Information Security
Information Security
Our company formulates and implements the "Information Security Policy" and "Information Security Management Measures" based on information security management principles, committed to preventing external threats, strengthening internal control, and ensuring the security and privacy of company and customer information.
Management Structure
- To enhance information security management, the company designates the Information Department as the authority responsible for information security management, tasked with promoting and implementing various information security measures outlined in these regulations, ensuring the implementation and effectiveness of all information security measures in the company.
- Senior management is responsible for formulating information security policies, providing resource support and commitment, and overseeing the implementation of information security policies.
- The Audit Office is the information security audit unit, responsible for independently supervising the implementation of the information security management system to ensure the effectiveness and compliance of internal control mechanisms.
Information Security Policy
Compliance with regulations, protecting assets
According to government regulations and internal specifications, implement information security management to ensure the confidentiality, integrity, availability, and legal compliance of information assets.
Risk prevention, continuous operation
Regularly conduct information security risk and disaster impact assessments, establish protection and backup plans to ensure uninterrupted company operations.
Full participation, raising awareness
Through education and training, strengthen the cybersecurity awareness and protection capabilities of employees and partners.
Strict adherence, continuous improvement
All employees and stakeholders are required to comply with information security regulations, regularly review the effectiveness of policies, and continuously improve.
Management Plan
Hacking Prevention and Intrusion Protection
Build firewalls, conduct vulnerability scanning and anomaly detection, regularly update patches to prevent external attacks and malware intrusions.
Network and Transmission Security
Using segment isolation, VPN encryption, access control, and secure communication protocols to ensure the confidentiality and integrity of data transmission.
Disaster and Business Continuity Management
Establish backup mechanisms and business continuity plans (BCP) to quickly restore operations in the event of a disaster or cybersecurity incident.
Incident Reporting and Compliance Response
Establish a classification and reporting process for cybersecurity incidents, report and improve in a timely manner according to the regulations of the competent authority, and maintain regulatory compliance.