To maintain the confidentiality, integrity, and applicability of Phison's assets and protect users' information privacy, we clearly stipulated in our information security policies that employees
shall avoid unauthorized access and revisions while respecting intellectual property rights and protecting the information of customers and the Company. Anyone who discovers information
security incidents or suspicious security weaknesses should report them to the Information Department through our reporting mechanism, at which point our Information Department personnel will conduct proper investigations and handle the matter appropriately.
It is the responsibility of all Phison personnel to follow our Information Security Policies. Company personnel who violate our information security policies shall face civil, criminal, or administrative responsibilities according to the severity of the violation, or penalties according to relevant rules. The policies are also integrated with the Company's employee performance evaluation
to reduce instances of employees being penalized or facing legal responsibilities due to information security violations and also reduce the Company's information security risks.
In accordance with ISO27001 certification guidelines, the Company conducts annual internal audits as well as external audits conducted by third-party verification agencies. No major errors have been found in recent years. We also perform information system recovery mechanism drills to test the effectiveness of our information system recovery procedures to ensure that the Company's system can continue to operate even if subject to natural disasters or malicious attacks. The Company also frequently scans for vulnerabilities. We officially introduced the Security Scorecard information security system in August 2019, and through continuous upgrades and enhancements. The Company also frequently scans for vulnerabilities. We officially introduced the Security Scorecard information security system in August 2019, and have since maintained an A rating (a score of 90 or above).
The Company quarterly announces and disseminates information about information security, so as to raise the information security awareness of all employees. The topics specified on the information security notification issued by the Information Technology Div. in 2021 include the alert for a fraud conducted through a phishing website, prevention and emergency response procedures for ransomware attacks, prevention of stealer software and melware, and information on prevention of fraud. In 2021, the contents of information security training courses include enterprise information security trends, dissemination of most recent cases, information security policy, and code of personnel information security conduct, while the contents of training courses on personal data/privacy include introduction of the Personal Information Protection Act, and EU's GDPR regulations and case review. 100% employees have completed the information security courses and the personal data/privacy protection courses.