Information Security Management Policy

Policy Content

This policy is intended to provide all employees with clear guiding principles in their daily work. All employees are obligated to actively participate in promoting information security to ensure the secure operation of the Company's data, information systems, equipment, and networks. It is expected that all employees understand, implement, and maintain the following information security objectives:

Implement Information Security, Enhance Service Quality

All employees shall thoroughly implement the ISMS. All information operation-related measures shall ensure the confidentiality, integrity, and availability of business data, preventing risks of leakage, destruction, or loss caused by external threats or improper internal management. Appropriate protective measures shall be selected to reduce risks to an acceptable level, with continuous monitoring, review, and auditing of the information security system to enhance service quality and improve service standards.

Strengthen Security Training, Ensure Business Continuity

Supervise all employees in implementing information security management, continue to provide appropriate information security education and training annually, establish the concept of "Information security is everyone's responsibility," promote employees' understanding of the importance of information security, encourage compliance with information security regulations, thereby enhancing security awareness and emergency response capabilities, reducing information security risks, and achieving the goal of business continuity.

Prepare Emergency Response, Rapid Disaster Recovery

Establish emergency response plans and disaster recovery plans for critical information assets and key business operations, and regularly conduct emergency response drills to ensure that when information systems fail or major disasters occur, rapid recovery is achieved, key business operations continue, and losses are minimized.

  1. The Company's information security management regulations must comply with relevant government laws and regulations (such as: Cyber Security Management Act, Criminal Code, Classified National Security Information Protection Act, Patent Act, Trademark Act, Copyright Act, Personal Data Protection Act, etc.).
  2. Establish an information security management organization responsible for the establishment and promotion of the ISMS.
  3. Establish management mechanisms for server and network usage to coordinate the allocation and utilization of resources.
  4. Before installing new equipment, risk and security factors must be considered to prevent situations that may compromise system security.
  5. Establish physical and environmental security measures for server rooms and conduct regular maintenance.
  6. Clearly define access permissions for network systems to prevent unauthorized access.
  7. Establish an internal audit plan for the information security management system, regularly review the usage of all personnel and equipment within the scope of the Company's ISMS, and formulate and implement corrective and preventive measures based on audit reports.
  8. All employees of the Company (including contract workers and interns), outsourced service providers, data users (including custodians), and visitors are responsible for maintaining information security and must comply with relevant information security management regulations.
  9. Information security management system documents shall have clear management regulations.

Responsibilities

  1. The Company's management is responsible for establishing and reviewing the policy.
  2. Information security managers implement this policy through appropriate standards and procedures.
  3. All personnel and contracted outsourced providers must follow procedures to maintain the information security management policy.
  4. All personnel are responsible for reporting and handling security incidents and any identified vulnerabilities.
  5. Any deliberate violation of information security will be subject to relevant regulations or legal action.