Information Security Basic Policy

The Nikken Group handles important information from clients and other parties involved with the Nikken Group on a daily basis as part of its operations.
In order to prevent infringements from both inside and outside the company regarding such information and information of the Nikken Group, and to deter acts that pose a threat, we have established and will adhere to an information security basic policy based on the Nikken Group philosophy and corporate vision, with the aim of properly acquiring, using, and managing information.

Positioning

This Information Security Policy (hereinafter referred to as the “Policy”) sets forth the fundamental principles of information security regarding all information assets handled by the Nikken Group in the course of its business.
Specific measures are stipulated in the internal regulations of each Nikken Group company, including the “Information Management Regulations,” the “Regulations on the Protection of Specified Private Information,” and the “Private Information Management Regulations” (hereinafter referred to as the “Internal Regulations”).

Scope and duration of application

The basic policy applies to all officers, employees, and other personnel of the Nikken Group who handle information assets, as well as all external contractors (hereinafter referred to as "covered persons"), and will apply not only during their employment but also after their retirement.

Management Responsibility and Structure

Each company within the group designates an information management officer as the highest-ranking officer responsible for information security measures, and specifies a department responsible for managing information security measures according to the regulations, thereby managing all aspects of information security related to each information asset.

Compliance with laws and regulations

Recognizing the importance of information security, we will comply with relevant laws and regulations, basic policies, and internal rules, and strive for the proper acquisition, operation, and management of information assets.

Education

We will regularly conduct information security training for the relevant personnel to ensure strict adherence to basic policies and internal regulations, and to improve their information security literacy.

Inspection and improvement

We regularly review the implementation status of information security measures and identify new threats and risks, and continuously implement revisions and improvements.



April 1, 2016

This site uses cookies. By continuing to use this website, you consent to the use of cookies.Our policy.