Information Security Policy

The Company established the information security policy to ensure the security of its information assets and proper operations, securing the confidentiality, integrity, and availability of the Company's critical assets. Such assets include data, information, equipment, personnel, and networks. The policy aims to reduce operational risks and maintain the Company's reputation. Over the years, the Company has been committed to improving information security management mechanisms internally, regularly promoting information security, and conducting employee training on information security.

We have strengthened our information security management, fortifying the belief that information security is everyone's responsibility. This ensures the confidentiality, integrity, and availability of client and company data. We aim to guarantee the security of data handling across the Company and provide secure, stable, and efficient information services.

Information Security Committee Structure

The Company submitted the information security governance report to the Board of Directors on December 20, 2023.
Information security governance system
The information department submits the Company's information governance and standards via internal electronic signatures through the chain of command, from department heads to the general manager, to improve information security management. Upon approval, the information department then releases a company-wide announcement after going through the review process by the document management center.

Information Security Operation Model
Information Security Strategy
Information Security Training
The Company organizes employee information security training annually at Hsinchu Science Park and Central Taiwan Science Park factory sites. External information security instructors are invited on-site to illustrate m.o.s of external hacker attacks and raise awareness of prevention measures. Meanwhile, the Company introduces the latest information security concepts to the employees to reduce risks. The Company hopes that, with an improved understanding of information security, all would take part in safeguarding the Company's interests.
Information Security Maintenance