Investor Zone > 

Information Security

Information Security

INFORMATION SECURITY POLICY

 

POLICY STATEMENT

International Integrated Systems, Inc. (IISI) maintains a strong commitment to information security and the protection of personal data, upholding the belief that “information security is everyone’s responsibility.” The organization has successfully fulfilled stringent information security requirements and achieved the ISO/IEC 27001 Information Security Management System certification, demonstrating alignment with international standards.
Furthermore, IISI adheres to the Personal Data Protection Act and relevant regulations, establishing a robust personal data protection system. This ensures all employees possess the awareness and capability to safeguard information and personal data. Consequently, business execution, personal data processing, and information system operations are conducted securely and effectively, preventing security incidents that could compromise information confidentiality, integrity, or availability, and safeguarding the security of information services.

MEASURES

In compliance with the requirements of the ISO/IEC 27001:2022 standard, IISI has established a comprehensive Information Security Management System (ISMS) and related governance framework. To ensure the effectiveness of its security controls and continuous improvement, IISI conducts annual asset inventories and updates, risk assessments, disaster recovery drills, vulnerability assessments, penetration testing, internal audits, management reviews, and periodic social engineering drills. Through these systematic measures, IISI strengthens its cybersecurity resilience, enhances risk management capabilities, and safeguards the confidentiality, integrity, and availability of its information assets.

COMPLIANCE AND TRAINING

To maintain a high standard of compliance, IISI is dedicated to promoting information security and personal data protection by integrating security and privacy requirements into corporate policies, such as personnel reward and penalty regulations, as well as new hire employment contracts.
To cultivate robust security awareness, all employees must complete mandatory annual training and achieve a perfect score on their final assessments.

Information Security is Everyone's Responsibility
Information Security is Everyone’s Responsibility
Scroll to Top