Information Security Policy
This is a reference translation. The Japanese version is the authoritative text. View the Japanese original.
HARO Inc. (hereinafter "the Company") believes that earning the trust of our customers comes first in realising our corporate philosophy. We therefore establish this "Information Security Policy", keep the matters set out below constantly in mind, make them fully known to all employees including management, and strive to protect information assets appropriately in accordance with this policy.
1. Matters to be implemented
- We will strengthen the relationship of trust with our customers through the protection of customer information.
- We will fulfil our social responsibility as a company through our management philosophy and compliance with laws and regulations.
- We will take every possible security measure for the information assets entrusted to us by customers and handled in the course of our business, and will continually work to prevent risks such as loss, destruction, falsification and leakage before they occur.
- By providing education and training on information security to employees on a regular basis, we will acquire the necessary skills and make our efforts on information security dependable.
- In the event of an information security incident or violation, we will respond appropriately and promptly and strive to prevent recurrence.
- We will set, implement and maintain objectives relating to information security.
- We will satisfy the applicable requirements relating to information security.
- We will continually gather the latest threat information and technical information relating to information security, and strive to improve our security measures while responding to new risks in a timely manner.
2. Responsibilities, obligations and penalties
In accordance with the procedures established to maintain this basic policy, all persons have a responsibility to report information security incidents and weaknesses. Any person who commits an act that endangers the protection of the information assets handled by the Company will be subject to disciplinary action in accordance with the work rules and applicable laws and regulations.
3. Regular review
We will regularly inspect and review compliance with the information security management system, and strive for continual improvement in response to changes in the social and internal environment.