GOVERNANCE LEADERSHIP

治理領航力

GOVERNANCE LEADERSHIP

Information Security and Risk Management
Creating customer value is a cornerstone of iST's sustainable development strategy. As a professional technical service provider, iST understands that providing accurate and precise data accelerates customers' R&D progress. Given that analytical data represents the proprietary property and intellectual fruits of our clients, we are committed to ensuring its absolute security and integrity.
Information Security and Management Structure
To ensure the security of iST's and the customers’information assets, the Company has set up a Security Governance Committee to integrate internal resources and perform information security risk assessment as well as developing annual information security plans and inspection standards. We also coordinate relevant resources and activities across units to implement various information security controls, annual education and training on information security for employees, and information security audits. The Security Governance Committee holds meetings biannually to review and resolve on information security and protection guidelines and policies in order to realize the effectiveness of the information security management measures. The committee may also hold a meeting from time to time based on the needs of management of information security risk. The convener of the Security Governance Committee represents the committee and reports to the board of directors every year. iST obtained the certification of ISO/IEC 27001 Information Security Management System (ISMS) in October 2020. The validity of certification expires on Oct. 15, 2026.
The Chief Information Security Officer is the convener of the meeting of security control committee, with Heads of Divisions as ex officio members, Information Security Implementation Team, Emergency Response Team, Information Security Audit Team and Document Management Center. A total of 25 people as listed above.
iST establishes various information security measures through three operating policies – “Establishing a dedicated information security organization,”“Obtaining support from senior management,”“Implementing all-staff participation,”and in compliance with relevant requirements of ISO/IEC 27001 information security management system, such as information security policies, management procedures, and operating standards, in order to safeguard the security and interests of iST and its customers’ information assets.
Information security policy and specific management plan
iST enhances the personnels awareness of information security and overall security resilience through“Establishing Multifaceted Information Security Message Communication”and“Implementing Information Security Educational Training”.
iST information security technical measures are planned and implemented in five major aspects to continuously strengthen information security protection capabilities.
Allocate resources for cybersecurity management
To achieve the vision of our cybersecurity policy, we have allocated resources to implement the following cybersecurity protection measures:
Information security protection measures
Enhance personnel information security literacy
  • Cyber security training course:New employees are required to complete the education training on information security arranged for new employees. Each employee receives a follow-up training every year.
  • Enhancement of cybersecurity awareness:Electronic newsletters or notices about cyber security are sent from time to time to help employees get to know cyber security practices and understand types of the cyber security attacks occurring externally.
    16 newsletters/notices were sent in 2025.
  • Social engineering drills:Annual training sessions and phishing email simulations are conducted to validate employees’ cybersecurity awareness.
    Two phishing email test was held in 2025.
  • Respect of intellectual property right:iST prohibits the use of illegal, cracked, or portable software.
  • Enhancement of cyber security skills:Security specialists are assigned to attend external seminars, security tool training, and offensive and defensive hacking courses on an irregular basis to strengthen cybersecurity knowledge and capabilities.
    14.5 hours per person in 2025.
Reinforce data protection and access control
  • Encryption:Document encryption software is installed to protect confidential information files and reduce the risk of unauthorized disclosure of confidential information.
  • Authorization:Access to the files is controlled by setting levels of authorization based on necessity.
  • Network management:Warnings are issued, and inspection is conducted, for abnormal network traffic. External data transmission requires prior application and approval.
  • Access control:Employees are not allowed to bring in personal storage devices or use personal equipment to take photos or film. The use of storage devices via USB ports is prohibited.
Implement routine IT operations and risk management
  • Audit and improvement:Systems are inspected and improved periodically. New technologies are adopted to enhance data protection. Compliance with requirements of the management system is secured through internal audits conducted periodically and audits conducted by external cyber security certification units. In 2025, an internal audit and an external verification audit were conducted, and the information security task force held a meeting every month to review relevant matters.
Ensure the stability and availability of critical services
  • Backup management:Implemented a backup appliance. Important systems are backed up and are renewed or upgraded for cyber security subject to the annual plan.
  • Cybersecurity:To enhance protection of internal and external cyber attacks, the firewall policy is adjusted and review, the detection of cyber attacks is activated, the anti-virus system is updated periodically, and vulnerabilities are patched and maintained. Enhanced protection is provided for important machines. Micromolecule firewalls are adopted to enhance lateral protection. iST has joined SP-ISAC and TWCERT/CC to receive and share critical cybersecurity threat intelligence and strengthen collaborative cyber defense.
