MiTAC
Information Security Management Practices and Policies
Pages
9
Time to read
4 mins
Publication
Language
English
Pages
9
Time to read
4 mins
Publication
Language
English
This document is a technical report detailing the information security management practices at MiTAC. It outlines the establishment of an Information Security Promotion Committee led by the President, with key roles assigned to senior management and dedicated cybersecurity personnel. The report describes the implementation of the ISO27001 standard in 2019, highlighting the company's commitment to maintaining its certification through annual audits and a recent transition to ISO27001:2022. Additionally, it discusses ongoing educational training for employees, including mandatory courses and social engineering drills to enhance awareness. The document also covers cyber security protection measures, including the use of the Cyber Defense Matrix for risk analysis, incident response procedures, and participation in the Taiwan Computer Emergency Response Team for threat intelligence. Furthermore, it details the business continuity drills conducted in 2024, ensuring operational resilience and effective response to potential incidents. The report concludes with a summary of information security targets achieved over the years.