Other
Information
73
Maxis Berhad
Annual Report 2014
9. Legal
The Legal department plays a pivotal role in ensuring that the interests of the Group are preserved and safeguarded from a legal
perspective. It ensures that the Group’s operations and transactions with third parties are in compliance with all laws. It also plays
a key role in advising the Board and Management on legal and strategic matters. The Board is briefed through reports to the Audit
Committee on material litigation and any changes in law affecting the Group’s operations.
10. Company Secretary
Please refer to Statement on Corporate Governance on pages 50 to 64 of this Annual Report.
11. Limits of Authority
A Limits of Authority (“LOA”) manual sets out the authorisation limits for various levels of Maxis’ Management and staff and
also those matters requiring Board approval to ensure accountability, segregation of duties and control over the Group’s financial
commitments. The LOA manual is reviewed and updated periodically to align with business, operational and structural changes.
12. Policies and Procedures
There is extensive documentation of policies, procedures, guidelines and service level agreements in manuals and on the Group’s
intranet site including those relating to Finance, Contract Management, Marketing, Procurement, Human Resources, Information
Systems, Network Operations, Legal, System and Information Security Controls. Continuous control enhancements are made to
cater for business environment changes and in line with Maxis’ new and growing business strategy.
13. Financial and Operational Information
A detailed budgeting and reporting process has been established. Comprehensive budgets are prepared by the operating units and
presented to the Board before the commencement of a new financial year. Upon approval of the budget, the Group’s performance
is tracked and measured against the approved budget on a monthly basis. Reporting systems which highlight significant variances
against plan are in place to track and monitor performance. These variances in financial as well as operational performance indices
are incorporated in detail in the monthly management reports. On a quarterly basis, the results are reviewed by the Board to enable
the Directors to gauge the Group’s overall performance compared to the approved budgets and prior periods.
14. Systems and Information Security
The Systems and Information Security department (“SIS”) has an assurance function and is responsible for continuously monitoring
and resolving security threats to the Group both internally and externally. This includes conducting security awareness, vulnerability
assessment and penetration test programmes, and compliance audits on IT systems and Networks of Maxis to reduce the impact of
service interruption due to malicious activities, cyber-attacks, negligence and malware. The effectiveness of the security programme
is validated by auditors and external security consulting companies.
Apart from the internal security compliance programmes, SIS is also required to maintain and assist in the compliance of the
following regulatory and industry security programmes, namely: MS/ISO27001:2013, Payment Card Industry/Data Security
Standard, and the Personal Data Protection Act 2010.
SIS is governed by a group of Maxis Senior Management team members who meet periodically to direct and approve the corporate
security policies and standards set by the department and security projects undertaken by the department. It is also responsible for
updating the Audit Committee at least annually on the Group’s security status.
Statement on
Risk Management and Internal Control
1...,65,66,67,68,69,70,71,72,73,74 76,77,78,79,80,81,82,83,84,85,...221
Powered by FlippingBook