Information Security Management
Information Security Policy, Customer Data Protection, and Trade Secret Management
HANTECH BIO-TECH has established an Information Security Office, with dedicated personnel responsible for information security planning and implementation and for coordinating the development and execution of information security policies. To protect the confidentiality, integrity, and availability of information assets, the company has established the Information Security Policy and the Information Cycle Internal Control Procedures. These cover measures for information equipment protection, detection, and recovery, while introducing institutionalized processes and international standards to strengthen security controls throughout the stages of information acquisition, processing, storage, and transmission, reduce the risks of business interruption and information security incidents, and ensure the security of both company and customer data.
The information security management system is planned and implemented in accordance with the framework and requirements of ISO/IEC 27001 and is continuously improved through daily operations. Key measures include:
• Daily data backup and system monitoring
• Weekly review and consolidation of abnormal traffic and firewall logs
• Monthly system version updates and security patches
• Information security meetings are convened as needed for specific projects or incidents to review risks and improvement measures.
In addition, beginning in 2025, the company regularly reviews its Information Security Policy and reports the review results and implementation status to the Board of Directors to ensure that information security management continues to meet operational and regulatory requirements. The Audit Office also conducts at least one annual spot check of information and communications security controls, tracks the effectiveness of improvement plans, and regularly reports audit results to the Board of Directors to strengthen oversight and support continuous improvement in information security management.