1. Purpose
To ensure the confidentiality, integrity, and availability of the company’s information assets, and to comply with the requirements of relevant regulations, so as to protect them from internal and external intentional or accidental threats.
2. Scope
Taking into account the company’s core information systems and the needs and expectations of relevant stakeholders, and with the goal of protecting the confidentiality, integrity, and availability of information assets, the security maintenance and management of software project system development/maintenance and of the computer room are given priority for inclusion in the scope of information security management, demonstrating the company’s philosophy of sustainable business management.
To prevent the improper use, disclosure, tampering, or destruction of information assets due to human error, intentional acts, or natural disasters — which could bring possible risks and harm to the company — appropriate control measures across organizational, personnel, technical, and physical dimensions shall be adopted to properly respond to such risks. The management items of the Information Security Management System are as follows:
- Information Security Management
- Information Security Policy Management
- Information Security Organization Management
- Human Resources Security Management
- Information Asset Management
- Access Control Management
- Cryptography (Password) Management
- Physical and Environmental Security Management
- Operations Security Management
- Communications Security Management
- Information System Acquisition, Development, and Maintenance Management
- Supplier Relationship Management
- Information Security Incident Management
- Business Continuity Management
- Compliance (Legal Conformity) Management
- Data Security Management
- Change and Configuration Management
- Cloud Service Management
3. Authority and Responsibility
Information Security Committee- The company’s decision-making body for information development and security management at the management level.
- Responsible for the planning, establishment, implementation, maintenance, review, and continual improvement of the company’s information security management system.
Company Employees, Information System Service Users, and Outsourced Personnel- Cooperate with the operation of the information security management system.
- Comply with the relevant information security management regulations.
4. Definitions
4.1 Information Security Protecting the confidentiality, integrity, and availability of information; may also involve properties such as authenticity, accountability, non-repudiation, and reliability.
5. Operational Content
- Relevant laws, regulations, and operational requirements shall be considered when conducting information risk assessments of information assets, in order to determine information operation security requirements, establish the operating standards of the “Information Security Management Procedures,” and adopt appropriate information security measures to ensure the security of information assets.
- Based on personnel roles and functions, an evaluation or assessment system shall be established, and information security education, training, and awareness activities shall be conducted as actually needed.
- The granting of access rights to information assets shall be based on business needs, taking into consideration the principle of least privilege, segregation of duties, and independent review.
- An information security incident management procedure shall be established to ensure that incidents are properly responded to, controlled, and handled; a business continuity plan shall be formulated and drilled regularly to ensure the continued operation of information systems or services.
- In accordance with the relevant provisions of the Personal Data Protection Act and intellectual property laws, personal information and intellectual property rights shall be carefully handled and protected.
- Information security audits shall be performed regularly to review the implementation of the information security management system.
- Violations of this policy and related information security regulations shall be handled in accordance with relevant laws, regulations, or personnel policies.
- To ensure that all employees are aware of their duties and responsibilities regarding information security, ongoing information security training shall be provided to strengthen employees’ awareness of information security requirements.
5.2 Understanding the Organization and Its Context- In accordance with operational objectives, internal and external issues that may affect the outcomes of the Information Security Management System shall be identified, including relevant legal requirements, competent authority policy requirements, and the needs of interested parties. Based on the identification results, an “Organizational Context Identification Table” shall be established as the basis for identification and implementation, and used to confirm the scope conformity of the ISMS.
- The “Organizational Context Identification Table” may be confirmed and revised as necessary annually or whenever a significant issue changes.
5.3 Objectives- Maintain the confidentiality, integrity, and availability of information, and protect the privacy of personal data.
- Protect business service information to prevent unauthorized access and modification, ensuring its accuracy and completeness.
- Establish an information operation continuity plan to ensure the continued operation of business services.
- The execution of business services shall comply with the requirements of relevant laws and regulations.
- Each year the organization shall establish quantitative measurement items based on the above objectives, record them in the “Objective Control and Measurement Table,” and manage them according to actual implementation.
5.4 Review- This policy shall be reviewed once a year to appropriately reflect the latest developments of the competent authority, laws and regulations, technology, organization, and business, so as to ensure the effectiveness of information security practices.
- This policy must be communicated in writing, electronically, or by other means to all employees and to the relevant vendors or stakeholders providing information services, so that they can access it in a timely manner.
5.5 Implementation This policy shall be implemented upon approval by the Information Security Committee; the same applies to any subsequent revisions.