Corporate Governance
Upholding integrity, professionalism and transparency to build a sound corporate governance system
Risk Management
Information Security Management
The company places a high priority on information security and has established a comprehensive information security management system to ensure the confidentiality, integrity, and availability of its information assets and to protect customer data and trade secrets.
Scope of Application
This information security management system applies to all departments, personnel, and information systems of the company, covering:
- All of the company's information systems, network equipment, and related infrastructure
- All data stored in the company's systems, including customer data, trade secrets, and personal data
- All employees, outsourced personnel, and partners who use the company's information resources
- Physical environments related to information security, including server rooms and offices
- Outsourced information services and cloud services
Information Security Management Structure
The company has established an Information Security Committee chaired by the CIO, which holds regular meetings to review information security policies and their implementation. A dedicated information security unit under the committee is responsible for policy formulation, risk assessment, incident response, and training.
Information Security Measures
- Deploy firewalls, intrusion detection systems, and antivirus software to defend against external attacks
- Implement identity authentication and access control mechanisms to manage data access permissions
- Regularly conduct security health checks and vulnerability scans to patch system vulnerabilities promptly
- Establish data backup and disaster recovery plans to ensure business continuity
- Encrypt the transmission of sensitive data to protect data transmission security
- Implement network segmentation to reduce the spread of security risks
Information Security Training
The company regularly conducts information security training to raise employees' security awareness. Training covers topics such as social engineering prevention, password management, phishing email identification, and mobile device security, ensuring all employees have basic security knowledge and protective capabilities.
Information Security Incident Response
The company has established an information security incident response mechanism, defining incident classification standards and reporting procedures. When a security incident occurs, the response procedure is immediately activated to conduct investigation, impact assessment, damage control, and recovery, followed by review and improvement to prevent recurrence.
Information Security Certification & Audit
The company is certified under ISO 27001 for its information security management system and undergoes regular internal audits and external verification each year to ensure that the management system continues to operate effectively and meets international standards.
Internal Audit
The company has an independent internal audit unit reporting directly to the Board of Directors. It assists the Board and management in examining and reviewing deficiencies in the internal control system and in measuring operational effectiveness and efficiency, providing timely improvement recommendations to ensure the internal control system is continuously and effectively implemented and to serve as a basis for reviewing and revising it.
Audit Organization & Responsibilities
The internal audit unit has a dedicated chief auditor and audit staff. The chief auditor should be capable of leading and managing audit work, and internal auditors should have professional knowledge or practical experience in accounting, finance, information, law, operations management, and other fields.
- Formulate the annual audit plan and carry out audit operations
- Evaluate the effectiveness of the internal control system
- Verify the reliability of financial reporting
- Review the effectiveness and efficiency of operating activities
- Assess compliance with laws and regulations
- Track the remediation of audit findings
Audit Scope & Procedures
The internal audit scope covers all of the company's operating activities, including finance, business, production, R&D, procurement, human resources, and information operations. Audits are conducted based on risk assessment results using both regular and project-based audits to ensure high-risk items receive appropriate attention.
Audit Result Reporting
Auditors should issue an audit report after each audit, documenting findings, recommended improvements, and the audited unit's responses. Audit reports should be regularly submitted to the Board of Directors and the Audit Committee, with significant anomalies reported immediately. The audit unit should also continuously track remediation to ensure deficiencies are effectively addressed.
Audit Independence & Professional Development
The company ensures the independence of the internal audit unit. Auditors maintain a spirit of detachment and independence when performing their duties, free from interference by other departments. The company also encourages auditors to pursue continuing education and attend professional internal audit training courses to enhance their expertise.
Whistleblowing Form
All reports are handled by dedicated personnel, with strict confidentiality of the whistleblower's identity and the report content.
