- In order to strengthen the company's information security management and ensure the security of data, systems and networks, the general manager serves as the chief information security officer, and the information department is a dedicated information security unit responsible for the planning and execution of information security matters. Among them, the chief information security officer reports major issues or plans to the board of directors at least once a year.
- Management should actively participate in information security-related activities and provide support for information security business.
- Management is responsible for supervising the implementation of this policy and related regulations.
- In addition to employees, all external personnel, outsourced service providers and visitors who have access to business information should also abide by this policy and related regulations.
- Employees and outsourced service providers are responsible for reporting information security incidents or information security weaknesses through appropriate reporting mechanisms and assisting in handling them.
- Employees should abide by laws, regulations and the company's various information security regulations, and have the obligation to participate in various information security education and training organized by the company.
- Any behavior that endangers the security of financial institutions will be dealt with in accordance with the company's relevant regulations depending on the severity of the case.
- The purpose of continuous improvement should be achieved by implementing improvement measures for the information security management system.
- The company's audit office is the audit unit for information security supervision. If deficiencies are found during the audit, the audited unit will be required to propose relevant improvement plans and report them to the board of directors, and will regularly track the improvement results to reduce internal information security risks.
Information Security Principles
- Information security education and training is held regularly every year and information security promotions are held from time to time, including information security policies, information security legal requirements, information security operating procedures, and how to use information technology facilities correctly, etc., to help employees understand the importance of information security and various possible security risks, so as to improve employees' information security awareness and comply with information security regulations.
- In order to prevent information systems and files from being infected by computer viruses, detection and prevention measures should be taken against computer viruses. An active intrusion detection system should be established for intrusions and malicious attacks to ensure computer data security requirements.
- In order to prevent the company from encountering natural disasters or major man-made events, which will cause the interruption of important information assets and key business or communication systems, a policy for sustainable operation planning of the information system should be established.
- For important information security tasks such as system host operating system or important software upgrades and disaster recovery drills, the Information Security Management Office regularly reviews the planning and execution progress every month. Through irregular social engineering drills, information security health inspection services, etc., it determines whether users' information security concepts are adequate, whether there are loopholes in information equipment resource investment and system configuration, and prepares an information security budget before implementation.
Information Security Measures

Emergency Notification Procedure
When an information security incident occurs, the unit where it occurred needs to notify the information department, which will determine the type of incident and identify the problem.
Information security implementation in 2025:
1. Disaster recovery drill-ERP disaster recovery drill
2. ERP version upgrade plan
3.AD domain creation user passcode specifications
4. Report to the board of directors on the implementation of information security on November 11, 2025
5. Important systems and databases are backed up daily through backup software
6. Annual disaster recovery drill
7. Irregular information security promotions every year
*No information security incidents or equipment abnormalities were found in 2025.