BlockChain Security (hereinafter referred to as "the Company") is committed to strengthening its information security management and ensuring the confidentiality, integrity, and availability of its information assets. This policy is established to provide a secure information environment that supports the continuous operation of the Company's business activities and complies with applicable legal and regulatory requirements. It is designed to protect the Company's information assets from both intentional and accidental internal and external threats.
This policy applies to all employees, contractors, temporary personnel, and supplier personnel of the Company.
- Information Assets: Hardware, software, services, documentation, and personnel required to support the normal operation of the Company's information systems and business activities.
- Information Environment for Business Continuity: The computing and information technology environment necessary to ensure the uninterrupted operation of the Company's business functions.
The Company is committed to maintaining the confidentiality, integrity, and availability of its information assets while safeguarding user privacy. Through the collective efforts of all personnel, the Company aims to achieve the following objectives:
- Protect business information from unauthorized access, disclosure, alteration, or destruction, ensuring its accuracy and completeness.
- Establish a cross-functional information security organization responsible for developing, implementing, promoting, and continuously improving information security management practices to support business continuity.
- Conduct information security awareness and training programs to strengthen employees' understanding of information security responsibilities and best practices.
- Implement information security risk assessment mechanisms to enhance the effectiveness and timeliness of security management.
- Establish and maintain an internal information security audit program to ensure compliance with information security requirements and controls.
- Ensure that all business operations comply with applicable laws, regulations, and contractual obligations relating to information security.
- The Company's management is responsible for establishing, approving, and reviewing this policy.
- The Information Security Committee is responsible for implementing this policy through appropriate standards, procedures, and controls.
- All employees and outsourced service providers must comply with relevant security management procedures to uphold this policy.
- All personnel are responsible for promptly reporting information security incidents and any identified vulnerabilities or weaknesses.
- Any actions that compromise information security may result in disciplinary measures and, where applicable, civil, criminal, or administrative liability in accordance with relevant laws and Company regulations.
This policy shall be reviewed at least annually to reflect changes in applicable laws, regulations, technologies, and business requirements, ensuring the Company's continued operational resilience and information security effectiveness.
The Company adopts the PDCA (Plan-Do-Check-Act) continual improvement framework to establish a structured and documented management system. Through ongoing monitoring, periodic audits, and regular management reviews, the Company continually improves the suitability, adequacy, and effectiveness of its information security management system.
This policy shall become effective upon review and approval by the Chairperson of the Information Security Committee and subsequent publication. Any revisions to this policy shall follow the same approval process.