Information Security Policy

Information Security Policy and Information Security Objectives

1. Policy Purpose
The Agency Business Division of  Atenlab Corporation. (hereinafter referred to as “the Department”) establishes this Information Security Policy (hereinafter referred to as “this Policy”) in order to promote the Information Security Management System (ISMS), create a secure and reliable information operating environment, and ensure the security of data, systems, equipment, and networks, thereby safeguarding the security of information operations.

2. Scope of Application
All employees of the Department and all relevant internal and external stakeholders are responsible for complying with this Policy.

3. Responsibility for Information Security
All employees of the Department and external personnel shall bear in mind that:
“Information and communication security is everyone’s responsibility.”

4. Information Security Policy and Objectives

4.1 Information Security Management and Regulations

4.1.1 All employees of the Department and external parties who need to access sensitive areas such as the Department’s server room, or participate in confidential projects, must undergo identity verification and comply with the requirements of national laws and relevant customer regulations related to information security, including the National Security Protection Act, Cyber Security Management Act, Personal Data Protection Act, Copyright Act, and Criminal Code. No information leakage or illegal activities shall occur; otherwise, legal liability will be pursued in accordance with the law.

4.1.2 Third parties entrusted to handle the Department’s commissioned operations shall ensure that their relevant procedures and environments are equipped with comprehensive information security management measures or have passed third-party verification.
If a third party further subcontracts any commissioned work, the scope and parties involved in the subcontracting must also implement appropriate information security protection measures.

4.2 Information Security Objectives and Measurement Indicators

4.2.1 Confidentiality Objective and Measurement Indicator:
No substantiated complaints due to leakage of sensitive information shall occur each year.

4.2.2 Integrity Objective and Measurement Indicator:
No substantiated complaints due to data tampering resulting from unauthorized intrusion shall occur each year.

4.2.3 Availability Objective and Measurement Indicator:
The cumulative annual system downtime shall not exceed 30 days.

4.2.4 Compliance Objective and Measurement Indicator:
An annual review of the information security management system shall be conducted. There shall be no substantiated complaints resulting from violations of national regulations such as the National Security Protection Act or the Personal Data Protection Act.

4.2.5 Information Security Management System or Security Awareness Training Indicator:
Employees shall receive no less than 3 hours per year of ISMS or information security awareness training.

4.2.6 Professional Training Indicator:
Designated information security personnel shall receive no less than 6 hours per year of professional cybersecurity training.

5. Policy Review

5.1 This Policy shall be reviewed and evaluated at least once per year to ensure compliance with relevant government regulations and international standards, and to maintain the effectiveness of information security management operations.

5.2 This Policy must be approved by the Information Security Management Committee, announced by the top management, and shall take effect on the date of announcement. All internal employees and external parties shall be notified in writing, electronically, or by other means to comply with this Policy. The same procedure applies to any revisions.


Top Management & Convener of the Information Security Committee:
Wu Meng-Hsueh
(Information Security Incident Complaint Email: billwu@atenlab.com.tw)

Information Security Officer & Executive Member of the Information Security Committee:
Liu Zheng-Ting
(Information Security Incident Reporting Email: city_liu@atenlab.com.tw)