The Company established an Information and Cyber Security Office on September 1, 2022, with one information security officer and one dedicated information security personnel. To effectively promote the implementation and operation of the company's Information Security Management System (ISMS), the Information and Cyber Security Management Committee was established on December 18, 2024, with the General Manager serving as the convener. A deputy convener and an executive secretary were appointed to coordinate the various tasks of the Information and Cyber Security Management Committee. Information security management representatives from the management levels of various business divisions and functional units are responsible for assisting in promoting and supervising the information security work of each unit. An Information Security Working Group was set up, divided into the following subgroups based on responsibilities: (1) Incident Response Team, (2) Information Asset Risk Management Team, (3) Document Management Team, and (4) Audit Team. Regarding the implementation and operation of the Company's Information Security Management System (ISMS), the system was officially announced in February 2025. The verification team from BSI Taiwan completed the two-phase verification in April 2025. After final confirmation by BSI Taiwan and headquarters, the ISO 27001:2022 certificate was issued in May, 2025.
In alignment with the core business characteristics of the Company, the Policy establishes a framework to protect the rights and interests of the Company and its stakeholders. (including but not limited to employees, customers, vendors/upstream suppliers, shareholders, investors and financial/securities institutions, non-vendor suppliers/contractors, and government/competent authorities and society). All employees and the Company are collectively responsible for fostering a safe information and communication environment, enabling information security to be embedded into its corporate culture. The Company will implement a tailored-information security policy to clearly define security objectives and establish compliance requirements which shall be consistently upheld. For detailed information, please refer to the "Information and Cyber Security Policy" published on the Company's official website (Approved by the Board of Directors on January 13, 2025).
Organizer | Course / Awareness Topic | Hours / Frequency | Participants |
---|---|---|---|
Taiwan Corporate Governance Association | Information Security Governance and Supervisory Strategies for the Board of Directors | 3 hours | Chief Information Security Officer Obtained a certificate from Taiwan Corporate Governance Association |
Chunghwa Telecom | Personal Data Protection Act Education and Training | 3 hours | Chief Information Security OfficerNote |
Taiwan Academy of Banking and Finance | Information Security Awareness, Essential Knowledge and Responsibility | 2 hours | Chief Information Security Officer Certificate Obtained from Taiwan Academy of Banking and Finance |
Explanation and Preventive Measures of Information Security Incidents | 2.5 hours | ||
Explanation of Cybersecurity Management Guidelines for Listed Companies | 1.5 hours | ||
Yuan Ze University remote course | Emergency Response Handling for Information Security Incidents | 3 hours | Certificate Obtained from Yuan Ze University |
MIS / Information and Cyber Security Office (ICSO) | Information and cyber security education for new employees | 3 sessions | 44 new employees |
Chunghwa Telecom | Personal Data Protection Act Education and Training | 3 hours | 439 on-the-job employeesNote |
Chunghwa Telecom | Information Security Management System (ISMS) Introductory Meetings | 16 times | 23 information / cyber security and project team personnel |
MIS / Information and Cyber Security Office (ICSO) | MIS Cybersecurity Awareness – “Information and Cyber Security and Software Use” and “Cybersecurity Intelligence” | 27 times | All employees |
Note: The participants in the Personal Data Protection Act Education and Training included 439 on-the-job employees, including the Chief Information Security Officer.
In 2023 and 2024, the Company had not suffered any losses or affected operations, goodwill, etc. due to the occurrence of material information and cyber security incidents.