Operation and Governance
Information Security Management
Effective cybersecurity management is fundamental to all operations. To ensure company has consensus of cybersecurity goals, USI set up a committee to boost cybersecurity awareness. The committee members are composed of CIO, CFO, GISO, Vice Presidents or Division heads level above, CIO shall report to Senior Vice President of Administration Group. Under the committee, there are information security representatives to assist the Information Security Committee in implementing cybersecurity affairs. USI have gotten ISO 27001:2013 Certification in 2020 and the cybersecurity management is further implemented in the USI Group. To be a gatekeeper of company cybersecurity, IT members not only take professional training courses, but also need be certified to ensure the effectiveness of our cybersecurity organization can systematically solve cyber incidents. USI had no cybersecurity incidents in 2021.
Cybersecurity Goals
The Company's cybersecurity objectives are to ensure the preservation of Confidentiality, Integrity, Availability and Compliance of the core systems engaged in business operations. Additionally, quantitative goals are defined according to organization level and job function to ensure the achievements of the ISMS implementations and cybersecurity objectives.
1. Protect USI's important information assets, including USI and customer products, manufacturing processing information and recipe, R&D information, services, and maintain their confidentiality, integrity, and availability.
2. Strengthen USI employee's awareness of the company's and customer's information asset protection responsibilities.
3. Ensure that the execution of all business comply with the requirements of relevant laws or regulations.
4. Construct a safe and convenient information network environment to protect employees from internal and external cybersecurity threats.
5. Establish a cybersecurity sustainability plan to ensure the business contingency.
6. In-depth assess existing cybersecurity level and enhance the maturity of entire cybersecurity management.