中華龍網 DragonSoft
Menu

Information Security Policy

Last updated: 2025-07-01

Policy Purpose

DragonSoft Security Associates, Inc. (hereinafter "the Company") has established this Information Security Policy (hereinafter "this Policy") to ensure the smooth operation of its business, advance its Information Security Management System (ISMS), and build a secure and trustworthy information operating environment. This Policy aims to prevent unauthorized access, use, control, disclosure, destruction, alteration, or other compromise of information or communication systems, and to ensure their confidentiality, integrity, availability, and legal compliance — thereby safeguarding information security, enhancing service quality, and achieving the goal of sustainable operations.

Scope of Application

All employees, partners, and units of the Company are responsible for complying with this Policy.

Security Policy and Objectives

To implement information security management, the Company complies with the requirements of ISO 27001 (Information Security Management System).

An information security management organization has been established, responsible for establishing and promoting the information security management system.

The collection, processing, and use of personal data shall respect the rights of data subjects, be conducted in good faith, not exceed the scope necessary for specific purposes, and bear a legitimate and reasonable connection to the purpose of collection.

Information security education and training are conducted regularly to promote this Policy and related implementation rules.

Policy Review

This Policy and its objectives shall be evaluated and reviewed at least once a year to comply with relevant government regulations and reflect the latest developments in information technology, ensuring the effectiveness of information security management operations.

This Policy shall be reviewed by the Management Committee or approved by the Management Representative, and shall take effect on the date of announcement. All employees, partners, and units shall be notified to comply via written notice, electronic communication, training sessions, internal meetings, or other means; the same applies to any subsequent amendments.

Last updated: 2025-07-01