FY2025: Conformity Confirmed in Our Information Security Management System (ISMS) Surveillance Audit, Certification Continued

In the 2025 surveillance audit of the Information Security Management System (ISMS) certification we obtained in 2022, our conformity was confirmed and the continuation of our certification registration was approved.

ISMS certification has a set period of validity. To maintain it, a company must undergo regular surveillance audits and have it confirmed that its information security management system is being properly operated and that its continual improvement activities meet the standard. In this surveillance audit, our information security management system was confirmed to conform to the requirements, and the continuation of our certification registration was approved.

ISMS is a management system for protecting the confidentiality, integrity, and availability of information, and an important framework for safeguarding a company's information assets. We have put in place a system that keeps our clients' valuable information safe and continually reduces security risks.

Focus for FY2025: Secure Use of AI

As AI technologies, led by generative AI, spread rapidly, the potential for greater operational efficiency is growing, but so are problems arising from the risk of information leaks and inappropriate use. As a priority for FY2025, we are driving a comprehensive set of initiatives to use AI safely and effectively.

Establishing AI Security Governance

To minimize the information security risks of using AI services in our work, we have put the following measures in place.

Developing AI usage guidelines and security policies We have clarified standards for handling information when using generative AI services and set out concrete rules, including a ban on entering confidential or personal information, the range of services that may be used, and restrictions on data storage and training. We have built a system in which every employee can use AI safely based on these guidelines.

Security assessment and approval process for AI services Before introducing any new AI service or tool, we carry out a comprehensive security assessment in advance. We evaluate it from multiple angles, including where data is stored, whether data is used for training, the encryption method, the access control mechanisms, and the vendor's security practices, and we have set things up so that only approved services are used in our work.

Implementing technical security measures Even for permitted AI services, we implement technical safeguards. We apply multiple layers of defense, including strict management of API keys and access tokens, filtering of confidential information, logging and monitoring, and regular security reviews.

Strengthening Internal Training and Awareness

Using AI safely requires not only technical measures but also greater security awareness on the part of every employee. We carry out the following training and awareness activities.

AI security training We regularly run training for all employees on the security risks of using AI services and how to address them. Using real-world examples, the training gives employees the opportunity to learn concrete points to watch out for, such as the risk of information leaks, problems caused by inappropriate prompts, and the risk of infringing copyright and intellectual property rights.

Sharing best practices for secure AI use We collect examples of AI being used safely and effectively within the company and share them across the company as best practices. Through regular knowledge-sharing sessions and our internal portal, we spread know-how on safe usage and security settings and work to raise security literacy across the organization.

Ongoing awareness activities Through our internal communication tools and email newsletter, we continuously share the latest information and alerts on AI security. When new threats or risks are discovered, we have a system in place to share information promptly and make sure everyone knows the countermeasures.

Looking Ahead

Taking this continuation of our certification as an opportunity, we will keep working to strengthen our information security management system in step with the evolution of AI technology. By approaching it from both sides, technical measures and training for our people, we will continue to provide our clients with safe and highly reliable services.

If you are considering strengthening information security in system development, using AI safely, or improving your development setup, please feel free to contact us.

Go to the contact form