ESG Section
Information Security Policy
The Company highly values information security and has established an information security management system to ensure the confidentiality, integrity, and availability of corporate information assets, safeguarding business continuity and the rights and interests of stakeholders.
Information Security Organizational Structure
- Information Security Committee:
Convened by the President, this committee coordinates the formulation and supervision of information security policies, and regularly reviews the effectiveness of information security management alongside improvement plans. - Information Technology Department:
Responsible for daily information security operations, system monitoring, and incident handling to ensure the effective execution and maintenance of various information security measures. - All Employees:
Comply with information security regulations and implement information protection. Every colleague is a guardian of information security.
Information Security Measures
- Network Security:
Deploy firewalls, intrusion detection systems, and encrypted VPN connections to block external threats. - Endpoint Protection:
Install antivirus software and implement operating system update management to ensure the security of terminal devices. - Data Backup:
Establish regular backup mechanisms and off-site disaster recovery plans to ensure data recoverability. - Access Control:
Implement account privilege management and multi-factor authentication (MFA) mechanisms to restrict unauthorized access. - Education and Training:
Regularly conduct information security education and advocacy programs to enhance employees' security awareness and incident response capabilities.
Major Information Security Incidents
Zero Major Information Security Incidents
No major information security incidents occurred this year, indicating that the Company's information security management system is operating optimally. Various protective measures are functioning effectively to continuously safeguard the security of corporate information assets.