Information Security

Information Security Policy

Enacted: December 1, 2006

SB AtWork Corp. (hereinafter referred to as”SB AtWork”) aspires to be highly evaluated by society both in name and reality by taking drastic and high-level measures against the risk of information leakage. To this end, with a view to making information security a fundamental and absolute corporate culture, SB AtWork has developed “Information Security Policy” that clarifies this policy.

SB AtWork intends, from now on, to comply with “Information Security Policy” and “Personal Information Protection Policy” as separately indicated and maintain an advanced information security management structure.

1.Buildup of information security management structure
Build up a highly secured information security management structure to gain the societ’s confidence at any time through making every possible effort to protect all information assets held by SB AtWork as well as complying with the information security-related statutes and other rules.
2.Assignment of “Chief Information Security Officer”
Assign “Chief Information Security Officer (CISO)”, which enables SB AtWork to take proactive actions to have accurate visibility of the companywide information security status and to promptly take necessary measures.
3.Development of information security-related company rules
Develop company rules based on Information Security Policy to demonstrate the clear policy for not only the personal information but also information assets in general as well as internally and externally keep everyone informed about SB AtWork’s tough stance against the information leaks.
4.Development/enhancement of audit structure
Further develop the structure which enables SB AtWork to carry out internal audits of compliance with Information Security Policy, the company rules and other relevant rules. In addition, SB AtWork makes every possible effort to continue external audits to obtain more objective evaluation. SB AtWork will prove that all of its employees comply with Information Security Policy.
5.Implementation of system with full information security measures
Implement a fully protected system against unauthorized access to, leaks, modification, loss, destruction or hindered use, of the information assets. As preventive measures, SB AtWork gets involved in this issue with the view to completely controlling access to data such as working in a highly secure area and preventing unauthorized users from accessing data base.
6.Enhancement of information security literacy
Ensure that all employees and temporary staffers are given security education/training and that all people engaged in SB AtWork’s information assets perform activities with information security literacy. In addition, SB AtWork will continue providing its employees with education/training to cope with ever-changing circumstances.
7.Strengthened management structure of outsourcing agents
Request outsourcing agents to keep a security level which is the same or more than that of SB AtWork by fully examining eligibility of the outsourcing agents when outsourcing operations. In addition, SB AtWork intends to continuously review the outsourcing agents to reinforce contract terms with intent to confirm without interruption that the security level is adequately maintained.

Coverage of Information Security Policy

“Information assets” covered by this policy are information obtained or known in the ordinary course of SB AtWork’s business and all the information held by SB AtWork for its business. All of SB AtWork’s “Directors, employees and temporary staffers” who are engaged in handling and controlling these information assets as well as “outsourcing agents and their employees” who deal with SB AtWork’s information assets must comply with Information Security Policy.