风险管理
Risk oversight is embedded in board responsibilities and audit processes, ensuring operational resilience and long-term sustainability.
Risk Management Policy and Procedures
To promote the Company’s sustainable development, strengthen corporate governance, and establish a sound risk management system, the Board of Directors approved the adoption of the “Risk Management Policy and Procedures” on November 6, 2024. The Company’s risk management procedures primarily include risk identification and analysis, risk assessment, risk response, and monitoring and review mechanisms. Each department identifies risk items related to its operations, conducts risk assessment and analysis based on the principle of materiality and stakeholder concerns, evaluates the potential impact of each risk on the Company, and formulates corresponding risk management measures and countermeasures.
The Company’s risk management framework covers operational risks related to environmental (climate change, biodiversity, occupational safety and health, energy, etc.), social and human rights, governance (regulatory compliance, anti-corruption and fraud prevention, information security), financial, and other relevant risk factors. The Audit Committee is responsible for supervision, while the Sustainability Development Office reports at least once a year to both the Audit Committee and the Board of Directors on the implementation status.
For details, please refer to our company's Policies and Procedures for Risk Management.
Organizational Structure and Responsibilities of Risk Management
Risk Management Levels and Responsibilities:
- Level 1: Responsible units for respective risks manage risks in accordance with risk management procedures as part of their daily operations.
- Level 2: The Audit Unit conducts regular audits and reviews the implementation status of risk management.
- Level 3: The Sustainability Development Office, established under the Chairman, coordinates overall risk management and reports the execution status to the Board of Directors.
Risk Management Implementation
Catcher actively implements risk management, with the Sustainability Development Office reporting at least once a year to the Audit Committee and the Board of Directors on the annual implementation status. The most recent report was presented on November 6, 2024, with the key contents summarized as follows:
1. Identification, Analysis, and Assessment of Risks Related to Material Issues

▼ Identification Results of Material Risk Issues

2. Risk Management Implementation

Information Security Risk Management Framework
The Company has established an Information Security Promotion Task Force, consisting of a Convener, Management Representative, Executive Secretary, Information Security Management Team, Data Protection Team, Emergency Response Team (task-oriented), and Audit Team. The task force formulates the Company’s information security development directions and strategies and promotes as well as implements various information security management initiatives to ensure the continuous and stable operation of the information security management system.
- Information Security Promotion Task Force: The Company’s decision-making and management body for information security, responsible for overall promotion of information security initiatives.
- Management Representative: Coordinates system planning, resource allocation, and project implementation related to information security.
- Executive Secretary: Assists the Management Representative and Convener in carrying out information security management tasks.
- Information Security Management Team: Responsible for planning, establishing, implementing, maintaining, reviewing, and continuously improving the Company’s information security management system for IT systems; reports information security issues to the Task Force, coordinates audit schedules, supervises audit execution, and oversees preventive and corrective measures.
- Data Protection Team: Promotes and manages the Company’s data and personal data protection systems.
- Emergency Response Team: A task-based unit responsible for monitoring and tracking major information security incidents, as well as maintaining, updating, and executing disaster recovery procedures.
- Audit Team: Formulates information security audit plans, conducts relevant audits, and follows up on preventive and corrective actions for items that do not meet audit standards.
Information Security Policy
Catcher is committed to information security management to safeguard the Company’s products and services from unauthorized access, alteration, use, and disclosure, as well as losses arising from natural disasters. The Company ensures the timely provision of complete and available information to protect the confidentiality, integrity, and availability of critical information assets. At the same time, Catcher complies with applicable laws and regulations, earns customer trust, fulfills commitments to shareholders, and guarantees the continuity of key business operations.
Full Participation, Enhanced Security Awareness:
Foster company-wide awareness to build a shared consensus that information security is everyone’s responsibility.
Proactive Prevention, Effective Security Management:
Establish information security technologies and implement an information security management system, continuously improving under the Plan-Do-Check-Act (PDCA) cycle.
Customer Trust, Sustainable Operations:
Provide a secure and trustworthy production environment to ensure business continuity and long-term sustainability.
Information Security Management Program
To demonstrate the Company’s commitment to information security management and to ensure that all information and information systems are appropriately protected, the Company has established, documented, implemented, and maintained an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001:2022 standard, and continuously improves its effectiveness.
Objectives:
Implement appropriate protection and preventive measures for information stored or transmitted by the Company.
Reduce the impact of information security incidents such as damage, theft, leakage, alteration, misuse, or infringement.
Continuously enhance the confidentiality, integrity, and availability of all operations across the Company’s information service systems.
Information Security Management Measures
In accordance with the ISO/IEC 27001:2022 standard, the Company adopts the Plan-Do-Check-Act (PDCA) cycle to establish and implement an Information Security Management System (ISMS), ensuring its effective operation and continuous improvement.
- Establish an information security management organization responsible for promoting, coordinating, and supervising information security management matters.
- Conduct a management review at least once a year to ensure the adequacy, sufficiency, and effectiveness of the ISMS. The review scope includes improvement plans and assessments of required changes to the system.
- Establish information security indicators to evaluate performance and the effectiveness of the ISMS.
- Perform regular or ad hoc security assessments or audits to review whether control objectives, measures, and procedures comply with laws, regulations, and relevant security requirements. Execute and maintain them effectively as planned to continuously enhance the effectiveness of the ISMS.
Information Security Management Achievements

