{"id":2326,"date":"2026-04-15T11:08:19","date_gmt":"2026-04-15T11:08:19","guid":{"rendered":"https:\/\/devnamchow.wpdu.me\/?page_id=2326"},"modified":"2026-04-20T02:56:44","modified_gmt":"2026-04-20T02:56:44","slug":"cybersecurity","status":"publish","type":"page","link":"https:\/\/www.namchow.com.tw\/en\/governance\/cybersecurity\/","title":{"rendered":"Information Security Risk Management"},"content":{"rendered":"<div data-elementor-type=\"wp-page\" data-elementor-id=\"2326\" class=\"elementor elementor-2326\" data-elementor-post-type=\"page\">\n\t\t\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-6690be1 e-flex e-con-boxed e-con e-parent\" data-id=\"6690be1\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2625091 elementor-widget elementor-widget-shortcode\" data-id=\"2625091\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\"><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-578785a e-flex e-con-boxed e-con e-parent\" data-id=\"578785a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8e6052d elementor-widget__width-initial elementor-widget elementor-widget-heading\" data-id=\"8e6052d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Cybersecurity Policy<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-267b7bd elementor-widget elementor-widget-heading\" data-id=\"267b7bd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Information Security Risk Management<\/h3>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-03f3c6b e-flex e-con-boxed e-con e-parent\" data-id=\"03f3c6b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-04ad28e elementor-widget elementor-widget-heading\" data-id=\"04ad28e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Information Security Policy<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f3df325 elementor-widget elementor-widget-text-editor\" data-id=\"f3df325\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Our company establishes an information security policy as a guiding principle for information and communication security management. It focuses on three major aspects: personal data file security and management, trade secret file management, and information system security. We continuously implement information and communication security management to strengthen the security management of information assets such as personnel, equipment, systems, data, and networks, thereby preventing risks such as leakage, destruction, or loss due to external threats or improper internal management.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c2f0d96 elementor-widget elementor-widget-heading\" data-id=\"c2f0d96\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Information Security Organization Structure<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9523ebc elementor-widget elementor-widget-text-editor\" data-id=\"9523ebc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>(1) Our company established the \"Information and Communication Security Management Promotion Team\" in 113 as a functional organization for information and communication security governance and operational management mechanisms. We utilize the PDCA (Plan-Do-Check-Act) cyclical management method to ensure the effectiveness and continuous improvement of the information and communication security risk management framework.<\/p><p>The \"Information Security Management Promotion Team\" held more than 19 related meetings in 2024, continuously reviewing and improving information and communication security management. Starting from the second quarter of 2025, information and communication security report meetings will be held quarterly. The information and communication security execution reports for the second and third quarters of 2025 have been completed, and the information and communication security execution report meeting for the fourth quarter of 2025 is scheduled to be held in January 2026.<\/p><p>(3) The Audit Office shall conduct audits of information security-related operations periodically or irregularly according to the annual audit plan, in order to strengthen internal control and risk management mechanisms.<\/p><p>All information users, including employees and contractors, must comply with this company's information security policy and related management regulations to jointly maintain the security of the company's information assets.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-82f380a elementor-widget elementor-widget-image\" data-id=\"82f380a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1584\" height=\"944\" src=\"https:\/\/www.namchow.com.tw\/wp-content\/uploads\/2026\/04\/\u8cc7\u901a\u5b89\u5168\u98a8\u96aa\u7ba1\u7406_\u67b6\u69cb.png\" class=\"attachment-large size-large wp-image-2364\" alt=\"\" srcset=\"https:\/\/www.namchow.com.tw\/wp-content\/uploads\/2026\/04\/\u8cc7\u901a\u5b89\u5168\u98a8\u96aa\u7ba1\u7406_\u67b6\u69cb.png 1584w, https:\/\/www.namchow.com.tw\/wp-content\/uploads\/2026\/04\/\u8cc7\u901a\u5b89\u5168\u98a8\u96aa\u7ba1\u7406_\u67b6\u69cb-768x458.png 768w, https:\/\/www.namchow.com.tw\/wp-content\/uploads\/2026\/04\/\u8cc7\u901a\u5b89\u5168\u98a8\u96aa\u7ba1\u7406_\u67b6\u69cb-1536x915.png 1536w\" sizes=\"auto, (max-width: 1584px) 100vw, 1584px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-07a7d85 elementor-widget elementor-widget-heading\" data-id=\"07a7d85\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Management hierarchy support<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fd83ef6 elementor-widget elementor-widget-text-editor\" data-id=\"fd83ef6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The company's management places a high priority on information security governance. In 2025, an information security policy will be established and implemented after approval by the board of directors, serving as the highest guiding principle for the company's cybersecurity management. The cybersecurity policy will be reviewed annually. Management will continuously oversee the progress of information security initiatives and report to the board of directors quarterly on the execution of cybersecurity measures and the effectiveness of risk management. This ensures the confidentiality, integrity, and availability of the company's operational information.