Information Security Management

Information Security Framework and Policy

In recent years, hacker activities around the world have become increasingly rampant, and information security threats continue to emerge. These threats may not only cause major financial losses for enterprises but also inflict irreparable damage on reputation.

To respond to information security risks, EGAT has established a complete information security management system. In addition to introducing the ISO 27001 Information Security Management System, the Company conducted renewal review procedures and external audits in 2025. In the same year, it also developed an information asset inventory and risk assessment management system to monitor company endpoint computer usage and block non-compliant software. At the organizational level, EGAT has established the Information Security Management Division, led by a dedicated information security officer responsible for company-wide security governance decisions and for planning and promoting information security management and personal data protection matters. EGAT has also established the Information Security Promotion Committee, convened by the President, to implement information security awareness among all employees through top-down cooperation and allocation of responsibilities. At the policy level, EGAT follows the spirit of ISO 27001 by documenting its information security management system and formulating the Information Security Policy and Information Security Management Manual as references for the Company's information security management. At the management level, EGAT sets information security measurement targets, regularly evaluates information security performance, and continuously improves through internal and external audits, corrective management, and management review meetings to ensure information security management effectiveness.

EGAT ISO/IEC 27001 and CNS 27001 certificates
EGAT ISO/IEC 27001 and CNS 27001 Certificates

Investment in Information Security Management

Item Specific Management Approach
Item Information Security Measurement Specific Management Approach
  • Set measurement indicators for key controls used to reduce risks and regularly record measurement results.
  • Analyze and review measurement results for each indicator to determine whether controls are effective and appropriate.
Item Information Security Incident Management Specific Management Approach
  • Formulate reporting methods for identifying information security events and incidents.
  • Establish response procedures for information security incidents.
Item Business Continuity Management Specific Management Approach
  • Develop business continuity plans for critical operations and procedures for activation and execution.
  • Conduct regular drills to ensure the adequacy of continuity plans and reduce the impact of interruption events.
Item Network Security Specific Management Approach
  • Introduce advanced technologies for computer scanning and system software updates.
  • Strengthen perimeter firewalls and network access controls to detect and block suspicious threat connections.
  • Regularly assess or test network system security and promptly remediate security risks and vulnerabilities in the network operating environment.
  • Deploy web behavior management and filtering equipment to control internet access and prohibit access to harmful or policy-prohibited sites and content.
  • Introduce cybersecurity threat detection management. In addition to providing early warning intelligence, dedicated personnel compile logs from key equipment such as firewalls, intrusion prevention systems (IPS), and AD servers for multidimensional correlation analysis, issue real-time alerts for potential attacks, and provide post-event defense blocking recommendations or emergency response handling.
Item Device Security Specific Management Approach
  • Establish computer device network access mechanisms to prevent unauthorized devices from entering the company network.
  • Deploy endpoint antivirus measures to strengthen malware behavior detection.
  • Introduce managed threat detection and response services to conduct full-time information security risk inventories for computer devices, including user account behavior investigation, program memory forensics, and network activity analysis.
  • Revoke administrator privileges on endpoint devices to prevent improper use of privileged accounts and reduce the risks of malware installation and lateral movement.
  • Establish an endpoint resource management platform to collect hardware and software inventories of endpoint devices and strengthen device compliance management.
Item Application System Security Specific Management Approach
  • Grant system users only the minimum authorized access needed to perform job duties based on business functions under the principle of least privilege, and delete access after transfers or departures.
  • Use digital electronic signatures in processes to ensure the information security of approving personnel.
  • Regularly conduct source code scans to identify web application security weaknesses and vulnerabilities, ensuring security of online system services.
  • Implement system account password changes, access monitoring, and log review operations.
Item Data Protection Security Specific Management Approach
  • Establish handling rules for sensitive data management and storage, and deploy appropriate protections such as outbound email controls, access permissions, and data encryption or masking.
  • Strengthen controls, usage rules, and regular review mechanisms for portable storage media.
  • Before information equipment is scrapped, storage media must be removed and physically destroyed before further processing under relevant procedures to avoid leakage of personal data and business secrets.
Item Emergency Response and Recovery Mechanism Specific Management Approach
  • Regularly review emergency response plans.
  • Conduct regular annual recovery drills for important systems.
  • Establish system backup mechanisms and implement off-site backups.

Information Security Training

In 2025, EGAT conducted the following information security training and provided corresponding courses for different employee groups to strengthen information security awareness.

Training TopicTraining DescriptionResources Invested
Training Topic Information Security Awareness Course Training Description Deepen information security risk awareness among all employees to protect company digital assets and strengthen cybersecurity resilience. Resources Invested 3,494 participants
Training Topic Social Engineering Protection Training Description Strengthen employees' awareness and vigilance against phishing emails. Resources Invested 3,383 participants
Training Topic Social Engineering Protection Training Course Training Description Introduce common social engineering techniques and fraudulent email types to high-risk email user groups to improve employees' information security awareness. Resources Invested 594 hours

Information Security Reporting Channels

For EGAT employees, information security incident reporting methods are announced on the Company's internal portal, with clear reporting guidance to help employees promptly report and handle information security risk events.

Personal Data Protection

To protect customer rights and ensure that the Company's collection, processing, and use of personal data comply with the Personal Data Protection Act and relevant regulations, and to prevent personal data held by the Company from being stolen, altered, damaged, lost, or leaked, EGAT has established the Personal Data File Security Maintenance Plan, which details procedures for personal data protection. In 2025, EGAT had no information security or privacy-related complaints involving data breaches, customer privacy violations, or loss of customer data, and no data leakage occurred.