Information Security Policy (ISO/IEC 27001:2022)
Information Security Policy | ISO/IEC 27001:2022 Clause 5.2
1. Basic Stance on Information Security
The information assets held and managed by our organization (customer information, personal information, business information, system information, etc.) are important management resources that support business continuity and the trust of stakeholders. Under the leadership of our CEO, our organization will promote the appropriate protection of the confidentiality, integrity, and availability of these information assets. This policy is appropriate for the objectives of our organization.
2. Framework for Information Security Objectives
This policy provides a framework for setting information security objectives based on the results of a risk assessment. These information security objectives should be aligned with this policy and reviewed regularly.
3. Satisfaction of applicable requirements
Our organization is committed to meeting applicable laws and regulations related to information security (including the Personal Information Protection Act, the Unauthorized Access Prohibition Act, and other relevant laws, regulations, and guidelines), as well as contractual information security requirements with stakeholders.
4. Continuous improvement of the information security management system
Our organization is committed to continuously improving the effectiveness of our Information Security Management System (ISMS). We will continuously strengthen our information security measures through risk assessment, internal audits, incident management, management reviews, and other means.
5. Awareness/Availability
This policy will be maintained as documented information, communicated within the organization to ensure understanding and application, and made available in an appropriate format to stakeholders upon request.
6. Review
This policy will be reviewed at least once a year, or whenever there are significant changes in the business environment, threats, laws, or risks, to ensure that it remains appropriate and effective.
Enacted: March 1, 2026
Unovia Co., Ltd.
Representative Director: Masahiro Tamura
Related documents: Information Security Objectives (ISP-002) / Statement of Applicability (SOA) / Risk Assessment Procedure (ISP-003) / Incident Management Procedure (ISP-004)