Security policy

1.Security Policy

Alongside the stable execution of the business operations of ATEC Co., Ltd., the protection of its information assets from all threats is necessary in order to ensure the safety, security, and trust of all users involved with the Company’s information systems. To that end, the Company has established an Information Security Policy covering the following matters to serve as a comprehensive set of rules for information security measures, and will accordingly work to ensure security.
All employees and workers engaged in the business of ATEC Co., Ltd. assume responsibility for implementing this Security Policy in order to fulfill this purpose, and must uphold and comply with it.

2.Information Security Organization

With respect to information handled in information systems, we will strive to maintain and improve information security by implementing appropriate security measures commensurate with the importance of such information and by establishing an Information Security Management System (ISMS) centered on management.

3.Information Asset Classification and Management

With respect to information handled in information systems, we will stipulate the classification definitions commensurate with information importance, responsibilities for information management, and management methods, based on the principle that important information shall receive prioritized management.

4.Personnel and User Security

We will stipulate authority and responsibilities regarding information security. However, users are not always receptive to information security improvements given that such improvements do not necessarily coincide with improvements in convenience. Therefore, we will accordingly stipulate measures necessary for ensuring implementation of adequate information security education and awareness initiatives.

5.Physical and Environmental Security

With respect to the locations where information systems have been installed, we will establish controlled areas in order to protect information assets from unauthorized physical access, damage, and disruption.

6.Communications and Operations Management

We will stipulate necessary measures with respect to operational matters such as confirming the status of compliance with this Policy and monitoring networks, in order to ensure the effectiveness of this Policy and to prevent unauthorized access as well as situations where unauthorized access is exploited to launch attacks on other information systems. In addition, we will stipulate emergency response plans for enabling a rapid response in the event of an emergency.

7.Legal Compliance

We will stipulate that users of our information systems must comply with this Policy and all applicable laws and regulations. In addition, we will stipulate that users shall not infringe upon the rights of others (including corporations) or breach their contractual obligations.

8.Evaluation and Review

We will stipulate that periodic evaluation and review of regulations and related documents will be implemented, and that continuous improvement will be pursued, taking into account factors such as the evaluation of this Policy and information security measures, changes to information systems, and new threats.