Corporate Commitment-Information Security Policy

Intrusion prevention services from Chunghwa Telecom are applied in order to ensure the internal network security of the company's information as well as building a firewall to block network viruses and intrusion attacks. Clients access Windows Update Services Servers to automatically update windows and repair any vulnerabilities as well as prevent viruses and hackers from attacking any vulnerabilities.
 
1- Purpose
This information security management policy has been formulated as a basis for all employees of the company to comply in order to ensure the security of the company's software, equipment and internet.
 
2- Definition
The prevention of internal and external threats can be achieved by following appropriate system planning, procedures, and administrative management.
 
3- Target
The goal is to prevent information systems from improper use or deliberate damage from internal or external sources. In case of emergencies such as improper usage or vandalism, the company can quickly respond to reduce damages caused by the incident.
 
4- Scope
Applicable to all company's information systems and users.
 
5- Organization
The Information Technology Center is responsible for coordinating information security and pertinent matters. The Audit Office formulates relevant internal control program management and regularly conducts internal audits.
 
6- Procedure
1- Employee security awareness and training.
The Information Technology Center needs to regularly implement and promote information security training and education to increase the employees knowledge and awareness of information security.
 
2- Information System Security Management
Computer hosts, servers and other equipments should be set up in a specific computer room managed by the information technology center. Unauthorized entry is not allowed and the computer room should remain locked when no one is present.
Personal computers and various equipments should be appropriately configured according to the nature of the business and should be connected to the power supply system to ensure stable power.
The maintenance and operating status of the main equipment should be recorded.
Each department must only use authorized and legal software. Software that is not legally authorized or irrelevant software may not be installed or used.
Data backup and recovery operations should be executed regularly. Backup media data should be stored in a safe off-site environment to ensure that the data is completely available.
 
3- Network Security Management
Firewalls and other security measures should be used to protect the network when connecting to external networks.
The company version of anti-virus software, intrusion detection software, and other anti-hacking software should be installed to protect company information systems from virus and malware infection or hacker intrusion.
The information technology center must be notified if the network is found or suspected of being intruded. Pertinent processing or legal action may be taken if necessary.
 
4- System Access Control
The information technology center should be notified by written document when a new user joins, changes duties or leaves (suspends) their position. The center will adjust or delete the users permission and authority to ensure system security.
All information systems must have a password setup. User passwords should comply with security standards and passwords should be changed regularly.
Computer screens should be locked when a user temporarily leaves and the computer equipment must be completely logged out when not in use.
The information technology center conducts regular self-checks.
 
5- Information System Development and Maintenance of Security Management
System development, maintenance, updates, online execution and version changes should be safely controlled.
System setup and user maintenance for the manufacturer should be regulated and restricted in the scope of systems and data they can access.
System programs and system authority modification requires filling out an application form and be executed by the information technology center personnel or consultants.  
 
6- Business Operation Sustainability Planning and Management
The information technology center and unit supervisor should be promptly notified if an information security incident occurs either causing the information system to fail to operate or if performance efficiency is affected.
The information technology center regularly evaluates the possibility of losses caused by information security risks. If necessary, an appropriate insurance will be applied to reduce pecuniary losses. 

We value your privacy
By clicking "Accept All," you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing and performance efforts.

Accept All Decline