Information Security Principles and Policies
Introduction
Multibook Limited (hereinafter referred to as “the Company”) operates under the philosophy: “Making the challenge of overseas business management more accessible and easier.”
The information assets handled in the course of our business operations—including customer information and other related data—are of critical importance to our corporate foundation.
All persons who handle information assets, including officers and employees, shall recognize the importance of protecting such assets from risks such as leakage, damage, and loss. They shall comply with this policy and take appropriate actions to maintain the confidentiality, integrity, and availability of those assets, thereby ensuring information security.
Our Commitments
-
Compliance with Laws and Regulations
To protect information assets, we have established this Information Security Policy along with related internal rules. We conduct our business in accordance with these policies and comply with applicable laws, regulations, relevant standards, and contractual obligations concerning information security.
-
Information Security Risk Management
We clarify the standards for analyzing and evaluating risks—such as leakage, damage, and loss—associated with information assets. We establish a systematic risk assessment methodology and conduct assessments periodically. Based on the results, we implement necessary and appropriate security measures.
-
Enhancement of Information Security Awareness
We establish an information security framework led by the designated executive officer and clearly define the authority and responsibilities related to information security. In addition, we provide regular training, education, and awareness programs to ensure that all persons recognize the importance of information security and handle information assets appropriately.
-
Information Security Audits
We regularly inspect and audit compliance with this Information Security Policy and the handling of information assets. When deficiencies or areas for improvement are identified, we take prompt and appropriate corrective actions.
-
Response to Information Security Events and Incidents
We take appropriate measures in response to information security events and incidents. In the event of such occurrences, we follow predefined procedures to minimize damage and respond swiftly, and, where necessary, implement corrective actions. For incidents that may disrupt business operations, we establish a management framework and review it regularly to ensure business continuity.
-
Continuous Improvement
We establish an Information Security Management System (ISMS) with clearly defined objectives to realize our basic philosophy. This system is implemented, reviewed regularly, and continuously improved to maintain its effectiveness.
Established: December 20, 2021
Multibook Limited
Manabu Watabe, President & COO