Overview
1. Policy Objective
Evergreen Logistics Corp. (hereinafter referred to as “the Company”) has established an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001 international standard to ensure business continuity and safeguard information assets. This system serves as the highest guiding principle for information security management and aims to effectively reduce operational and information security risks.
2. Information Security Objectives
Based on the Information Security Policy, the Company has defined the following core objectives:
- Ensure System Stability
Maintain continuous availability of information systems and services to support global operations
- Protect Information Confidentiality
Prevent unauthorized access and disclosure to ensure the security of customer and company data
- Enhance Security Awareness
Improve employees’ awareness and capabilities in information security to mitigate human-related risks
- Strengthen Environmental Protection
Enhance physical and infrastructure security to reduce environmental impacts on information systems
These objectives will be continuously monitored and evaluated using measurable indicators to ensure expected outcomes are achieved.
3. Information Security Commitment
The Company’s management commits to:
- Establishing, implementing, maintaining, and continually improving the ISMS
- Ensuring alignment between the information security policy and overall business strategy
- Providing sufficient resources and personnel support for information security initiatives
- Establishing an Information Security Committee and conducting regular management reviews
- Communicating information security policies and requirements to internal and external stakeholders
- Complying with applicable laws, regulations, and contractual obligations
4. Information Security Principles
The Company is committed to the three core principles of information security:
- Confidentiality: Prevent unauthorized access and information leakage
- Integrity: Ensure accuracy and completeness of information
- Availability: Maintain stable operation of systems and information services
Through risk assessment and control measures, the Company aims to effectively reduce the impact of security incidents on business operations.
5. Information Security Practices
The Company continuously implements the following management measures:
| Management Area |
Description |
| Risk Management |
Conduct regular inventory and risk assessments of information assets, and apply appropriate controls |
| Governance Implementation |
Establish comprehensive documented systems (policies, procedures, workflows, and records) |
| Security Training |
Provide regular information security training to enhance employee awareness |
| Audit & Review |
Perform internal audits and management reviews at least annually |
| Continuous Improvement |
Optimize the management system through performance monitoring, incident analysis, and corrective actions |
6. Continuous Policy Improvement
The Company will regularly review the appropriateness of information security policies and objectives through internal audits, management reviews, and risk management mechanisms. It will also continuously improve the ISMS to enhance overall security protection capabilities and ensure sustainable business operations.