Stakeholders

This is a translation provided for reference. In case of any discrepancy between the Chinese and English versions of this policy, the Chinese version shall prevail.

Information Security Policy, Objectives and Communication

Cyber Security Policy

To keep the Company operating smoothly and to prevent losses arising from unauthorized use of information and communication systems (including illegal access, use, control, disclosure, destruction, alteration and deletion, and other forms of intrusion), and to ensure the confidentiality, integrity and availability of those systems, this policy is established for all colleagues to observe:

  • Establish a cyber security risk management mechanism, and periodically review its effectiveness in response to changes in the cyber security landscape.
  • Protect the confidentiality and integrity of sensitive information and information systems, preventing unauthorized access and alteration.
  • Strengthen the resilience of core information and communication systems to ensure business continuity.
  • Conduct cyber security training regularly to raise security awareness; all colleagues are required to take part.

Cyber Security Objectives

  • On becoming aware of a security incident, complete notification, response and recovery within the prescribed time.
  • Adjust the scope of cyber security maintenance in response to changes in law and technology, so as to prevent damage from unauthorized use of information and communication systems and to ensure their confidentiality, integrity and availability.

Communication of the Cyber Security Policy

The cyber security policy is communicated to all employees each year through training, internal meetings and other channels, in order to raise security awareness and prevent security incidents.

Contact Channels