Information Security Policy
ISI Group Information Security
1. Declaration
The ISI Group (WEWORLD Co., Ltd., ISI Co., Ltd., ISI Gakuen Educational Institution, Togen Group Co., Ltd., hereinafter referred to as "the Group") considers the proper management of information to be one of the important management issues. We strive to ensure and enhance the confidentiality, integrity, and availability of all information assets, and to respond to the trust of society as a whole, including our customers, we declare the establishment and implementation of the Basic Information Security Policy (hereinafter referred to as "this Policy").
2. Scope of Application and Applicators
This policy applies to all information (including personal information) related to business activities under the management of the ISI Group, and is applicable to all individuals who utilize the group's information assets, including group executives, employees (full-time, contract, temporary, dispatched, part-time, and casual workers), and contractors.
3. Compliance with laws and regulations
Our group complies with various laws and regulations regarding information security, as well as guidelines and other standards established by the government.
4. Establishment of Information Security Regulations
Our group will establish information security regulations that clearly outline the basic requirements necessary to unify the standards for compliance and decision-making when implementing information security measures.
5. Establishment of an Information Security Management System
Our group will establish an information security management system and implement unified information security management as an organization.
6. Response to security incidents and accidents
Our group will respond swiftly in the event of an information security issue and minimize the damage. We will also implement appropriate measures, including those to prevent recurrence.
7. Implementation of Information Security Education and Training
The group will raise awareness of the importance of information security among executives, all employees, and contractors, and will implement education and training to ensure that information assets are used appropriately.
8. Evaluation of the Implementation Status of Information Security Measures and Continuous Improvement
The group will regularly evaluate the implementation status of information security measures to ensure compliance with this policy and information security regulations, and will strive for continuous improvement.
9. Modification and Abolition of Documents
Amendments or abolishments of this policy must be drafted by the Information Security Committee and require approval from both the Group Board of Directors and the Executive Board.
Established: November 26, 2008
Revised: August 1, 2016