Information Security Policy
Information Security Risk Management Framework

Information Security Policy
In order to strengthen information security management and establish a safe and reliable operating environment, to protect the rights and interests of employees, shareholders, manufacturers and customers, this policy is formulated as the basis for the implementation of various information security measures.
Scope of application:
This policy is applicable to all employees, contracted personnel, consultants, vendors and other business entities of the company.
Policy Highlights:
- All operations shall be carried out in accordance with the various decrees issued by the competent authorities and the relevant regulations of the company.
- Job assignment should take into account the division of functions and the scope of responsibilities should be distinguished in order to avoid unauthorized modification or misuse of the information.
- Sign confidentiality contracts with third parties, vendors, consultants or customers if necessary depending on the nature of the business.
- Conduct information security training for all employees to improve the company’s information security level.
- All employees are obligated to protect the confidential and sensitive information of the company, and it is prohibited to access, use or disclose the information without authorization.
- In order to prevent computer viruses and malware, the use of unauthorized software is prohibited.
- Antivirus software and firewall should be installed and continuously updated to prevent the computers from being attacked by computer viruses and malware.
- A complete backup mechanism should be established for important information, and a redundancy mechanism should be established for important systems.
- The business continuity operation plan should be formulated according to the business needs and exercise regularly to ensure the applicability.
- Employees who violate information security regulations should be punished in accordance with relevant internal regulations of the company.
Information Security Management Measures
| Management Items | Specific Management Measures |
|---|---|
| Information Security Certification | Certified to ISO 27001 by the British Standards Institution (BSI). |
| Network Security Management | Deploy enterprise-grade firewalls to block external attacks; enforce internet access policies and content filtering to prevent access to harmful websites. |
| System Access Control | Require account passwords for all information systems with regular mandatory changes; set user permissions based on the Need-to-Know and Principle of Least Privilege. |
| Computer and Server Security Management | Implement automated system updates; install antivirus software with continuous virus definition updates; restrict use of USB storage devices without prior authorization. |
| Email Security Protection | Implement an anti-spam system; install multiple antivirus solutions on email systems for layered protection. |
| Data Backup | Conduct daily backups of critical databases and files; implement offline and offsite backup strategies. |
| System Reliability Management | Implement high availability mechanisms for critical information systems; perform full daily backups of application systems. |
| Emergency Response | Conduct annual restoration drills for critical systems to validate recovery procedures. |
| Supply Chain Information Security | Conduct annual information security questionnaires for key suppliers to assess supply chain security levels. |
| Penetration Testing | Engage external parties to conduct vulnerability assessments and penetration testing. |
| Endpoint Protection | Implement endpoint protection for critical endpoint devices to strengthen security posture. |
| Information Security Awareness | Mandatory security training for new and in-service employees annually; regular security incident case sharing; annual social engineering drills. |
| Information Security Capability | Dedicated information security supervisors and personnel; regular participation in professional training and seminars. |
Certification Achieved
The Company implemented an Information Security Management System (ISMS) in 2025 and obtained ISO 27001 certification following verification by the British Standards Institution (BSI). The certificate is valid from December 18, 2025 to December 17, 2028.