About Us

Information Security Policy

The company's information security control measures aim to protect the confidentiality, integrity, and availability of personal and vital company data. By strengthening information security management, we ensure the safety of data, systems, equipment, and networks, create a reliable IT environment, deploy innovative defense technologies, and thoroughly implement security operations. To achieve these goals, the key policy regulations are defined below:

Internal Audit

  • The Information Security Committee shall establish the "Internal Audit Operating Procedures" to define the standards for internal audit operations.
  • Internal audits must be conducted at least once a year, or when requested by the Committee Chairman if necessary.

Prohibition of Unauthorized Network Connections

  • To maintain internal network security, employees are strictly prohibited from bridging external networks with the company's internal network, or connecting unauthorized network devices (e.g., Hubs, Routers, APs) to the corporate network.
  • If testing operations at designated test sites require connection to the internal network, employees must notify the IT Department in advance for configuration assistance. Unauthorized connections are strictly forbidden.

Antivirus Software Installation

  • All computers accessing the company's internal network must have the designated antivirus software installed.
  • The antivirus software will automatically update virus definitions and perform scans daily to defend against the latest security threats.
  • If a computer is suspected of being infected, immediately disconnect the network cable to prevent the spread of the virus and contact the IT Department promptly for assistance.

Software Updates

  • Over time, security vulnerabilities may emerge in software, making systems susceptible to cyberattacks. Software vendors release patches and updates to address these vulnerabilities.
  • Computers joined to the domain will automatically receive and install updates.
  • For non-domain computers, users must pay close attention to OS update notifications and complete updates as instructed to ensure system security.

Firewall Controls

  • Network firewalls prevent unauthorized intrusions via the Internet aimed at corrupting files or stealing confidential data.
  • To ensure network security and effective resource utilization, the corporate firewall will filter all non-work-related websites. Using company network resources for personal use is strictly prohibited.
  • These access restrictions do not apply during lunch breaks or after business hours. Department managers must actively supervise their staff to ensure strict compliance.

Account and Password Management

Passwords are the first line of defense for computer data. Basic security guidelines include:

  • Never share your password with anyone.
  • Do not write passwords down.
  • Set passwords that are difficult to guess.
  • Change passwords immediately if compromise is suspected, and rotate passwords routinely every three months. Do not share company accounts/passwords with clients or vendors, nor use another person's credentials. Contact IT if assistance is needed.
Detailed Account & Password Rules:
  • Users must immediately change their password and inform IT system administrators if unauthorized account access is suspected (whether internal or external).
  • Passwords must be at least 8 characters long and include a combination of uppercase letters, lowercase letters, and numbers.
  • The system enforces password changes every 3 months; new passwords cannot match any of the previous 5 passwords used.
  • Accounts will be locked after 5 failed login attempts. The lock automatically resets after 30 minutes, or users may contact IT for manual unlocking.

Data Confidentiality

  • Folder access permissions on internal File Servers are categorized into: No Access, Read-Only, and Modify. Permission changes require submitting an "IT Service Request Form" approved by the department manager.
  • Storing vital or confidential files in public areas is strictly prohibited, and File Servers must not be used to store personal files. File storage is strictly for business purposes and department sharing.

System Development and IT Assistance Procedures

  • System development, permission configuration, account creation, technical support, and IT equipment procurement must strictly follow internal audit and control procedures by submitting appropriate forms for IT processing.

Software Usage and Installation

  • Personal software installations are prohibited; all installations must be handled by IT personnel.
  • Unauthorized or illegal software is strictly forbidden. Standard installations are limited to Windows and Office. Specialized software (e.g., Acrobat Writer, OrCAD, Allegro) may only be installed in departments that have officially purchased them, strictly adhering to the purchased license count under manager supervision.

Server Room and Equipment Control

  • Unauthorized personnel are forbidden from entering branch office network rooms or operating IT equipment. Server rooms must remain locked, with access restricted to IT personnel. Non-IT personnel require prior notice and IT approval to enter.

Internet Usage Guidelines

  • Company Internet access is restricted to business use only. Using resources for personal matters or utilizing public cloud storage (e.g., Google Drive, O365) is prohibited to prevent data leakage and reputational damage.
  • General instant messaging apps are blocked, except for WeChat, which is restricted to uploading files smaller than 3MB.

Email Usage Guidelines

  • Sending emails containing obscene, immoral, divisive, or damaging content during work hours is forbidden. Violators will have their network privileges revoked immediately upon IT verification.
  • If sending personal emails leads to system malfunction or infection, IT will immediately revoke Email access privileges.
  • When transmitting sensitive data via email, appropriate encryption must be applied to protect confidentiality, along with setting a read receipt request.
  • Using external personal email accounts (e.g., Gmail, Hotmail, Yahoo Mail) is strictly prohibited.

FTP Usage Guidelines

  • Internal FTP account access requires an application stating the business reason, subject to manager approval before IT activation. External FTP access requires submitting the target URL to allow uploads for customer downloads via specific approved IPs.

Data Backup

  • File Servers and Database (DB) systems feature security controls to protect data confidentiality.
  • Critical directories and databases undergo scheduled full or differential backups, accompanied by periodic recovery tests to guarantee data integrity.

IT Asset Management

  • Departments must designate specific custodians and users for all computer equipment.
  • Asset transfers or disposals must follow internal workflows via the intranet's "Fixed Asset Transfer/Disposal Form." Disposals are routed to the Accounting Department for write-off processing.

Confidential Data Management

  • Departments must establish management procedures for physical and digital storage media containing confidential or sensitive data (including paper documents, electronic files, magnetic tapes, floppies, CDs, etc.) to prevent leakage or misuse.

Security Incident Reporting Procedure

Security Incident Identified
Confirm Incident
Report to IT Department
Major Impact Assessment
YES
Report to the General Manager's Office
NO / Continue
Directly Proceed to the Next Step
Activate Response Mechanism
External Support Needed?
YES
Engage External Vendors
NO
Resolve Internally
Incident Resolution & Tracking
Notify Affected Parties (Clients)
Archive Incident Record
Case Closure
  • 9F.-2, No. 33, Huanke 1st Rd., Zhubei City, Hsinchu County 302047
  • Tel:886-3-5509980
  • Fax:886-3-5501880
  • Email:ksmt_svr@ksmt.com.tw