Information Security Management
The Company recognizes information security as vital to sustainable development. In 2016, it established the “Information and Personal Data Security Management Committee,” and in 2023 appointed a Chief Information Security Officer (CISO) to address external threats and internal vulnerabilities.
▍Information Security Committee Organization
▍Cybersecurity Risk Protection and Management Measures
In July 2019, the Information Security and Personal Data Management Committee decided to introduce external consultancy resources. In December of the same year, the “Information Security Management System Implementation and Verification Project” was launched; it successfully passed the ISO 27001 Information Security Management System certification in 2021.
▍Specific Measures
In Jul 2019, the “Information Security and Personal Data Protection Committee” decided to engage external consultants and launched the “Information Security Management System Implementation and Certification Project” in Dec 2019. The project achieved ISO 27001 certification in 2021 and was recertified to ISO 27001:2022 by DNV in 2024.
The Committee holds annual management review meetings. The Head of the IT Department reports annually to the Board of Directors; in 2024, the report on Nov 14 covered risk mitigation efforts and key security initiatives.
The Committee focuses on reviewing information security policies and objectives, ensuring system effectiveness through regular reviews and audits, and continuously enhancing defenses against external threats and internal risks.
To further strengthen cybersecurity, the Company plans to implement protective measures for Operational Technology (OT) networks across its facilities.
▍Information Security and Personal Data Incident Reporting Process
According to the operational principles for handling information security and personal data incidents. If a major information security incident occurs, the Company will promptly follow the established procedures to address the incident and minimize the impacts.
1
Inform
2
Initial judgment of the problem
3
Problem analysis
4
Obstacle removal operations
5
Service recovery operations
6
Close the case