Information Security Policy Declaration
Information Security Declaration
Company Overview
Founded in 2016 and headquartered in Hsinchu, Taiwan, the company focuses on medical-grade physiological sensing, remote healthcare, and cloud platform integration. We provide ECG and vital-sign monitoring devices together with remote monitoring solutions, helping healthcare organisations build stable, secure telehealth data systems.
Our core technologies span biosensing integration, secure wireless transmission across multiple protocols, cloud data platforms, centralised management of continuous physiological data, and multi-patient monitoring systems. They are applied in chronic disease management, remote patient monitoring, and post-discharge follow-up care.
VitalSigns is guided by a commitment to innovation, product quality, and disciplined information security management. We deliver medical technology solutions that are secure, reliable, and aligned with international regulatory requirements, and we protect the confidentiality, integrity, and availability of the medical data entrusted to us — in support of higher-quality, more efficient healthcare worldwide.
Information Security Governance
VitalSigns maintains an IT Security Committee and has appointed the Chief Technology Officer of the Technology R&D Division as the Company’s Chief Information Security Officer (CISO). The CISO is responsible for planning, monitoring, and administering our information security policies and control framework, and works with the IT function and other business units to strengthen the Company’s cybersecurity defenses and management practices.
VitalSigns Information Security Organization
Information Security Committee (CISO)
Executive Secretary
Information Security Task Force
Emergency Response Team
Information Security Audit TeamIndependent audit function, linked to the Executive Secretary by a dashed line.
IT Security Committee
The Company’s IT Security Committee is led by the Chief Information Security Officer — the Chief Technology Officer of the Technology R&D Division — and its members are the heads of the relevant departments. The Committee meets on a regular schedule to review the Company’s principal information security policies, security risk assessments and improvement plans, security performance indicators, and the global security landscape and emerging threats, so that our information security policy and management objectives are met.
Information Security Task Force
The Company has established an Information Security Task Force with members drawn from the Technology R&D, Operations Management, Marketing and Sales, Manufacturing, and Quality Management departments. The task force meets regularly to review information security and data protection policies and to decide how the resulting programs are carried out, so that the Company’s information security objectives are achieved in practice.
Security Management & Execution Priorities
To prevent and reduce security risks originating outside the Company, VitalSigns implements and continually updates a rigorous set of security measures. These include advanced virus scanning tools that keep the information systems we use free of infection; strengthened network firewalls and network controls that prevent malware from spreading between sites; anti-virus protection and advanced malware-detection solutions on company computers; and shorter security deployment times that harden our data centers. We also establish and regularly review security performance indicators; adopt new technologies to strengthen data protection; improve phishing detection and run periodic employee awareness testing; operate an integrated security monitoring and operations platform to improve incident detection; rehearse our procedures for responding to security attacks on an ongoing basis; and engage outside experts to carry out independent security assessments. Our standing annual execution priorities are as follows:
- 1Information Security Governance and Policy
- 2Human Resources Security
- 3Asset and Data Security
- 4Access Control and Identity Authentication
- 5Physical and Environmental Security
- 6Operations and Communications Security
- 7Supplier and Third-Party Relationship Security
- 8Information System Acquisition, Development, and Maintenance Security
- 9Security Incident Response and Business Continuity
- 10Regulatory Compliance and Audit
Incident Handling & Reporting
VitalSigns has established an emergency response team for information security incidents together with a documented incident management procedure that defines the required process and controls. These cover the reporting and escalation path for security incidents; the assignment of accountable personnel to handle major cybersecurity incidents; assessment of losses incurred and of any further action required; and evaluation of the potential financial and operational impact of security risks, along with the measures taken in response.
Start
Incident sources
- DecisionDoes IT staff classify this as a security incident?
No
Handle directly
Record the handling process
End
Note: cases with no information-security implication.
Yes
Dedicated security personnel engage
- DecisionClassify incident severity
Major incident (level 3-4)
Notify stakeholders and the CISO
Security incident report
Corrective and preventive action
Report the outcome to stakeholders and the CISO
End
Note: Taiwan-listed companies must file a material-information disclosure within 48 hours.
Minor incident (level 1-2)
Security incident report
End