公司治理 背景圖片

Corporate Governance

公司治理

我們傳遞股東的合法權益及兼顧其他利害關係人的利益

Cyber security team

資安組織圖
Item Description
Job Responsibilities

The Company has established the "Cyber security team" under the President to supervise the information security management systems of the Company and its subsidiaries. The task force also regularly reports internal and external information security management risks to achieve stakeholders' expectations and expectations for the Company's information security. The organization and execution of the Cyber security team are as follows:

  1. CISO: Coordinates the planning of information security policies and resource allocation / Approves information security policies / Approves information security work plans / Reports to the Board of Directors.
  2. Cyber Security Manager: Reviews and signs off on information security goal settings / Formulates information security work plans / Guides information security work advancement / Reviews information security work implementation status and maintains continuous improvement / Hosts routine information security work meetings / Performs primary review of information security incidents.
  3. Security Specialist: Executes information security work plans / Participates in information security risk assessments / Implements information security policies, programs, and methods to implement information security work items / Participates in professional training to enhance personal security skills / Promotes information security education to enhance information security awareness among all employees / Participates in information security incident investigation work.
Report to the Board of Directors

The Cyber security team reports on information security work to the Board of Directors at least once a year. The content of this year's information security report was completed and reported to the Board of Directors on August 22, 2025.

Cyber security management policies
  1. Allocate appropriate resources to establish an information security management mechanism, strengthen employees' awareness of information security, and ensure that all employees have the responsibility and obligation to protect the security of the information assets they are responsible for or use.
  2. Authorize appropriately and only grant employees necessary permissions and information to complete their work, to prevent intentional or unlawful acts, and ensure the confidentiality, integrity, and availability of the company's important information assets.
  3. The Company's information security measures shall comply with the Company's information security policy and related information security management methods, and shall comply with legal and regulatory requirements.
  4. When an information security incident occurs, it shall be handled in a timely and appropriate manner with an appropriate response.
Prevention Plans
  1. Establish a cyber security team to promote group-wide information security defense work.
  2. Establish internal information security management methods in accordance with legal and regulatory requirements.
  3. Execute information security risk assessments and perform project improvements for risk items.
  4. Review information security work implementation status through external audits.
Specific Management Plans and Implementation Status for the Current Year

The Company places great emphasis on information security management, continuously optimizing and establishing various management measures. In 2025, the main resources invested in information security management are as follows:

  1. Entrusted a certification body to conduct a network security level protection assessment of the CRM membership system, including physical data center environment, application system security, network perimeter protection, and security management controls. A total of 30 working days were invested, with costs of RMB 276,000.
  2. To enhance employees’information security awareness, the Company conducted organization-wide cybersecurity training, with each employee participating for approximately 1 hour.
  3. Security personnel participated in online training programs totaling 35 hours, with costs of RMB 11,500.
  4. The Company continuously revised and updated its information security management policies, requiring 6 working days.
  5. An annual information and communication risk assessment was conducted, requiring 15 working hours.
  6. Email security was strengthened through the upgrade of the email firewall to filter inbound and outbound messages, involving 17 working days and costs of RMB 160,000.
  7. End-user internet access controls were enhanced by upgrading the web access behavior management system and adjusting access policies, involving 8 working days and costs of RMB 96,600.
  8. Vulnerability scanning and assessment were conducted on all network servers and web services, with identified vulnerabilities tested and remediated, requiring 25 working days.
  9. A comprehensive review and validation of user accounts and access privileges across all systems were performed, requiring approximately 40 working days.
  10. File server management was strengthened through a review and verification of folder and file access permissions, requiring 12 working days.
  11. Systems and databases containing personal data were reviewed for privacy information. Access controls are strictly enforced, and no leakage risks were identified. This required 30 working days.
  12. Three internal and external information security audits were conducted, with no material deficiencies identified.
本網站使用 Cookies 提升您的使用體驗及網站服務,為了幫助您瞭解本網站如何蒐集、應用及保護您的個人資訊,請務必詳細閱讀本站的「網站隱私政策」