Item 1B. Unresolved Staff Comments
Item 1B. UNRESOLVED STAFF COMMENTS
The Company has no unresolved comments from the SEC staff relating to the Company’s periodic or current reports filed with the SEC pursuant to the Securities Exchange Act of 1934, as amended.
Item 1C. CYBERSECURITY
Cybersecurity Risk Management and Processes
The Company is actively working towards the integration of a cybersecurity risk management program into its comprehensive risk management framework to protect the confidentiality, integrity, and availability of its critical systems and information.
Our cybersecurity risk management program is being designed based on various cybersecurity frameworks, including National Institute of Standards and Technology and the Center for Internet Security, as well as information security standards issued by the International Organization for Standardization, including ISO 27001 and ISO 27002. The Company uses these frameworks and information security standards as a guide to identify, assess, and management cybersecurity risks relevant to the business.
The Company has implemented or is implementing the following key elements into the cybersecurity risk management program :
Formalization and implementation of robust IT security policies;
Conducting vulnerability assessments;
Revision of user access request documentation to clearly define the roles and permissions assigned to users;
Thorough review of the accuracy and completeness of user listings and access;
Preservation of evidence related to system modifications; and
Continued collaboration with external specialists to aid in the ongoing evaluation of existing policies and procedures.
27
Table of Contents
In addition, the Company has a strategic plan , which encompasses the following key elements:
Establishment of a dedicated cybersecurity governance committee;
Standardization of cybersecurity incident response procedures and formats;
Conducting penetration tests on a quarterly basis;
Enhancement of segregation of duties to mitigate the risk of self-review of transactions within the system;
The Company has not identified any risks from known cybersecurity threats and did not have any cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company.
Cybersecurity Governance
Our Board of Directors actively collaborates with management to supervise cybersecurity risks. In its risk oversight role, our Board of Directors has the responsibility to satisfy itself that the risk management processes designed and implemented by management are appropriate and functioning as designed. In general, we seek to address cybersecurity risks through a cross-functional approach that is focused on preserving the confidentiality, integrity, and availability of the information that we collect and store by identifying, preventing, and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
Management considers cybersecurity risk as part of its risk oversight function and is in the process of establishing a cybersecurity governance committee. Once established, the cybersecurity governance committee will oversee the management’s implementation of the cybersecurity risk management program.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.