Purpose

The purpose of the Information Security Policy of Yu-Chen System Technology Corp. (hereinafter referred to as the Company) is to establish, maintain, and enhance an information security management system to ensure the proper protection of the company's information assets and to ensure that our project operations are conducted in a secure environment.

  Applicability

This policy applies to all personnel of the Company, including internal employees and external partners.

  Definitions

Terms and definitions in this policy may refer to relevant laws and standards to ensure consistency and clarity.

  Vision and Objectives

(a) Information Security Policy Vision: Provide critical operational information services, government-commissioned software development, operation, and data center management.
(b) Information Security Objectives: Increase employee awareness of information security through information security education and training.
(c) Ensure that the development process complies with security standards.
(d) Adhere to contractual obligations.

  Responsibilities

(a) Information Security Execution Team:

(b) The Information Security Execution Team implements this policy through appropriate standards and procedures.
(c) All personnel and outsourced service providers must adhere to relevant security management procedures to maintain information security policy.
(d) Any behavior that jeopardizes information security will be subject to civil, criminal, and administrative responsibilities, or disciplinary actions in accordance with the Company's relevant regulations.

  Review

This policy should be reviewed at least annually to reflect the latest developments in regulations, technology, and business.

  Implementation

The Information Security Policy, approved by the convener, will be implemented from the date of issuance, and any modifications will follow the same process.

  ISO 27001 Information security management systems