Acrit Co., Ltd. (hereinafter referred to as "the Company") recognizes the protection of information assets entrusted to us by our customers and information assets owned by the Company as a critical management issue, as a provider of internet solutions through cloud services. In order to implement measures to protect information assets, we have established an "Information Security Basic Policy," and all employees will adhere to this policy and strive to appropriately handle and manage information assets, and will continue to improve our practices
Information security goals
Our company sets information security objectives, develops plans to achieve them, establishes internal systems, and builds and operates an information security management system (hereinafter referred to as "ISMS")
Scope of Information Security Policy
This policy covers all information assets held by our company in the course of its business operations (hereinafter referred to as "ISMS assets"), including information assets obtained and acquired in the course of our business activities, as well as information assets entrusted to us by our customers for business processing. All of our employees (officers, employees, part-time workers, external contractors, etc.) involved in the handling and management of ISMS assets will understand and comply with this policy. When providing cloud services, we will obtain prior agreement with customers regarding the handling of cloud service customer data, etc. Furthermore, when using cloud services, we will ensure that we correctly understand the environment in which the cloud services are provided and that we are aware of vulnerabilities and threats before using them
Compliance with laws and regulations
By operating the ISMS established in accordance with this policy, our company will comply with various laws and regulations, contractual requirements, and internal regulations, as well as with information security-related standards for which we have obtained certification
Development of internal regulations regarding information security
We will establish regulations based on our information security policy to clearly define our course of action regarding the handling of not only personal information but also all ISMS assets
Improvement and enhancement of the audit system
We will establish a system to conduct internal audits to ensure compliance with our information security policy and various regulations. By systematically conducting audits and implementing improvement activities based on the results, we will continuously strengthen our security
Realizing a system with thorough information security measures
We will implement a management system that takes thorough measures to prevent intrusion, leakage, alteration, loss, destruction, or interference with ISMS assets
Thorough information security education
We will provide all employees with the necessary security training to ensure that everyone involved with our ISMS assets understands and is concerned with information security in their work. Furthermore, we will continuously provide education and training to adapt to changing circumstances