Information Security and Risk Management
Creating customer value is a cornerstone of iST's sustainable development strategy. As a professional technical service provider, iST understands that providing accurate and precise data accelerates customers' R&D progress. Given that analytical data represents the proprietary property and intellectual fruits of our clients, we are committed to ensuring its absolute security and integrity.
Information Security and Management Structure
To ensure the security of iST's and the customers’information assets, the Company has set up a Security Governance Committee to integrate internal resources and perform information security risk assessment as well as developing annual information security plans and inspection standards. We also coordinate relevant resources and activities across units to implement various information security controls, annual education and training on information security for employees, and information security audits. The Security Governance Committee holds meetings biannually to review and resolve on information security and protection guidelines and policies in order to realize the effectiveness of the information security management measures. The committee may also hold a meeting from time to time based on the needs of management of information security risk. The convener of the Security Governance Committee represents the committee and reports to the board of directors every year. iST obtained the certification of ISO/IEC 27001 Information Security Management System (ISMS) in October 2020. The validity of certification expires on Oct. 15, 2026.
The Chief Information Security Officer is the convener of the meeting of security control committee, with Heads of Divisions as ex officio members, Information Security Implementation Team, Emergency Response Team, Information Security Audit Team and Document Management Center. A total of 25 people as listed above.
iST establishes various information security measures through three operating policies – “Establishing a dedicated information security organization,”“Obtaining support from senior management,”“Implementing all-staff participation,”and in compliance with relevant requirements of ISO/IEC 27001 information security management system, such as information security policies, management procedures, and operating standards, in order to safeguard the security and interests of iST and its customers’ information assets.
Information security policy and specific management plan
iST enhances the personnels awareness of information security and overall security resilience through“Establishing Multifaceted Information Security Message Communication”and“Implementing Information Security Educational Training”.
iST information security technical measures are planned and implemented in five major aspects to continuously strengthen information security protection capabilities.
Allocate resources for cybersecurity management
To achieve the vision of our cybersecurity policy, we have allocated resources to implement the following cybersecurity protection measures:
Information security protection measures
Enhance personnel information security literacy
  • Cyber security training course:New employees are required to complete the education training on information security arranged for new employees. Each employee receives a follow-up training every year.
  • Enhancement of cybersecurity awareness:Electronic newsletters or notices about cyber security are sent from time to time to help employees get to know cyber security practices and understand types of the cyber security attacks occurring externally.
    16 newsletters/notices were sent in 2025.
  • Social engineering drills:Annual training sessions and phishing email simulations are conducted to validate employees’ cybersecurity awareness.
    Two phishing email test was held in 2025.
  • Respect of intellectual property right:iST prohibits the use of illegal, cracked, or portable software.
  • Enhancement of cyber security skills:Security specialists are assigned to attend external seminars, security tool training, and offensive and defensive hacking courses on an irregular basis to strengthen cybersecurity knowledge and capabilities.
    14.5 hours per person in 2025.
Reinforce data protection and access control
  • Encryption:Document encryption software is installed to protect confidential information files and reduce the risk of unauthorized disclosure of confidential information.
  • Authorization:Access to the files is controlled by setting levels of authorization based on necessity.
  • Network management:Warnings are issued, and inspection is conducted, for abnormal network traffic. External data transmission requires prior application and approval.
  • Access control:Employees are not allowed to bring in personal storage devices or use personal equipment to take photos or film. The use of storage devices via USB ports is prohibited.
Implement routine IT operations and risk management
  • Audit and improvement:Systems are inspected and improved periodically. New technologies are adopted to enhance data protection. Compliance with requirements of the management system is secured through internal audits conducted periodically and audits conducted by external cyber security certification units. In 2025, an internal audit and an external verification audit were conducted, and the information security task force held a meeting every month to review relevant matters.
Ensure the stability and availability of critical services
  • Backup management:Implemented a backup appliance. Important systems are backed up and are renewed or upgraded for cyber security subject to the annual plan.
  • Cybersecurity:To enhance protection of internal and external cyber attacks, the firewall policy is adjusted and review, the detection of cyber attacks is activated, the anti-virus system is updated periodically, and vulnerabilities are patched and maintained. Enhanced protection is provided for important machines. Micromolecule firewalls are adopted to enhance lateral protection. iST has joined SP-ISAC and TWCERT/CC to receive and share critical cybersecurity threat intelligence and strengthen collaborative cyber defense.