Menicon Group Information Security Policy
Menicon Group Information Security Policy
As a provider of high-quality products and services, most notably medical equipment, the Menicon Group has always set and strived to surpass its own high safety standards.
We believe this safety philosophy goes beyond merely making safety the top priority in manufacturing and service delivery. It also applies to our obligation to ensure rigorous control and protection from internal and external threats for information assets comprised of valuable personal information concerning customers, information assets accumulated and required by Group companies for product development processes, and various other information assets related to the administration of each company.
For these reasons, the Menicon Group has formulated a basic policy concerning information security and hereby declares that by building and administering information security systems and instituting appropriate safety measures, we will safeguard information assets concerning customers and group companies, including personal information, from all threats, whether deliberate or accidental.
The Menicon Group will abide by the following basic provisions:
- With regard to information assets concerning customers and group companies, including personal information, we will establish information security measures to maintain and ensure confidentiality, integrity, and availability.
- To implement information security measures appropriately and reliably, we will establish a structure, clarify responsibilities, and specify the information that needs to be protected.
- To maintain our information security measures, we will define processes corresponding to each phase of the PDCA (plan, do, check, act) cycle and maintain/enhance the level of information security.
- To ensure understanding of the vital nature of information security measures, we will provide training and education on information security to our officers and employees.
- We will safeguard the personal information handled during the course of business activities and institute necessary protections and appropriate safety measures in accordance with a Personal Information Protection Policy.
- We will establish and abide by internal rules and management procedures concerning information security.
- We will impose penalties for violations of this basic policy or of various rules in accordance with rules concerning rewards and penalties.