Skip to content
  • Contact
    • Worldwide Branches
    • Corresponding Contact Person Info.
    • Contact Form
  • Human Resource
    • Delight Living in CHC
    • Career in CHC
    • Recruitment Information
  • 简
  • 繁
  • EN
CHC Healthcare Group
  • About CHC
    • About CHC
    • Business Philosophy
      • Corporate philosophy
      • Corporate Identity
    • Milestones
    • Structure & Team
    • Quality Policy
    • Global Offices
  • Business
    • Business Scope
    • Partner Relationship
  • Investors
    • Financial Information
      • Monthly Operating Revenues
      • Financial Statements
    • Shareholder Services
      • Stock Quote
      • Dividend Information
      • Shareholders’ Meeting
      • Major Shareholders
    • Events & News
      • Investor Calendar
      • Material Information
    • FAQ
    • Contact Us
  • Corporate Governance
    • Board of Directors and Functional Committees
      • Board of Directors
      • Audit Committee
      • Compensation Committee
      • Sustainability Committee
    • Risk Management Committee
    • Corporate Governance Implementation Status
      • Corporate Governance Policy
      • Corporate Ethical Management
      • Intellectual Property Management
    • Internal Audit
    • Internal Policies
    • Whistleblowing System
    • Information security risk management
  • Sustainability
    • Sustainability Committee
      • Organization
      • Plans & Results
    • Stakeholders
      • Stakeholder Engagement
      • Customers
      • Suppliers
      • Investors
      • Employees
      • General Public
    • Events & News
    • Sustainability Reports
  • Media Center
    • All
    • Corporate
    • Financial
    • Sustainability
    • Events
    • Contact
      • Worldwide Branches
      • Corresponding Contact Person Info.
      • Contact Form
    • Human Resource
      • Delight Living in CHC
      • Career in CHC
      • Recruitment Information
    • 简
    • 繁
    • EN
  • Contact
    • Worldwide Branches
    • Corresponding Contact Person Info.
    • Contact Form
  • Human Resource
    • Delight Living in CHC
    • Career in CHC
    • Recruitment Information
  • 简
  • 繁
  • EN
CHC Healthcare Group
  • About CHC
    • About CHC
    • Business Philosophy
      • Corporate philosophy
      • Corporate Identity
    • Milestones
    • Structure & Team
    • Quality Policy
    • Global Offices
  • Business
    • Business Scope
    • Partner Relationship
  • Investors
    • Financial Information
      • Monthly Operating Revenues
      • Financial Statements
    • Shareholder Services
      • Stock Quote
      • Dividend Information
      • Shareholders’ Meeting
      • Major Shareholders
    • Events & News
      • Investor Calendar
      • Material Information
    • FAQ
    • Contact Us
  • Corporate Governance
    • Board of Directors and Functional Committees
      • Board of Directors
      • Audit Committee
      • Compensation Committee
      • Sustainability Committee
    • Risk Management Committee
    • Corporate Governance Implementation Status
      • Corporate Governance Policy
      • Corporate Ethical Management
      • Intellectual Property Management
    • Internal Audit
    • Internal Policies
    • Whistleblowing System
    • Information security risk management
  • Sustainability
    • Sustainability Committee
      • Organization
      • Plans & Results
    • Stakeholders
      • Stakeholder Engagement
      • Customers
      • Suppliers
      • Investors
      • Employees
      • General Public
    • Events & News
    • Sustainability Reports
  • Media Center
    • All
    • Corporate
    • Financial
    • Sustainability
    • Events
    • Contact
      • Worldwide Branches
      • Corresponding Contact Person Info.
      • Contact Form
    • Human Resource
      • Delight Living in CHC
      • Career in CHC
      • Recruitment Information
    • 简
    • 繁
    • EN

Corporate Governance

Home  >  Information security risk management

Information security risk management

  • Board of Directors and Functional Committees
    • Board of Directors
    • Audit Committee
    • Compensation Committee
    • Sustainability Committee
  • Risk Management Committee
  • Corporate Governance Implementation Status
    • Corporate governance policy
    • Corporate structure & department operations
    • The Responsibility of Corporate Governance Officer
    • The refresher programs for Corporate Governance Officer
    • Implementation Results of Designated Unit in Charge for Corporate Governance
    • Implementation Results of Designated Unit in Charge for Corporate Ethical Management
    • Implementation Results of Designated Unit in Charge for Intellectual Property Management
  • Internal Audit
  • Internal Policies
  • Whistleblowing System
  • Information security risk management

Information security risk management

Describe the information and communications security risk management framework, information and communications security policies, specific management plans, and resources invested in information and communications security management.

Information and Communications Security Risk Management Organizational Structure

The Company has established an Information Department to be responsible for information security governance, planning, supervision and implementation, and regularly reports the status of information security management operations to the General Manager.

