一、資訊安全治理制度、目標與策略
創意電子以打造嚴密有效的資安防禦網為資訊安全願景,以資安治理一致性為基礎,逐步提升全方位防護能力,期望成為於資安治理成熟度表現傑出之企業。資訊安全部統籌資訊安全制度及合規遵循,並推動相關作業的落實,持續提升資安意識與專業能力。透過技術的運用,識別資安風險與弱點,並進行有效的強化,建構完善的治理制度與全方位的資安防護能力,同時培養同仁良好的資訊安全意識。
創意電子為專業的系統晶片設計服務公司,提供設計和一站式代工服務,認定環保、安全與衛生議題為公司經營之重要基石。創意電子持續不斷提升服務及產品的品質,因此我們致力於達成「安全零事故、環境永續發展」,成為世界級之環保、安全與衛生之標竿企業。
創意電子鼓勵所有員工,本著創新與持續改善的精神,提供客戶高品質ASIC服務、量產服務及IP產品組合,並致力於傾聽客戶的聲音,建立與客戶間可信互利的夥伴關係。
創意電子遵循國際品質標準,包括 ISO 9001、ISO13485和 IECQ QC 080000,建立其品質系統管理架構。
產品設計與生命週期評估:創意電子從產品生命週期之設計研發階段,即導入綠色設計,嚴格要求供應商生產製造中不得使用有害物質,確保綠色IC生產,並對產品包材限制有害物質之要求,以避免所有過程對環境造成衝擊,如全球暖化、臭氧層破壞等不同面向。
對環境的潛在衝擊評估
智慧財產權管理
申訴及檢舉辦法
資訊安全政策
資訊安全政策
創意電子以打造嚴密有效的資安防禦網為資訊安全願景,以資安治理一致性為基礎,逐步提升全方位防護能力,期望成為於資安治理成熟度表現傑出之企業。資訊安全部統籌資訊安全制度及合規遵循,並推動相關作業的落實,持續提升資安意識與專業能力。透過技術的運用,識別資安風險與弱點,並進行有效的強化,建構完善的治理制度與全方位的資安防護能力,同時培養同仁良好的資訊安全意識。
1. 建立符合法規與客戶需求之資訊安全管理規範
2. 透過全員認知,達成資安防護,全面落實的共識
3. 保護公司與客戶資訊的機密性、完整性、可用性與法律遵循性
1. 資訊安全委員會
「資訊安全委員會」負責執行資訊作業安全管理規劃,建置與維護資訊安全管理體系,由資訊安全主管督導全公司資訊安全作業執行以及資安風險管理機制之有效性,向總經理報告,每季必須向高階主管管理會議與每年向董事會呈報整體資訊安全管理組織相關資安管理作業及制度之執行成效,讓高階主管與董事會成員充分了解公司資安管理現況,並落實管理階層對資安相關policy的要求,為資訊安全最高負責主管。每年至少召開一次「資安代表會議」,與會者包括相關資訊系統負責人與外部資安顧問,與會人數超過13位,負責審查資訊安全發展計畫、執行成果及宣達相關資訊安全政策與執行要點。
2. 機密資訊保護(Proprietary Information Protection, PIP)委員會
PIP 訓練
PIP 訓練
該年度員工總數
完成訓練比例
2022
2023
2024
759
819
839
100%
100%
100%
PIP 違反狀況
PIP 違反狀況
同仁違反事件數
外包廠商違反事件數
2022
2023
2024
1
1
1
0
0
0
1. 強化資安防禦能力及成熟度評鑑:
2024 年度 Security Scorecard 預期目標為95 分以上,從 2024 年 1 月起,分數維持在98分以上。
Panorays預期目標為90 分以上,從 2024 年 1 月起,分數維持在97分以上。
2022年起,外部弱點掃描頻率從每週一次增加到目前每天一次,一旦發現高風險漏洞都能在第一時間完成修補,執行成效如下圖。
為了進一步強化防駭能力,2022年並雇用國內知名白帽駭客團隊進行紅隊演練模擬攻防,2024年進行滲透測試,除了主動了解駭客思維強化員工防駭意識外,並以此經驗持續改善內網自動化聯防系統。
2. 精進資安管理程序 :
創意電子已於 2021 年度符合資訊安全相關的 ISO 27001 國際標準並取得驗證,透過年度的複審作業不斷地進行持續改善。因應國際標準組織(ISO)已於 2022 年 10 月 25 日正式公布 ISO / IEC 27001:2022 標準,已於 2024 年 10 月通過驗證公司的書審與與實地稽核作業,完成轉版審查暨重新驗證稽核,且沒有不符合項(Nonconformities) 。
3. 風險管理
社交工程
該年度員工總數
完成社交工程比例
2022
2023
2024
759
819
839
100%
100%
100%
4. 教育訓練
資訊技術處每季亦針對全體同仁進行資安宣導教育訓練,其宣導主題依據時下內外部威脅狀況進行規劃,2024年度各季度之主題如下:
