Information Security
情報セキュリティ基本方針

Information Security Initiatives

Our Commitment to Comprehensive Information Security

N&I Systems Co., Ltd. (hereinafter referred to as the Company) is universally dedicated to delivering services that our clients can rely upon with absolute confidence, an objective that our entire workforce strives daily to achieve.

Uncompromising quality is the foundational cornerstone of the services we provide. We firmly believe that the meticulous preservation, maintenance, and strategic governance of information assets are vital to guaranteeing this standard of quality. This core conviction represents the exact driving force behind our early adoption and successful acquisition of BS 7799 and Information Security Management System (ISMS) certifications.

Moving forward, we remain steadfast in our pursuit of operational excellence. Beyond guaranteeing strict regulatory compliance, we will continuously optimize our internal infrastructure to thoroughly safeguard our information assets, ensuring we consistently deliver services that provide our clients with total peace of mind and satisfaction.

Information Security Basic Policy

Robust information-security management represents a fundamental pillar of our corporate governance, serving as a critical driver that sustains the Company's healthy management and long-term commercial growth.

All officers and employees bear direct accountability for the information-security management of both client data and internal corporate intelligence. To execute this responsibility at the highest possible tier, it is imperative that every member of our organization maintains an acute awareness of information security and actively contributes to its continuous enhancement.

Accordingly, all officers and employees must correctly recognize the critical importance of secure data governance and maintain absolute compliance with the complete suite of regulations derived from this Information Security Basic Policy.

1. Purpose

  1. Information is a vital asset to the Company. Ensuring the flawless management and protection of all data assets is both a premier management priority and a profound social responsibility. This policy formally defines the baseline principles governing the security, orchestration, and defense of all information held by the Company.
  2. The Information Security Basic Policy establishes the strategic framework required to proactively prevent the loss, leakage, alteration, or unauthorized utilization of data. It executes information management with the explicit objective of enforcing confidentiality and integrity while continuously improving system availability.

    - Confidentiality: Access to and utilization of both Company and client information assets must be rigorously and appropriately regulated.
    - Integrity: Stored information must be robustly shielded from unauthorized modification or illicit tampering throughout its lifecycle to guarantee absolute accuracy, data consistency, and reliability.
    - Availability: Information assets must remain seamlessly and securely accessible to authorized users in a timely manner whenever required by the business.

2. Scope of Application

  1. This Information Security Basic Policy applies universally to all informational and technological assets owned or managed by the Company. It is strictly binding for all corporate officers and employees alike.
    Furthermore, all external parties entrusted with handling Company information, including third-party contractors, suppliers, and partner enterprises, must formally pledge and guarantee absolute adherence to this policy.
  2. The Basic Information Security Policy applies to all officers and employees of the Company.
  3. All parties handling our information—including external contractors and partner companies—must commit to complying with our Basic Information Security Policy.

3. The Information Security Manual

The concrete provisions required to operationalize this basic policy within daily commercial workflows are explicitly codified in our Information Security Manual. This manual serves as our official internal regulatory rulebook, meticulously engineered in strict compliance with the international implementation requirements of ISO-standardized ISMS frameworks.

4. Information Security Governance Structure

  1. The President serves as the chief executive officer bearing ultimate accountability for the Company's global information-security management. The President establishes the overarching security infrastructure, ensures all personnel are profoundly informed of this policy, and mandates targeted initiatives to elevate internal security literacy.
  2. The President establishes the Information Security Steering Committee to deliberate on emerging security benchmarks, evaluate technical requirements, and oversee the execution of strategic countermeasures.
  3. Guided by the decisions of the Steering Committee, the President appoints a dedicated Chief Information Security Manager to orchestrate the smooth, continuous execution of the corporate ISMS.
  4. The Chief Information Security Manager implements advanced, proactive technical controls to ensure the Company maintains an elite standard of data protection at all times.
  5. Departmental managers, executing the directives of the Steering Committee, are responsible for conducting continuous risk assessments of their respective information assets, formulating robust security controls, monitoring risk factors, and driving the ongoing optimization of the ISMS.
  6. Every officer and employee must maintain a profound comprehension of information governance, taking proactive, autonomous steps to uphold and elevate our enterprise security standards.

5. Information Governance and Compliance Enforcements

  1. The Company executes all data-protection workflows in strict accordance with the Information Security Manual.
  2. Any individual conduct or operational deviation that violates the provisions of the manual shall be subject to strict disciplinary actions in direct accordance with the corporate Employment Regulations.
Initial Enactment Date: October 28, 2004
Last Amended: April 1, 2018

N&I Systems Co., Ltd. > Tsutomu Kawase, President and CEO