INFORMATION SECURITY POLICY
INFORMATION SECURITY POLICY
INFORMATION SECURITY POLICY
SECURITY POLICY
ETHAN Co., Ltd. (hereinafter referred to as the “Company”) recognizes information obtained from customers and business partners through its business activities, as well as all information handled by the Company, as among its most important assets. We also consider the proper maintenance of security for these information assets to be a social responsibility. Based on this principle, we hereby establish the following Information Security Policy and declare that we will implement it and strive for its continuous improvement and enhancement.
1. Definition of Information Security
Information security means ensuring and maintaining the “confidentiality*1,” “integrity*2,” and “availability*3” of information assets.
- Only authorized users can access the information, and the information is not disclosed externally.
- Information and information systems are accurate, and established handling procedures are followed.
- Authorized users can access information and information systems as needed.
2. Purpose
By handling information assets appropriately, we aim to earn the trust of customers, business partners, shareholders, employees, and other stakeholders and fulfill our social responsibility as a company.
3. Scope of Application
- This policy applies to all organizations within the Company.
- This policy applies to all Company personnel, including officers, employees, temporary staff, part-time workers, casual workers, and interns, as well as contractors who are stationed at Company offices to perform their duties.
- This policy applies to all information related to business activities under the Company’s control.
4. Objectives
- Prevent information security incidents and minimize their occurrence.
- If an information security incident occurs, minimize the damage and ensure business continuity.
5. Risk Management Framework
We conduct risk assessments and risk management in accordance with the framework below and establish control objectives and measures.
-
Identification and Classification of Information Assets
Accurately assess the importance of information assets within the Company and classify them accordingly. -
Risk Assessment
Establish criteria for evaluating risks and conduct risk assessments. -
Risk Management
Implement administrative, physical, and technical risk controls.
6. Other Information Security Principles
-
Compliance with Information Security Obligations
Comply with laws and regulations (including, but not limited to, (1) the Unfair Competition Prevention Act, (2) the Act on Prohibition of Unauthorized Computer Access, (3) the Copyright Act, and (4) the Act on the Protection of Personal Information, as specified in the Information Security Management Regulations), internal rules, and contractual information security obligations. -
Education and Awareness Activities
Conduct education and awareness activities related to information security. -
Business Continuity Management
Address interruptions to business activities caused by major information system failures or disasters, protect critical business processes, and ensure the resumption of business activities and critical processes. -
Disciplinary Measures for Violations
Apply disciplinary measures to persons who violate the Information Security Policy. -
Responsibility for Information Security Management
General and specific responsibilities for information security, including responding to information security incidents and making external reports when necessary, rest with the Company's management. -
Information Security Management System Documentation
We create and maintain information security management system documentation to appropriately manage information security and use this documentation to implement this policy.
Established March 15, 2015