<\/p><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-809ef91 elementor-widget elementor-widget-heading\" data-id=\"809ef91\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Information Security Specific Management Plan<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a61aabd elementor-widget elementor-widget-text-editor\" data-id=\"a61aabd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Adopt next-generation firewalls to strengthen network perimeters and prevent external threats.<\/p><p>Spam filtering, reducing the security risks caused by spam.<\/p><p>(3) Install antivirus software on each computer and perform regular scans to provide a safe operating environment for colleagues.<\/p><p>Regularly download and update operating system vulnerability patches to prevent hacker or virus attacks.<\/p><p>(5) Perform backup operations regularly on a daily and monthly basis, and store backup data off-site.<\/p><p>(6) Conducted a core system restore drill in December of the 114th year to ensure backup data is correct and effective.<\/p><p>(7) During the year 114, changes in authority were made according to operational requirements upon personnel arrival, transfer, and departure.<\/p><p>(8) Changes to application system software shall be initiated by the user department completing a \"Computer Operation Change Request Form,\" obtaining approval from the responsible supervisor, and proceeding according to the program development and design procedures.<\/p><p>(9) Starting in 112 [year], joined the Taiwan Computer Emergency Response Team Coordination Center (TWCERT\/CC) to obtain cybersecurity early warning intelligence, cybersecurity threat, and vulnerability information.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c06f74 elementor-widget elementor-widget-heading\" data-id=\"7c06f74\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Cybersecurity resource investment<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2430b3f elementor-widget elementor-widget-text-editor\" data-id=\"2430b3f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Our company has established a firewall system and a spam filtering system. Every computer is installed with antivirus software, and regular vulnerability updates are performed to prevent illegal intrusion, damage, or data theft, thereby ensuring data security.<\/p><p>(2) All the aforementioned information and communication systems have designated specific personnel responsible for them to enhance information and communication security capabilities.<\/p><p>(3) In 114 (2025), entrusted a vendor to conduct information and communication security testing, including host and website vulnerability scanning, and to evaluate and remediate based on the test results.<\/p><p>(4) Conducted 1 social engineering drill, 3 cybersecurity awareness and prevention sessions on social engineering, and sent 12 cybersecurity newsletters monthly in 2025 to enhance staff cybersecurity awareness.<\/p><p>In 114, general cybersecurity awareness training courses were provided to all employees, with a total learning time of 304.18 hours.<\/p><p>(6) In 114, specialized information security personnel participated in external information security professional education and training courses, totaling 2 person-times and 16 hours.<\/p><p>(7) Appoint one full-time information security officer and one full-time information security specialist, responsible for information and communication security governance, planning, and related execution tasks.<\/p><p>(8) Established a SOC (Security Operations Center) in 2025, collecting logs from various heterogeneous devices for 24\/7 monitoring and tracking of abnormal events.<\/p><p>(9) In the 114th year, an EDR endpoint real-time monitoring system was introduced to enhance the detection and real-time response capabilities against unknown threats and ransomware.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1aee2f9 elementor-widget elementor-widget-heading\" data-id=\"1aee2f9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Cybersecurity and Network Risk Assessment<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c42353a elementor-widget elementor-widget-text-editor\" data-id=\"c42353a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>(1) In 114, Hou Jianye United Certified Public Accountants surveyed the effectiveness of information system internal controls. The survey did not identify any significant risk deficiencies.<\/p><p>(2) In 114, conducted vulnerability scanning for host systems and websites, and implemented corresponding strengthening and improvement measures based on the scan results.<\/p><p>Participate in the Digital Industries Administration SIG information security rating and cybersecurity health check project (organized by industry associations). Review the company's cybersecurity maturity through external assessment mechanisms and improve information and communication security management accordingly.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1a4f784 elementor-widget elementor-widget-heading\" data-id=\"1a4f784\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Cybersecurity incident<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-423787a elementor-widget elementor-widget-text-editor\" data-id=\"423787a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>(1) In the past three fiscal years, there have been no major cybersecurity incidents that have resulted in losses or adverse impacts on the company's operations.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Cybersecurity Policy \u8cc7\u901a\u5b89\u5168\u98a8\u96aa\u7ba1\u7406 \u8cc7\u8a0a\u5b89\u5168\u653f\u7b56 \u672c\u516c\u53f8\u5236\u5b9a\u8cc7\u8a0a\u5b89\u5168\u653f\u7b56\u4f5c\u70ba\u8cc7\u901a\u5b89\u5168\u7ba1 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":326,"menu_order":25,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_eb_attr":"","footnotes":""},"class_list":["post-2326","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/pages\/2326","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/comments?post=2326"}],"version-history":[{"count":7,"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/pages\/2326\/revisions"}],"predecessor-version":[{"id":3008,"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/pages\/2326\/revisions\/3008"}],"up":[{"embeddable":true,"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/pages\/326"}],"wp:attachment":[{"href":"https:\/\/www.namchow.com.tw\/en\/wp-json\/wp\/v2\/media?parent=2326"}],"curies":[{"name":"WordPress","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}