2024年度資訊安全教育訓練宣導
季度
主題
內容
第四季度
數位時代如何識別假新聞
第三季度
如何防範深偽AI詐騙影片
第二季度
使用社群網站要注意
第一季度
何謂竊取軟體
持續投入資源於資訊安全相關領域,資源投入事項包含完善治理面及技術面之基礎架構、強化資安防禦設備、情資監控分析、紅隊演練、資安事件應變演練與教育訓練等,全面提升資訊安全能力。
對資訊安全事件的通報與處理,明確訂立資安通報及處理流程,資安事件由資訊單位通報窗口進行收錄並訂定事件等級,如為重大資安事件將通報風險管理小組,資訊單位需於目標處理時間內排除及解決資訊安全事件,並在事件處理完畢後進行根因分析與採取矯正措施,以預防事件重複發生。
2024年度迄今本公司無因重大資通安全事件所遭受之損失。
資通事件
重大資通安全事件
資料外洩件數
員工&客戶個資外洩件數
因資安事件被罰款金額
2022
2023
2024
0
0
0
0
0
0
0
0
0
0
0
0
智慧財產權管理
本公司採取結合營運發展重點目標與保護智慧財產權之策略,針對特定開發之矽智財(SIP))=與先進封裝技術(APT),例如CoWoS、HBM與G-Link,由專利工程師會同相關研發人員檢視研發、設計過程及成果,以評估專利申請之可行性後,針對具有專利布局價值之個案積極進行專利申請,並持續追蹤相關提案進度。本公司針對特定開發之矽智財(SIP)已陸續進行專利布局,該作為除了強化本公司在特定領域之競爭優勢,並同時落實「矽智財(SIP)專案/IC產品專利化」,以達成「專利保護矽智財(SIP)專案/IC產品」之目標。同時,本公司定期的專利技術盤點可作為專利智財與矽智財(SIP)之關聯性管理以及本公司專利智財之價值評估依據。截至2024年12月31日止,本公司自成立以來獲得各國專利數量逾560件。法務主管每年至少一次向董事會報告智慧財產管理計畫執行情形。
另外,本公司自2000年起推動智慧財產權相關管理計畫,主要之執行情形如下:
2000年制定「專利提案申請程序」。2022/8/9 公布修訂第二十二版次。
2003年制定「機密資訊管制程序」。2021/5/26 公布修訂第十版次。
2008年制定「商標申請管理辦法」。2012/5/23 公布修訂第三版次。
2012年制定「機密資訊保護政策」。
2015年啟用專利提案系統。針對專利相關事務之各種期程管控,如提案管理、申請案管理、獎金管理、事務所管理等,有效提高整體之專利相關作業效率。同時從提案到專利申請等專利程序,有效記錄完整之內部技術、專利研發成果。
2016年制定「智慧財產權管理辦法」。
申訴及檢舉辦法
申訴及檢舉辦法
Whistle Blowing Policy
檢舉辦法
為建立誠信經營之企業文化,並依據本公司「誠信經營作業程序暨從業道德規範」第五條第五項及第二十五條之規定,特訂定「創意電子股份有限公司檢舉辦法」,明確建立本公司檢舉管道及調查處理程序,並維護本公司之合法權益。
檢舉人得透過下列管道提供上述之檢舉相關資料:檢舉信箱:ombudsman@guc-asic.com、傳真/電話專線:03-5790696、郵寄地址:新竹市科學園區力行六路10號/創意電子內部稽核收、本公司官網之違反從業道德行為舉報系統,或審計委員會主席信箱(acinfo@guc-asic.com)。本公司員工之檢舉應依照本辦法規定之程序提出。除有特別之情事外,不得擅自將檢舉案件之內容揭露予外部第三人(如新聞媒體、民意代表、關係企業)。
Last updated: Jan. 01, 2022
This Notice is issued by Global Unichip Corporation. (“GUC”, “we”, “us” and “our”).
This Notice applies to websites that are operated or controlled by GUC:
Cookies are simple text files that are stored on your computer or mobile device by a website’s server. Each cookie is unique to your web browser. It will contain some anonymous information such as a unique identifier, website’s domain name, and some digits and numbers.
