G.U.Group Co., Ltd. (hereinafter referred to as "the Company") is committed to protecting its information assets as well as information assets entrusted by customers from threats such as accidents, disasters, and crimes, in order to meet the trust of customers and society. Based on the following policy, the entire company is committed to information security.
- We shall build information security that fulfills necessary social responsibilities while not obstructing an environment where employees can work freely and openly, in the pursuit of activities that serve the founding purpose of the Group.
- The Company provides infrastructure to financial institutions, and the importance of maintaining trust in that business is critical not only to customers but also to society. The Company's greatest responsibility is to maintain the confidentiality of customer information at a high level and to maintain the information system environment used by customers in an extremely stable manner. All employees must recognize that the Company's consortium-type blockchain operation and management is sustained by meeting the trust of customers and society.
- In order to fulfill the responsibilities imposed on the Company, we shall establish a basic information security policy, and all relevant parties shall act in accordance with the established policy; the policy is set forth below.
- We shall establish an organization in which management participates to promote and improve information security activities. In addition, we shall define the roles and responsibilities for information management and ensure the full operation of the Information Security Management System.
- Employees of the Company shall comply with the information security policy and related laws, regulations, and contractual obligations, and shall act responsibly.
- We shall establish criteria for evaluating risks, identify risks to information assets, and implement risk response plans.
- In order to protect the information entrusted to the Company by customers and to continue business, we shall strictly protect information processing facilities and related equipment from accidents, disasters, and external interference.
- The Information Security Management System shall be continuously reviewed and its effectiveness evaluated, and improvements shall be made as necessary. In addition, continuous internal audits shall be conducted to ensure compliance with established rules.
- We shall establish emergency measures for accidents and disasters that may occur in the services provided by the Company, and shall take measures to continue business without delay.
- In the event of a violation of laws or contracts related to information security or an incident, we shall respond appropriately and strive to prevent recurrence.
- The ISMS Committee shall take the lead in setting and monitoring goals for maintaining and improving information security across all departments, and shall ensure that efforts are put into practice.
- We shall provide education and training on the basic information security policy, related standards, and procedures, as well as education to develop the necessary competencies for all employees involved in information assets within the scope of application.
Established: June 1, 2024
G.U.Group Co., Ltd.
President and Representative Director: Hidekazu Kondo