站内搜寻
Start typing keywords to discover the service, support, or details you’re looking for.
隐私权政策
欢迎来到「可成网站」(以下称「本网站」)。为了让您安心使用本网站的各项服务与资讯,特此向您说明本网站的隐私权政策,以保障您的权益,请详阅下列内容:
01. 隐私权政策适用范围
本政策适用于您使用本网站服务时所涉及的个人资料搜集、处理与利用方式。但不适用于本网站所连结之其他网站,也不适用于非本网站所委托或管理之人员。
02. 个人资料的搜集、处理与利用方式
当您造访或使用本网站服务时,可能依服务性质请您提供必要的个人资料,且仅于特定目的范围内处理与利用,未经您的书面同意,不会另作他用。 使用如联络表单、留言或问卷等互动功能时,本网站可能会保留您的姓名、电子邮件、联络方式及使用时间。一般浏览时,伺服器会自动记录您的 IP 位址、使用时间、浏览器类型、浏览纪录等资讯,作为改善网站服务之用,不对外揭露。 为提供更精准的服务,本网站可能对问卷内容进行统计分析,统计结果可能以数据或文字呈现供内部研究或对外公开,但不包含个人身分资讯。
03. 资料保护
本网站的伺服器均设有防火墙、防毒系统及其他相关资安设备,以确保您的个人资料受到妥善保护。仅限经授权人员得以接触资料,所有相关人员皆已签署保密协议,违者将依法处理。 如因业务需要委外处理个人资料,本网站将充分监督并要求其确实遵守保密义务。
04. 外部连结
本网站可能提供外部网站连结,但本网站的隐私权政策并不适用于该等网站。请您自行参阅各该网站的隐私权政策。
05. 个人资料之第三方共享
本网站绝不会出售、交换、出租或提供您的个人资料予任何个人、公司或机关,但符合法律或契约义务之情形除外。
例外情形包括但不限于:
01. 经您书面同意
02. 法律明文规定
03. 为防止危及您的生命、身体、自由、财产之危险
04. 为公共利益,与政府或学术机构合作进行统计或学术研究(资料经处理后无法识别个人)
05. 您在本网站之行为违反服务条款,或造成其他使用者或第三人损害
06. 为维护您的权益
07. 委外机构协助搜集、处理或利用个人资料,且本网站依法监督其行为
06. Cookie 之使用
为提供更佳服务,本网站将于您的装置上写入并读取 Cookie。若您不愿接受,可透过浏览器设定提高隐私权等级,但可能导致部分功能无法正常运作。
07. 隐私权政策修订
本政策将因应需求随时修订,修改后的条款将公布于本网站。