We may use cookies to:
We do not use the collected information to create visitor profiles.
Our Website uses single-session (temporary) and multi-session (persistent) cookies. Temporary cookies last only as long as your web browser is open, and are used for technical purposes such as enabling better navigation on our Website. Once you close your browser, the cookie disappears. Persistent cookies are stored on your computer for longer periods and are used for purposes including tracking the number of unique visitors to our site and information such as the number of views a page gets, how much time a user spends on a page, and other pertinent web statistics. Cookies, by themselves, will not be used by GUC to disclose your individual identity. This information identifies your browser, but not you, to our servers when you visit the Website. If you want to disable the use of cookies or remove them at any time from your computer, you can disable or delete them using your browser (consult your browser's "Help" menu to learn how to delete cookies). Below you will find a list of the cookies we may use on our Website:
Type of Cookie
Name
Purpose
Duration
Cookies Used on This Website
HTTP
_ga
Registers a unique ID that is used to generate statistical data on how the visitor uses the Website.
2 years
HTTP
_gat
Used by Google Analytics to throttle request rate.
1 day
HTTP
_gid
Registers a unique ID that is used to generate statistical data on how the visitor uses the Website.
1 day
If you want to restrict or block the cookies that are set by our website, you can do so through your browser setting. Alternatively, you can visit https://www.allaboutcookies.org/manage-cookies/, which contains comprehensive information on how to do this on a wide variety of browsers and devices. You will find general information about cookies and details on how to delete cookies from your device.
Last modified: August 8, 2024
We are committed to protecting your privacy. This policy describes the types of
personal information that we may collect from you or that you may provide when you visit the website
https://www.guc-asic.com/en/ (the
"Website") utilize our services, or interact with us through social media websites, and our practices
for collecting, using, maintaining, protecting, and disclosing that information. This policy does not
apply to information collected by a third party.
We provide this policy to explain the type
of information we collect and to inform you of the specific practices and guidelines that protect the
security and confidentiality of your personal data. Please read this policy carefully. If any term in
this policy is unacceptable to you, please do not provide any personal data. This policy may change
from time to time (see Revisions to Our Privacy
Policy).
We collect several types of information from and about individuals, which may include information defined as personal data or personally identifiable information under an applicable law (“personal data”). For example, we may collect information – if you choose to provide it – such as your name, home address, date of birth, ID number, marital status, family information, education, contact information, working experiences, profession, e-mail address, telephone number, country, job function, company/organization name, industry. We may also collect information about your internet connection and the equipment you use to access our Website. We may automatically collect information such as your usage details, IP addresses, and information collected through cookies for limited purposes.
The information we collect about individuals may include:
In addition to the information you give us, we may also collect information about
you from third party service providers, affiliates and/or partners. For example, we may collect
credit or employment information from credit bureaus or any other third parties with your
consent.
As you navigate through and interact with our Website, we may use automatic data
collection technologies to collect certain information about your equipment, browsing actions, and
patterns, including:
The information we collect automatically is statistical data that helps us improve our Website and deliver a better and more personalized service, including by enabling us to:
This Website uses Google Analytics, a web analytics service provided by Google,
Inc. (“Google”). Google Analytics uses cookies, which are text files placed on your computer, to
analyze how users use the Website. The information generated by the cookie about your use of the
Website will be transmitted to and stored by Google on servers in the United States of America
(“USA”).
Google will use this information on behalf of us as the operator of this Website
for the purpose of evaluating your use of the Website, compiling reports on Website activity for us
and providing us other services relating to website activity and internet usage.
The IP
address that your browser conveys within the scope of Google Analytics will not be associated with
any other data held by Google. You may refuse the use of cookies by selecting the appropriate
settings on your browser; however, please note that if you do this you may not be able to use the
full functionality of this Website.
The legal basis for the use of Google Analytics is
your consent provided by accepting the use of cookies and specifically Google Analytics via our
[cookie banner / cookie consent tool] when visiting our Website for the first time. The recipient of
the collected data is Google. Personal data will be transferred to the USA under the EU-US Data
Privacy Framework. You can locate the certificate by visiting https://www.dataprivacyframework.gov/list and searching for Google. The data
sent by us and linked to cookies, user-identifiers (e.g., User-IDs) or advertising-identifiers are
automatically deleted after 14 months. Data whose retention period has been reached is automatically
deleted once a month.
You can withdraw your consent at any time with effect for the
future and opt-out from being tracked by Google Analytics by downloading and installing Google
Analytics Opt-out Browser Add-on for your current web browser: (click here: https://tools.google.com/dlpage/gaoptout?hl=en-GB). To prevent Universal
Analytics from collecting data across different devices, you must opt-out on all systems used. If
you click here, the opt-out cookie will be set.
