Information Security Policy

1. Information Security Risk Management Framework:

To strengthen the information security management of our company, the responsible unit for information security is the Information Department, which consists of 2 members, including an information manager and professional information personnel. They are responsible for coordinating and executing various information activities, formulating all internal information management regulations and related operations, promoting information security messages, enhancing employees' awareness of information security, implementing various information cycles, conducting information security audits, and enforcing information security mechanisms.

 

2. Information Security Policy:

In order to protect the rights and interests of the company and its employees, and to implement the internal information security management measures of the company, a reliable information security operating environment is established to ensure the confidentiality and integrity of information assets, as well as the security of equipment and networks, maintaining the principle of continuous operation of information systems. The information security policy is as follows:

  1. System and application access control: Permissions management is set according to each account, and changes must be approved before system permissions are granted.
  2. Network Security Management: Set up firewalls to segment internal and external networks, and regularly review firewall rules.
  3. Protection of information records: Control of personnel in the machine room, implementation of file backup and off-site backup, system recovery testing operations.
  4. Network Security of Personal Computer Systems: The IT department periodically promotes or announces, installs antivirus software, and regularly updates passwords.
 

3. Specific Management Plans for Information Security:

  1. Colleagues' accounts, passwords, and permissions should be properly managed and used responsibly, and changed regularly.
  2. Important information systems or equipment should establish appropriate backup or monitoring mechanisms, conduct off-site data backups, regularly practice disaster recovery, and maintain their availability.
  3. Personal computers should have antivirus software installed and regularly check for updates to the virus definitions, and the installation and use of unauthorized software should be prohibited.
  4. Employees are strictly prohibited from bringing personal computer equipment to the company and connecting it to the internal network without authorization.
  5. Regular risk assessments for information security should be conducted, and if necessary, included in the annual budget plan to implement various information security measures and enhance operational safety.
  6. Email Security Control: Set up an email scanning protection system to isolate suspicious and unsafe attachments and spam before users receive the email, preventing malicious emails from entering the company.
  7. Firewall Protection: Set up firewall connection rules. Connections with special external requirements must be applied for and opened before they can be used.
  8. All personnel should comply with legal regulations and information security policy requirements. Supervisors should oversee the implementation of information security compliance systems and strengthen colleagues' awareness of information security and legal concepts.
  9. Regularly perform updates to patch vulnerabilities in personal computer operating systems in advance to strengthen system defense capabilities and reduce risks.
  10. Data Center Access Control Management.
  11. In the year 114, one information security meeting was held, the server system was upgraded to enhance system security, strategies were adjusted in response to new threat dynamics, and the implementation of information security policies by various units was reviewed. There were no incidents that threatened the information security of the company that year.

 

IV. Implementation of Information Security Awareness Initiatives:

Category Execution Time Content
Information Security Protection Advocacy Once a week Legal Software Usage Policy, strengthen employees' awareness of using legally licensed software, avoid using unauthorized software, and enhance alertness to security risks.
Once a week Ransomware Prevention Promotion
Once a month Information security protection, turn off personal computers when not in use to reduce the risk of being hacked.
Once a year Information Security Education and Training
Computer and Software Usage Regulations New Employee Onboarding Day Promoting Personal Computer Usage Guidelines during Training
New Employee Reporting Day Sign the Computer and Software Usage Agreement
Disaster Recovery Testing Once a year ERP Application System Disaster Recovery Testing
Account Permission Review Once a year The account permissions for ERP and CRM applications are confirmed by the heads of each department.

 

Inquiry Cart

total 0 items

Compare

total 0 items

Privacy Settings

We use cookies to allow our website to function properly, personalize design content and advertisements, provide social media features, and analyze traffic. We also share information about your use of our website with social media, advertising, and analytics partners.

View Privacy Policy

Manage Consent Settings

Essential Cookies

Accept All

The website cannot operate without these cookies, and you cannot disable them in the system. These cookies are typically set based on your actions (i.e., service requests), such as setting privacy preferences, logging in, or filling out forms. You can configure your browser to block or prompt you about these cookies, but this may cause certain website functions to not work.