治理营运
Information Security
Information systems are core to operations, and strengthening information security is a key issue in reducing the Company's operational risk.
Information Security Risk Management Framework
The Company operates on principles of integrity, transparency and accountability. We have established sound corporate governance and risk management mechanisms and comply with the Company Act, the Securities and Exchange Act, the Business Entity Accounting Act, listing regulations and other commercial laws as the foundation for integrity management.
- Communication Channels:
為實踐四項資通安全政策目標,投入之資源如下:
(1) A complete information security risk management framework has been established based on the ISO 27001 information security management system.
(2) The Board approves the information security protection policy, and an Information Security Management Committee (the Vice President and managers at all levels) coordinates implementation.
(3) System classification, asset inventory, risk identification, assessment and treatment are carried out under the Information Assets and Risk Procedures.
(4) The Operational Risk Response Team measures information security performance annually and submits it to the Committee for review and continuous improvement. 
Cybersecurity Policy and Management Programs
Policy statement: pursue sustainable development and safeguard confidential Company data and customer privacy, Ensure the confidentiality, integrity and availability of information assets, and meet applicable regulatory and customer contractual security requirements.
| Management Area | Key Points of the Management Program |
|---|---|
| Incident classification and reporting |
Incidents are graded from level 0 to 4. Suspected incidents are reported immediately; for major incidents the response mechanism is activated within 1 hour, around the clock. |
| Incident response and handling |
Managed in three phases: prevention, response and recovery. An investigation and improvement report is submitted within one month of recovery. |
| Outsourcing security management |
Handled under the outsourcing and project management procedures to ensure vendors meet security requirements and are properly supervised. |
| Cloud service management |
Managed under the cloud service management procedures to secure cloud services and guard against cloud environment risks. |
| Employee security awareness and training |
Security capability training and awareness education are provided, with regular internal communication to ensure all staff understand and follow the policy. |
| Business continuity management |
A business continuity framework has been established, defining maximum tolerable downtime to ensure rapid recovery of critical operations. |
| Audit and continuous improvement |
Internal audits are conducted annually; non-conformities are tracked and remediated under corrective procedures to continuously strengthen security capabilities.
|
Personal Data Protection
Personal data protection policy:Applies to all personal data collected, processed or used in the Company's operations. The Resource Services Division is the responsible unit, handling system design, process oversight, regulatory compliance, training, and the reporting and handling of personal data incidents.
Scope and Covered Parties:
(1) Customers and prospective customers|Customers, prospective customers, customer contacts and related personnel
(2) Suppliers and partners|Contacts at suppliers, contractors, agents, distributors and consultants
(3) Employees and job applicants|Necessary personnel data of current and former employees, job applicants and interns
(4) Visitors and other stakeholders|Data on natural persons including visitors, investors, shareholders and media
