本頁內容已使用機器翻譯技術自動翻譯。我們已盡合理努力確保翻譯內容的準確性,但英文版本為正式且具權威性的版本。如有任何差異、歧義或解釋上的不一致,均以英文版本為準。

密碼學政策

ComponentSource Group(以下稱為「ComponentSource」、「we」、「us」、「our」)由眾多個別公司組成,包括:

  • ComponentSource Holding Corporation,Atlanta,USA;
  • ComponentSource, Inc.,Atlanta,USA;
  • ComponentSource Limited,United Kingdom;
  • ComponentSource Software Europe Limited,Republic of Ireland and The Netherlands;
  • ComponentSource KK,Japan。

Purpose

為確保正確且有效地使用密碼學,以保護資訊的機密性、真實性及/或完整性。本政策訂定了在整個加密生命週期中使用與保護加密金鑰及加密方法的要求。

Scope

由 ComponentSource 開發及/或控管、且儲存或傳輸機密資料的所有資訊系統。

General requirements

ComponentSource 將評估資料處理與儲存所固有的風險,並在適當時實施密碼學控制以降低這些風險。凡使用加密之處,將實施並記錄具備相關金鑰管理流程與程序的強密碼學。所有加密將依照業界標準執行,包括 NIST SP 800-57。

客戶或公司機密資料在儲存或透過公用網路傳輸時,必須依照供應商建議與業界最佳實務,使用強式密碼套件與組態,包括 NIST

Key Management

對金鑰與機密的存取將依照 Access Control Policy 進行嚴格管制。下表詳細列出 ComponentSource 核准的加密演算法:

Domain Key Type Algorithm Key Length Max Expiration
Web Certificate RSA or ECC with SHA2+ signature RSA or ECC with SHA2+ signature 2048 bit or greater/ RSA, 256 bit or greater/ ECC Up to 1 year
Web Cipher (TLS) Aysmmetric Encryption Ciphers of B or greater grade on SSL Labs rating Varies N/A
Confidential Data at Rest Symmetric Encryption AES 256 bit Per data retention policy
Passwords One-way Hash Bcrypt, PBKDF2, or scrypt, Argon2 256 bit+10K Stretch. Include unique cryptographic salt+pepper N/A
Endpoint Storage (SSD/HDD) Symmetric Encryption AES 128 or 256 bit N/A

Exceptions

對本政策之例外申請必須提交至 systems@componentsource.com 以供核准。

在於任何媒體或可移除裝置上移動、複製或儲存客戶或公司機密資料之前,必須取得書面例外核准;所有包含敏感資料的可攜式裝置與可移除媒體都必須使用核准的標準與機制進行加密。

Violations & enforcement

任何已知違反本政策的情況都應回報至 group-compliance@componentsource.com。違反本政策可能導致立即撤銷或暫停系統與網路權限,及/或依公司程序採取紀律處分,最高可至終止僱用。

CSCGP 10/2025