Information Security Management

The Company recognizes information security as vital to sustainable development. In 2016, it established the “Information and Personal Data Security Management Committee,” and in 2023 appointed a Chief Information Security Officer (CISO) to address external threats and internal vulnerabilities.

Information Security Committee Organization

  • Responsible Units

    The “Information Security and Personal Data Management Committee” is chaired by the General Manager, with the head of the IT department serving as the executive secretary. Key managers from various departments are appointed as information security representatives, convening regularly for information security review meetings.

Cybersecurity Risk Protection and Management Measures

In July 2019, the Information Security and Personal Data Management Committee decided to introduce external consultancy resources. In December of the same year, the “Information Security Management System Implementation and Verification Project” was launched; it successfully passed the ISO 27001 Information Security Management System certification in 2021.

Specific Measures

In Jul 2019, the “Information Security and Personal Data Protection Committee” decided to engage external consultants and launched the “Information Security Management System Implementation and Certification Project” in Dec 2019. The project achieved ISO 27001 certification in 2021 and was recertified to ISO 27001:2022 by DNV in 2024.

The Committee holds annual management review meetings. The Head of the IT Department reports annually to the Board of Directors; in 2024, the report on Nov 14 covered risk mitigation efforts and key security initiatives.

The Committee focuses on reviewing information security policies and objectives, ensuring system effectiveness through regular reviews and audits, and continuously enhancing defenses against external threats and internal risks.

To further strengthen cybersecurity, the Company plans to implement protective measures for Operational Technology (OT) networks across its facilities.

Information Security and Personal Data Incident Reporting Process

According to the operational principles for handling information security and personal data incidents. If a major information security incident occurs, the Company will promptly follow the established procedures to address the incident and minimize the impacts.

1

Inform

  • Description
    – System automatic monitoring notification
    – Customer notification of abnormal events
    – Personnel inspection findings
    – Others

  • Based on Standards
    – Information Security and Personal Data Incident Management Procedures

  • Responsible person
    – Colleagues

2

Initial judgment of the problem

  • Description
    – Make preliminary judgments on abnormal problems
    – Notify the business leader

  • Based on Standards
    – Information Security and Personal Data Incident Management Procedures

  • Responsible person
    – Business Leader

3

Problem analysis

  • Description
    – Report the causes of incidents for information security and personal data
    – Determine the type, the level and the impact of the incidents for information security and personal data
    – Determine the time required to handle the incidents and whether to report it externally

  • Based on Standards
    – Information Security and Personal Information Incident Management Procedures
    – Business Continuity Plan

  • Responsible person
    – Business Leader
    – Risk Management and Assessment Team

4

Obstacle removal operations

  • Description
    – Start up obstacle removal operations
    – During system check, notification will be stopped if the system repairs itself
    – Exclusions can be made directly and cases can be closed according to the SOP
    – Initiate the business continuity plan
    – Assess whether external support is needed
    – Report the incidents of information security and personal data
    – Designate personnel to coordinate external response to incidents

  • Based on Standards
    – Information Security and Personal Information Incident Management Procedures
    – Business Continuity Plan

  • Responsible Person
    – Business Leader
    – Risk Management and Assessment Team

5

Service recovery operations

  • Description
    – Describe the status of obstacle removal operations
    – Consolidate the incidents of information security and personal data into reports
    – Carry out correction and improvement procedures, and deal with the incidents in the order of “correction-recovery-review” according to the affected area

  • Based on Standards
    – Information Security and Personal Data Incident Management Procedures

  • Responsible Person
    – Business Leader
    – Risk Management and Assessment Team

6

Close the case

  • Based on Standards
    – Information Security and Personal Data Incident Management Procedures

  • Responsible Person
    – Business Leader
    – Risk Management and Assessment Team