Information Security Risk Management

Cybersecurity Policy

Information Security Risk Management

Information Security Policy

Our company establishes an information security policy as a guiding principle for information and communication security management. It focuses on three major aspects: personal data file security and management, trade secret file management, and information system security. We continuously implement information and communication security management to strengthen the security management of information assets such as personnel, equipment, systems, data, and networks, thereby preventing risks such as leakage, destruction, or loss due to external threats or improper internal management.

Information Security Organization Structure

(1) Our company established the "Information and Communication Security Management Promotion Team" in 113 as a functional organization for information and communication security governance and operational management mechanisms. We utilize the PDCA (Plan-Do-Check-Act) cyclical management method to ensure the effectiveness and continuous improvement of the information and communication security risk management framework.

The "Information Security Management Promotion Team" held more than 19 related meetings in 2024, continuously reviewing and improving information and communication security management. Starting from the second quarter of 2025, information and communication security report meetings will be held quarterly. The information and communication security execution reports for the second and third quarters of 2025 have been completed, and the information and communication security execution report meeting for the fourth quarter of 2025 is scheduled to be held in January 2026.

(3) The Audit Office shall conduct audits of information security-related operations periodically or irregularly according to the annual audit plan, in order to strengthen internal control and risk management mechanisms.

All information users, including employees and contractors, must comply with this company's information security policy and related management regulations to jointly maintain the security of the company's information assets.

Management hierarchy support

The company's management places a high priority on information security governance. In 2025, an information security policy will be established and implemented after approval by the board of directors, serving as the highest guiding principle for the company's cybersecurity management. The cybersecurity policy will be reviewed annually. Management will continuously oversee the progress of information security initiatives and report to the board of directors quarterly on the execution of cybersecurity measures and the effectiveness of risk management. This ensures the confidentiality, integrity, and availability of the company's operational information.

 

Information Security Specific Management Plan

Adopt next-generation firewalls to strengthen network perimeters and prevent external threats.

Spam filtering, reducing the security risks caused by spam.

(3) Install antivirus software on each computer and perform regular scans to provide a safe operating environment for colleagues.

Regularly download and update operating system vulnerability patches to prevent hacker or virus attacks.

(5) Perform backup operations regularly on a daily and monthly basis, and store backup data off-site.

(6) Conducted a core system restore drill in December of the 114th year to ensure backup data is correct and effective.

(7) During the year 114, changes in authority were made according to operational requirements upon personnel arrival, transfer, and departure.

(8) Changes to application system software shall be initiated by the user department completing a "Computer Operation Change Request Form," obtaining approval from the responsible supervisor, and proceeding according to the program development and design procedures.

(9) Starting in 112 [year], joined the Taiwan Computer Emergency Response Team Coordination Center (TWCERT/CC) to obtain cybersecurity early warning intelligence, cybersecurity threat, and vulnerability information.

Cybersecurity resource investment

Our company has established a firewall system and a spam filtering system. Every computer is installed with antivirus software, and regular vulnerability updates are performed to prevent illegal intrusion, damage, or data theft, thereby ensuring data security.

(2) All the aforementioned information and communication systems have designated specific personnel responsible for them to enhance information and communication security capabilities.

(3) In 114 (2025), entrusted a vendor to conduct information and communication security testing, including host and website vulnerability scanning, and to evaluate and remediate based on the test results.

(4) Conducted 1 social engineering drill, 3 cybersecurity awareness and prevention sessions on social engineering, and sent 12 cybersecurity newsletters monthly in 2025 to enhance staff cybersecurity awareness.

In 114, general cybersecurity awareness training courses were provided to all employees, with a total learning time of 304.18 hours.

(6) In 114, specialized information security personnel participated in external information security professional education and training courses, totaling 2 person-times and 16 hours.

(7) Appoint one full-time information security officer and one full-time information security specialist, responsible for information and communication security governance, planning, and related execution tasks.

(8) Established a SOC (Security Operations Center) in 2025, collecting logs from various heterogeneous devices for 24/7 monitoring and tracking of abnormal events.

(9) In the 114th year, an EDR endpoint real-time monitoring system was introduced to enhance the detection and real-time response capabilities against unknown threats and ransomware.

Cybersecurity and Network Risk Assessment

(1) In 114, Hou Jianye United Certified Public Accountants surveyed the effectiveness of information system internal controls. The survey did not identify any significant risk deficiencies.

(2) In 114, conducted vulnerability scanning for host systems and websites, and implemented corresponding strengthening and improvement measures based on the scan results.

Participate in the Digital Industries Administration SIG information security rating and cybersecurity health check project (organized by industry associations). Review the company's cybersecurity maturity through external assessment mechanisms and improve information and communication security management accordingly.

Cybersecurity incident

(1) In the past three fiscal years, there have been no major cybersecurity incidents that have resulted in losses or adverse impacts on the company's operations.