Our Website uses single-session (temporary) and multi-session (persistent) cookies. Temporary cookies last only as long as your web browser is open and are used for technical purposes such as enabling better navigation on our Website. Once you close your browser, the cookie disappears. Persistent cookies are stored on your computer for longer periods and are used for purposes including tracking the number of unique visitors to our site and information such as the number of views a page gets, how much time a user spends on a page, and other pertinent web statistics. Cookies, by themselves, will not be used by us to disclose your individual identity. This information identifies your browser, but not you, to our servers when you visit the Website. If you want to disable the use of cookies or remove them at any time from your computer, you can disable or delete them using your browser (consult your browser's "Help" menu to learn how to delete cookies).
Below you will find a detailed list of the first-party cookies we may use on our Website:
First-party Cookies
Type of Cookie
Name
Purpose
Duration
Cookies Used on This Website
HTTP
_ga
Registers a unique ID that is used to generate statistical data on how the visitor uses the Website.
2 years
HTTP
_gat
Used by Google Analytics to throttle request rate.
1 day
HTTP
_gid
Registers a unique ID that is used to generate statistical data on how the visitor uses the Website.
1 day
Below please find information about how we process information collected about you (including personal data) as well as the corresponding legal basis. We may process your information where the processing is:
We may disclose aggregated information about our users, and information that does not identify any individual, without restriction. Subject to applicable laws and regulations, we may disclose personal data that we collect or you provide as described in this policy:
The data that we collect from you will be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed by staff operating outside the EEA who work for us or other entities acting as data processors processing data on our behalf. This includes staff engaged in, among other things, the fulfillment of your request or order and the provision of support services. We have implemented international data transfer agreements on the basis of EU Standard Contractual Clauses in order to provide appropriate and suitable safeguards for personal data being transferred to countries outside the EEA where an adequate level of protection is not already guaranteed. A copy can be obtained by contacting us at privacy@guc-asic.com. We will take all steps reasonably necessary to ensure that your data is treated securely and subject to appropriate safeguards in accordance with this policy and applicable legislation.
The length of time we retain personal data depends upon the purposes for which it was collected and how it is used to provide service, comply with applicable laws, and/or establish, exercise, or defend our legal rights. Unless otherwise required by law, we will erase personal data when it is no longer necessary in relation to the purposes for which was collected or otherwise processed; when you withdraw your consent (where lawfulness of processing was based on your consent) and there is no other legal ground for the processing; when you object to the processing and there are no overriding legitimate grounds for the processing; when your personal data has been unlawfully processed; and when it is necessary to comply with legal obligations.
We strive to provide you with choices regarding the personal data you provide to us. We have created mechanisms to provide you with the following control over your information:
You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of this Website may then be inaccessible or not function properly.
If you do not wish to have your contact information used by us to promote our own products or services, you can check certain boxes on the forms we use to collect your data. You can also always exercise your right to ask us not to process your personal data for markzeting purposes by contacting us at privacy@guc-asic.com. If we have sent you a promotional email, you may send us a return email asking to be omitted from future email distributions. Please note that this does not apply to information provided to us as a result of a product purchase, warranty registration, product service experience, or other transactions.
Depending on your interactions with us, we have collected and disclosed the categories described above, which may include sensitive information, to third parties in the preceding 12 months. Third parties include:
We remind you that you, or your authorized agent (upon validation of authorization), may at any time exercise certain rights you may have under applicable laws and regulations, without penalty or disadvantage. Your rights may include:
Any requests related to the above rights may be made by sending an email to privacy@guc-asic.com . We strive to respond to all requests promptly and within any legal deadlines. Once we receive your request, we may verify your identity by requesting additional information sufficient to confirm your identity.
We have implemented measures designed to secure your personal data from accidental
loss and from unauthorized access, use, alteration, and disclosure. Personal data provided to us in
accordance with this policy will be encrypted in transit and at rest.
Unfortunately, the
transmission of information via the internet is not completely secure. Although we will do our best to
protect your personal data, we cannot guarantee the absolute security of the data. Any transmission of
your personal data is at your own risk.