Department Main Responsibilities
General Manager

Responsible for approving the scope, policies and senior management decisions of the information security management system.

Information Departmen

The head of the Information Department is responsible for the execution and management of information security risk management and the summary and reporting of the implementation status of each group to the general manager.

Information Security Executive Team

Members of the information unit are responsible for planning and implementing various information security operations.

Emergency Response Team

Led by the information unit, the team members are assisted by the persons in charge of key business processes, and seek guidance from professional information security vendors on the best response solutions.

Internal Audit Team

Check the information security management system and the management of all control measures, submit audit reports, and track improvements.

Information security consulting

The company cooperates with professional information security vendors to provide necessary information security improvement suggestions and plans, and performs information security related testing at irregular intervals every year.

Information Security Policy

  1. Ensure the security of the company’s data, systems, equipment and network communications, and prevent external intrusion and sabotage.
  2. Ensure that system information account access permissions and system changes are authorized according to company-specified procedures.
  3. Scrapped computer storage media should be destroyed to prevent accidental exposure and leakage of data.
  4. Monitor the security status and activity records of information systems to effectively grasp and handle information security incidents.
  5. Maintain the availability and integrity of data and systems so that normal operations can be restored in the event of a disaster or damage.
  6. The information room is equipped with independent fire-fighting equipment with smoke and temperature detection.
  7. In order to ensure that the computer software used in the quality management system/production or service/supervision and measurement of medical devices can achieve the planned results through validation or verification before the computer software is applied or after use or when the software is changed according to the actual situation, the company introduced the Taiwan Medical Device Quality Management System (QMS) in 2011.

Specific management plan

At present, our company has complete information security maintenance measures and considering that information security insurance is still an emerging insurance type, involving supporting facilities such as information security classification and claims identification, we are still in the stage of evaluating its future applicability.
However, the Company has established written internal control systems – computerized information system cycles, information management methods and disaster recovery plans to implement internal control systems and maintain information security policies. Ensure the adequacy and effectiveness of its safety policies and procedures by reviewing and evaluating them annually. The following sub-items are described in detail:

  1. Information security network architecture
    ①The company’s internal systems are all located in a virtual network. The external network is isolated and cannot be directly accessed. Multiple network security defense systems have been adopted, including a firewall at the front end of the network and an intrusion prevention connection screening system.
    ②Use Chunghwa Telecom HiBox mailbox for emails. Chunghwa Telecom HiBox mailbox has a security control system that is responsible for filtering the content of network inbound and outbound connections, which can defend against external network attacks and instantly block the latest malicious software, harmful website links, junk emails and other threats.
    ③Anti-virus software is deployed on all internal hosts and endpoints to update virus codes at any time and identify malicious behavior characteristics in real time. It can instantly intercept viruses, Trojans, worms, ransomware, malicious programs in folders, etc., effectively reducing the risk of damage by hacker attacks.
  2. System account and permission account management
    User accounts and permissions are set according to business scope and responsibilities. Data access must be approved by the responsible supervisor through an electronic form approval process before it can be used and changed. Once a user leaves his or her original position, his or her account and permissions will be revoked immediately to prevent unauthorized use.
  3. Information system preservation and backup
    The system and documents are backed up locally and off-site daily, and system data recovery test drills are performed regularly every year to ensure the normal operation of the information system and data preservation, which can reduce the risk of data loss caused by natural disasters and man-made disasters without warning.
  4. Disposal of scrapped host
    All scrapped hosts will have their hard drives dismantled and destroyed to comply with regulatory compliance management systems and information security policies.

Resources invested in information security management - annual implementation status

2025 Implementation Status of InfoSec Resources
2024 Implementation Status of InfoSec Resources
2023 Implementation Status of InfoSec Resources

CHC Healthcare Group

Provide the most reliable healthcare management services
The leader of healthcare equipment, technology and service in the Asia-Pacific region

Contact Address.

No. 88, Xing’ai Rd., Neihu Dist., Taipei City 114067, Taiwan, R.O.C.
(886) 2 6608 1999

Links

About CHC
Business
Investor Relations
Corporate Governance
Sustainability
Media Center
Contact Us
Human Resource

Subsidiaries of CHC Healthcare Group

CHIU HO MEDICAL SYSTEM
CHIU HO SCIENTIFIC
SHIN HO BIOTECH
CHC Healthcare (UK) Limited

Copyright © 2026 CHC. All rights reserved.

Use Notice | Privacy Policy
In order to enhance the experience in your use, the Website uses analytics cookies technology. By continuing to browse contents of this Website, you agree to our use of cookies. Please refer to our Privacy Policy for more information about cookies.
SettingI Accept
Setting

Privacy Policy

In order to enhance the experience in your use, the Website uses analytics cookies technology. By continuing to browse contents of this Website, you agree to our use of cookies. Please refer to our Privacy Policy for more information about cookies.
SAVE & ACCEPT