Mar 18, 2026
Our company has always been committed to protecting the security of information assets belonging to our clients, partners, and all employees. In response to increasingly severe cybersecurity challenges and to continuously optimize the risk management mechanisms of our core business, we completed the revision of the latest version of our Information Security Policy on March 16, 2026.
We fully understand that information security is not only the cornerstone of maintaining business operations but also a solemn commitment to our customers and society. This policy aims to establish a secure and trustworthy information environment to ensure the Confidentiality, Integrity, and Availability (CIA) of all information assets.
The newly revised Information Security Policy of the company is as follows:
1. Purpose
This Information Security Manual is specifically formulated to implement the ISO/IEC 27001:2022 Information Security Management System (ISMS) and to deploy its various security clauses and implementation requirements.
2. Scope
This policy applies to all operational procedures, standards, and documented information established by the company's Plant Management Department in accordance with ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. The term "Business" as mentioned in ISO/IEC 27001:2022 shall be broadly interpreted as those activities central to the purpose of the organization’s existence.
3. Responsibilities and Authorities
- Management Representative: The Plant Director shall appoint an Information Security Management Representative, who is responsible for approving information security policies and objectives, as well as chairing management reviews.
- Information Security Organization: The company has established an Information Security Promotion Team responsible for planning and executing activities related to information security management.
- All Employees: All employees shall comply with relevant information security regulations and report any information security incidents in a timely manner.
4. Definitions
(Omitted)
5. Operational Procedures
- Company Profile: Established in 1951, San Jung Rubber Industry Co., Ltd. was formerly known as Tai Jung Rubber Industry Co., Ltd., initially specializing in the production of high-quality inner and outer tires for bicycles, motorcycles, and hand trucks. In 1972, San Jung Rubber Industry Co., Ltd. was officially incorporated, becoming the largest tire manufacturer in Taiwan at the time. In 1982, San Jung successfully developed and mass-produced various series of eco-friendly rubber flooring products and founded the "SAN JUNG" rubber flooring brand.
- Core Businesses:
- Rubber Building Materials: Manufacturing various types of rubber flooring, flooring accessories, and tile/roll flooring to meet high demands for safety and durability in public spaces and transportation.
- Industrial Rubber Products: Custom design and processing of industrial rubber products.
- Covered Yarn & Textile Applications: Production of rubber-coated N6 tire cord and covered yarn.
6. Information Security Policy
To ensure the confidentiality, integrity, and availability of information assets related to rubber product manufacturing and associated business operations, the company has established an Information Security Management System (ISMS) and commits to the following:
- Establish and maintain an Information Security Management System that complies with ISO/IEC 27001:2022 requirements.
- Comply with applicable laws, regulations, and contractual obligations.
- Establish information security objectives and regularly review their achievement.
- Implement risk management mechanisms to mitigate information security risks.
- Continuously improve the effectiveness of the Information Security Management System.
Plant Director / Chief Information Security Officer: Wen-Lung Hsieh (2026.03.16)
This policy is drafted by the Chief Information Security Officer (Plant Director) and issued by the Information Security Organization. The information security policy shall be communicated and publicized to all stakeholders; the same applies to any major revisions.