Miroku Corporation

INFORMATION SECURITY POLICY

基本方針など

基本方針など

May 1st, 2025
MIROKU CORPORATION
Yoshihiko Miroku, President
We are committed to information security based on the following policies in order to protect our client’s information and other information assets held by the Group from threats such as accidents, disasters, and crimes, and to live up to the trust of our customers and society.
  1. Management responsibility

    We recognize information security, including cybersecurity, as one of our most important management issues. We are committed to establishing an information security management system that encompasses the entire group and to fostering an organizational culture through leadership.
  2. Employee Initiatives

    We are committed to developing the knowledge and skills necessary for robust information security.
  3. Establishment of a management system

    To properly manage and protect information assets, we will establish an operational management system that enables the implementation of necessary security measures based on security risk analysis.
  4. Protection of Information Assets

    We will take appropriate organizational and technical measures to protect the confidentiality, integrity and availability of information assets.
  5. Continuous improvement activities

    To respond to changes in legal and regulatory requirements and new information security risks, such as cyber-attacks, we will implement continuous improvement activities by regularly evaluating and reviewing our security measures.
  6. Response to Incidents

    1. In the event of a breach of laws, regulations or contracts relating to information security, or in the event of an accident, we will endeavor to minimize the impact and prevent recurrence by taking immediate action to prevent the spread of damage.
    2. We will develop an emergency response system in the event of an incident, as well as a business continuity and recovery system to prepare for the damage caused by an incident.
    3. Information about incidents will be shared with relevant parties as appropriate to the situation.
  7. Implementation of security training

    Regular information security education and training is provided to directors and all employees to continually improve their security awareness.