- Latest ESG News
- Sitemap
- Stakeholder Service
- Management Commitment and Philosophy
- Sustainability Performance
- Corporate Sustainability Management
- Corporate Governance
- Sustainable Supply Chain Management
- Conflict Minerals Management
- Sustainable Envrionment
- Talent Transition and Happiness in Workplace
- Social Participation
- Interactive zone
- Policy and Certificate
- Sustainability Report
▶️Information Security Management
Information Security Governance
To ensure secure and reliable information management systems and electronic exchange environments for each company within the group, and as well as ensuring the security of the data, servers, application systems, equipment, and networks, the implementation guiding principles of the "Information Security Management Regulations" are established by WPG Holdings. This framework aims to avoid information assets from being improperly accessed, disclosed, altered, damaged, or otherwise compromised as a result of human error, malicious actions, or natural disasters.
Information Security Governance
To effectively promote various tasks of the information security management system, the "Information Security Management Committee" is established by WPG Holdings, with the CEO of WPG Holdings serving as the convener. Under the Information Security Management Committee, an information security management team is established, within which the Chief Information Security Officer is responsible for comprehensively managing information security policy promotion and resource deployment affairs, with meetings convened monthly.

● Information Security Management Measures
Comprehensive Information Security Management Regulations are formulated by WPG Holdings. The validity of the ISO 27001:2022 transition
certification as well as the validity of the ISO 27017 Information Security Controls for Cloud Services certification are maintained.


● Information Security Incidents
If an information security incident involves regulatory violations, relevant competent authorities shall be actively notified, full cooperation shall be provided throughout the review process, and relevant evidence shall be retained. No major information security incidents or confidential data leakages have occurred at WPG over the past three years, nor have any losses been caused to the company and customers.
● Information Security-Related Incidents

● Information Security-Related Education Training and Awareness Promotion
Educational training for information security is carried out annually by the information security execution unit, with training outcomes consolidated and tracked. With this, annual information security training requirements are established, Concurrently, upon the official appointment of new employees, educational training related to information security topics is arranged to ensure that employee responsibilities and obligations are understood and employee information security awareness is enhanced. Regarding managers and employees across the Group, relevant precautions regarding recent information security incidents are promoted from time to time.

● Business Continuity Plan
The Business Continuity Plan (BCP) is promoted by WPG Holdings. In the event of system abnormalities where services cannot be provided normally, all system services shall be switched to the backup data center to avoid the disruption of system services that would prevent normal operations.
Testing and reviews are conducted by WPG Holdings at least once annually, with the execution contents detailed as
follows:
