Corporate Governance
Information Security
Information Security
Information Security Policy
Information Security Maintenance Plan

To establish and protect all information assets related to the Company's information and communication systems, including physical environment, hardware and software facilities, network, cloud, data, information, and personnel security, against internal or external threats, such as damage, loss, disclosure, or improper control, which constitute information security risks, this policy is hereby established.

The Company shall take the following measures:

I. To strictly comply with laws and regulations in formulating relevant Information Security Management Regulations, and to provide appropriate protection measures for the Company's information assets to ensure their confidentiality, integrity, availability, and legal compliance.

II. To regularly assess the impact of various human and natural disasters on the Company's information assets, and to establish disaster prevention countermeasures and a Disaster Recovery Plan (DRP) for important information assets and critical business operations, to ensure the Company's business continuity.

III. To supervise all Company employees in implementing information security protection work, establish the concept that "Information Security is everyone's responsibility," and enhance the information security awareness of all business departments and personnel.

IV. To require Company employees and vendors connecting to the Company's information and communication systems or providing services to strictly comply with the Company's relevant information security regulations. Violators will be subject to disciplinary action in accordance with the Company's regulations or contractual penalties, depending on the circumstances, and serious offenseswill be subject to relevant legal prosecution.