- Home
- Governance Leadership
- Information Security Management
Information Security and Risk Management
Creating customer value is a cornerstone of iST's sustainable development strategy. As a professional technical service provider, iST understands that providing accurate and precise data accelerates customers' R&D progress. Given that analytical data represents the proprietary property and intellectual fruits of our clients, we are committed to ensuring its absolute security and integrity.
Information Security and Management Structure
To ensure the security of iST's and the customers’information assets, the Company has set up a Security Governance Committee to integrate internal resources and perform information security risk assessment as well as developing annual information security plans and inspection standards. We also coordinate relevant resources and activities across units to implement various information security controls, annual education and training on information security for employees, and information security audits. The Security Governance Committee holds meetings biannually to review and resolve on information security and protection guidelines and policies in order to realize the effectiveness of the information security management measures. The committee may also hold a meeting from time to time based on the needs of management of information security risk. The convener of the Security Governance Committee represents the committee and reports to the board of directors every year. iST obtained the certification of ISO/IEC 27001 Information Security Management System (ISMS) in October 2020. The validity of certification expires on Oct. 15, 2026.
The Chief Information Security Officer is the convener of the meeting of security control committee, with Heads of Divisions as ex officio members, Information Security Implementation Team, Emergency Response Team, Information Security Audit Team and Document Management Center. A total of 25 people as listed above.
iST establishes various information security measures through three operating policies – “Establishing a dedicated information security organization,”“Obtaining support from senior management,”“Implementing all-staff participation,”and in compliance with relevant requirements of ISO/IEC 27001 information security management system, such as information security policies, management procedures, and operating standards, in order to safeguard the security and interests of iST and its customers’ information assets.

Information security policy and specific management plan
.jpg)
iST enhances the personnels awareness of information security and overall security resilience through“Establishing Multifaceted Information Security Message Communication”and“Implementing Information Security Educational Training”.
iST information security technical measures are planned and implemented in five major aspects to continuously strengthen information security protection capabilities.
.jpg)
Allocate resources for cybersecurity management
To achieve the vision of our cybersecurity policy, we have allocated resources to implement the following cybersecurity protection measures:
| Information security protection measures | |
| Enhance personnel information security literacy |
|
| Reinforce data protection and access control |
|
| Implement routine IT operations and risk management |
|
| Ensure the stability and availability of critical services |
|

Information Security and Risk Management
Creating customer value is a cornerstone of iST's sustainable development strategy. As a professional technical service provider, iST understands that providing accurate and precise data accelerates customers' R&D progress. Given that analytical data represents the proprietary property and intellectual fruits of our clients, we are committed to ensuring its absolute security and integrity.
Information Security and Management Structure
To ensure the security of iST's and the customers’information assets, the Company has set up a Security Governance Committee to integrate internal resources and perform information security risk assessment as well as developing annual information security plans and inspection standards. We also coordinate relevant resources and activities across units to implement various information security controls, annual education and training on information security for employees, and information security audits. The Security Governance Committee holds meetings biannually to review and resolve on information security and protection guidelines and policies in order to realize the effectiveness of the information security management measures. The committee may also hold a meeting from time to time based on the needs of management of information security risk. The convener of the Security Governance Committee represents the committee and reports to the board of directors every year. iST obtained the certification of ISO/IEC 27001 Information Security Management System (ISMS) in October 2020. The validity of certification expires on Oct. 15, 2026.
The Chief Information Security Officer is the convener of the meeting of security control committee, with Heads of Divisions as ex officio members, Information Security Implementation Team, Emergency Response Team, Information Security Audit Team and Document Management Center. A total of 25 people as listed above.
iST establishes various information security measures through three operating policies – “Establishing a dedicated information security organization,”“Obtaining support from senior management,”“Implementing all-staff participation,”and in compliance with relevant requirements of ISO/IEC 27001 information security management system, such as information security policies, management procedures, and operating standards, in order to safeguard the security and interests of iST and its customers’ information assets.

Information security policy and specific management plan
.jpg)
iST enhances the personnels awareness of information security and overall security resilience through“Establishing Multifaceted Information Security Message Communication”and“Implementing Information Security Educational Training”.
iST information security technical measures are planned and implemented in five major aspects to continuously strengthen information security protection capabilities.
.jpg)
Allocate resources for cybersecurity management
To achieve the vision of our cybersecurity policy, we have allocated resources to implement the following cybersecurity protection measures:
| Information security protection measures | |
| Enhance personnel information security literacy |
|
| Reinforce data protection and access control |
|
| Implement routine IT operations and risk management |
|
| Ensure the stability and availability of critical services |
|

