Accrete Inc. (hereinafter referred to as the "Company"), as a provider of internet solutions through cloud services, recognizes that protecting the information assets entrusted to us by our customers and our own information assets is a crucial management challenge. To implement information security measures, we have established an "Information Security Basic Policy." All employees comply with this policy, strive for the proper handling and management of information assets, and are committed to continuous improvement.
Information Security Objectives
We set information security objectives and formulate action plans, build internal structures, and establish and operate an Information Security Management System (hereinafter referred to as "ISMS") to achieve these objectives.
Scope of the Information Security Policy
Information assets subject to this policy include all information assets held by the Company in the course of business (hereinafter referred to as "ISMS Assets"), including information assets acquired or learned through our business activities, as well as information assets entrusted to us by customers for business processing. All personnel involved in the handling and management of ISMS Assets (executives, regular employees, part-time workers, external contractors, etc.) are required to understand and comply with this policy. When providing cloud services, prior agreement is reached with customers regarding the handling of cloud service customer data. Furthermore, when utilizing cloud services, they are used after thoroughly understanding the environment in which they are provided and identifying vulnerabilities and threats.
Compliance with Laws and Regulations
By operating the ISMS constructed based on this policy, we ensure compliance with various laws, contractual requirements, and internal regulations, and implement measures conforming to the information security standards for which we seek certification.
Establishment of Internal Regulations Regarding Information Security
We establish regulations based on our information security policy to provide clear guidelines not only for personal information but also for the handling of all ISMS assets.
Establishment and Enhancement of Audit Systems
We maintain a system capable of conducting internal audits to ensure compliance with our information security policy and various regulations. By planning audits and implementing improvement activities based on their results, we continuously strengthen our security.
Realizing a System with Thorough Information Security Measures
We implement a management system incorporating rigorous measures to prevent intrusion, leakage, tampering, loss, destruction, and disruption of ISMS assets.
Thorough Information Security Education
We provide necessary security education to all employees, ensuring that everyone involved with our ISMS assets can perform their duties with an understanding of and interest in information security. Furthermore, we continuously conduct education and training to adapt to changing circumstances.