Japan EHS Audit Co., Ltd. (hereinafter referred to as "the Company") recognizes that protecting information assets entrusted by customers and our own information assets from all threats is an extremely important management issue in conducting EHS and ESG audit and consulting business. Based on this philosophy, we establish the following basic policy for ensuring information security and declare that our officers and all employees will comply with it.
This policy applies to all information assets (including personal information and confidential information) under our control and to the officers, employees, and partners who handle them.
The Company will build a management system to maintain information security and appoint a responsible person. This clarifies the locus of responsibility for information security and promotes company-wide measures.
The Company complies with laws, regulations, norms related to information security, and security obligations in contracts with customers.
The Company appropriately evaluates the risks of information assets handled and takes appropriate physical, technical, and organizational security measures to prevent unauthorized access, leakage, tampering, loss, destruction, etc.
The Company continuously conducts education and training for officers, employees, and partners to raise awareness of the importance of information security and ensure proper use of information assets.
In the unlikely event of an information security incident, we will verify the cause promptly, take appropriate measures to minimize damage, and strive to prevent recurrence.
The Company will periodically and continuously review and improve this policy, related regulations, and the management system to respond to changes in business content, social environment, and technological trends.