Our Website may contain links or references to other Websites outside of our control. Please be aware that this policy does not apply to these Websites. The Company encourages you to read the privacy statements and terms and conditions of linked or referenced Websites you enter. These third-party Websites may send their own cookies and other tracking devices to you, log your IP address, and otherwise collect data or solicit personal data. WE DO NOT CONTROL AND ARE NOT RESPONSIBLE FOR WHAT THIRD PARTIES DO IN CONNECTION WITH THEIR WEBSITES, OR HOW THEY HANDLE YOUR PERSONAL DATA. PLEASE EXERCISE CAUTION AND CONSULT THE PRIVACY POLICIES POSTED ON EACH THIRD-PARTY WEBSITE FOR FURTHER INFORMATION.
Our Website and Services are not intended for or directed to children under 18 years of age, and we do not knowingly collect or use any personal data from children under the age of 18. No one under the age of 18 may provide any information to or on the Website or to our employees. If we learn we have collected or received personal data from a child under the age of 18, we will delete that information. If you believe we might have any information from or about a child under the age of 18, please contact us at privacy@guc-asic.com
We reserve the right to change this policy at any time. Any changes we make will be posted on this page. If we make material changes to how we treat your personal data, we will notify you through a posting on the Website. The date this policy was last revised is identified at the top of the page. Your continued use of our Website and services after such amendments will be deemed your acknowledgement of these changes to this policy.
The data controller is Global Unichip Corporation, No. 10, Li-Hsin 6th Road, Hsinchu Science Park, Hsinchu City 300096, Taiwan. Should you have any questions or concerns about this policy and our privacy practices, you may contact us at privacy@guc-asic.com
The information and materials included in this website (the "Site") are provided by Global Unichip Corp. ("GUC") as a service to its customers and may be used for informational purposes only. Any promotional efforts by other company without specific written approval by GUC are restricted. Single copies may be downloaded subject to the provisions below. Your access and use of the Site, along with any services or materials contained or referenced herein, is governed by and subject to the following terms as well as all applicable laws. Please review the terms carefully, before using the Site. By accessing, using or downloading any materials from the Site, you agree to be bound by the terms.
Registered Trademark of GUC:
GUC's trademarks may be used publicly with permission only from GUC. Fair use of GUC's trademarks in advertising and promotion of GUC products requires proper acknowledgement. All other trademarks and logos are the property of their respective owners.
The material contained in the Site are protected by worldwide copyright laws and treaty provisions. They may not be copied, reproduced, modified, published, uploaded, posted, transmitted, or distributed in any way, without GUC's prior written permission. Except as expressly provided herein, GUC and its suppliers do not grant any express or implied right to you under any patents, copyrights, trademarks, or trade secret. Other rights may be granted to you by GUC in writing or incorporated elsewhere in the materials. GUC may at any time in its sole discretion and without notice, discontinue, remove and/or discard the Site or any content within the Site for any reason. GUC may terminate your access to the Site for any reason, including if GUC believes in its sole discretion that you have violated or acted inconsistently with the letter or spirit of these Terms.
Except where expressly provided otherwise by GUC, all comments, feedback, information or materials submitted to GUC through or in association with the Site shall be considered non-confidential and the property of GUC. By submitting such comments, feedback, information or materials to GUC, you agree to a free of charge assignment to GUC of all worldwide rights, title and interest in copyrights and other intellectual property rights to the comments, feedback, information or materials. GUC shall be free to use such comments, feedback, information or materials on an unrestricted basis.
Your personal information may be used within GUC or shared with GUC business locations throughout the world. GUC may also track the Internet addresses of our visitors and analyze this data for trends and statistics.
THE INFORMATION PROVIDED ON THE SITE MAY BE OUT OF DATE OR INCLUDE OMISSIONS, INACCURACIES OR OTHER ERRORS. EXCEPT WHERE EXPRESSLY PROVIDED OTHERWISE IN AN AGREEMENT BETWEEN YOU AND GUC, ALL INFORMATION PROVIDED DIRECTLY ON THE SITE OR INDIRECTLY THROUGH THE SITE BY HYPERTEXT LINK OR OTHERWISE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. GUC HEREBY DISCLAIMS ALL WARRANTIES WITH RESPECT TO THIS INFORMATION, WHETHER EXPRESS OR IMPLIED, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, SATISFACTORY QUALITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL GUC BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES, OR DAMAGES FOR LOSS OF PROFITS, REVENUE, DATA OR USE, INCURRED BY YOU OR ANY THIRD PARTY, WHETHER IN CONTRACT, TORT OR OTHERWISE, ARISING FROM YOUR ACCESS TO, USE OF, OR RELIANCE UPON INFORMATION OBTAINED FROM OR THROUGH THE SITE. GUC RESERVES THE RIGHT TO MAKE CHANGES, UPDATES OR CORRECTIONS TO THE INFORMATION ON THE SITE AT ANY TIME WITHOUT NOTICE.