Information Security Policy
Information Security Principles
Fuji Electric recognizes IT and product security as critical management priorities. Guided by our commitment to business continuity, customer value, and social responsibility, we ensure the safety and reliability of our information assets, products, and services. Accordingly, we have established this Information Security Policy in strict compliance with applicable laws, regulations, and industry guidelines. We are dedicated to maintaining robust IT and product security to protect all company-managed information assets from cyber threats and to prevent security incidents across our product and service offerings.
IT Security Policy
Amidst evolving cyber threats and the rapid advancement of digital transformation, we have established this IT Security Policy. Encompassing both enterprise information and factory security, this policy outlines our commitment to protecting our own information assets as well as those entrusted to us by our customers and business partners.
Protection of Information Assets
We stringently protect all information assets—including customer and partner data, personal information, intellectual property, and operational data across our management, sales, technical, factory, and product domains—and proactively work to mitigate associated security risks.
Compliance with Laws, Standards, Guidelines, and Regulations, and Auditing
We maintain IT security management rules that comply with all applicable laws and regulations, and we enforce these through regular audits. Should any non-compliance or issue be identified, we will promptly implement corrective actions and preventive measures.
Organizational Structure and Incident Prevention/Response
Management will continuously promote and improve IT security activities based on this policy. To oversee and drive our IT security initiatives, management has established specialized response teams, including a CSIRT (Computer Security Incident Response Team) and an FSIRT (Factory Security Incident Response Team). We strive to prevent IT security incidents; in the event of an incident, we will respond promptly and appropriately, investigate the cause, and implement measures to prevent recurrence.
Supply Chain Management
We are committed to robust risk management and the enforcement of IT security across our entire supply chain, including all procurement activities.
Information Disclosure
Information regarding IT security incidents will be shared and communicated promptly and appropriately with customers and relevant parties as necessary.
Education and Training
We will provide planned and continuous IT security education and training to our employees to raise awareness and ensure thorough understanding.
Continuous Improvement
To ensure IT security, we will formulate plans, implement measures, evaluate their effectiveness, and make continuous improvements.
Product Security Policy
We have established this Product Security Policy to safeguard the information and ensure the safety of all customers utilizing our products and services. We are committed to strengthening the security of our products and services across the entire supply chain and responding appropriately to vulnerabilities.
Protection of Information Assets
We will appropriately protect all information assets related to our products and services, striving to mitigate threats to and minimize risks regarding these assets.
Compliance with Laws, Standards, Guidelines, and Regulations, and Auditing
We comply with all relevant laws, regulations, industry standards, and guidelines, embedding these requirements into every phase of our product lifecycle: design, development, procurement, manufacturing, and maintenance. We will ensure our product security management rules comply with laws and conduct regular audits.
Organizational Structure and Response to Vulnerabilities and Incidents
Spearheaded by the Product Security Committee, we champion "Secure by Design" methodologies to proactively eliminate vulnerabilities during the design and development phases, well before products or services reach the market. We will establish and operate policies regarding the collection, investigation, mitigation, and disclosure of vulnerability information. Furthermore, we will set up a point of contact to receive vulnerability information. We strive to prevent product security incidents; in the event of an incident, we will respond promptly and appropriately, working with customers to investigate the cause and implement measures to prevent recurrence. We will establish a PSIRT (Product Security Incident Response Team) to promote activities related to product security.
Supply Chain Management
We will work on risk management and ensuring product security across the entire supply chain, including procurement, manufacturing, and maintenance.
Information Disclosure
Vulnerability and incident information regarding our products and services will be shared and communicated appropriately and promptly with customers and relevant parties. Should a vulnerability impact specific customers, we will proactively contact them individually via our sales representatives.
Education and Training
We will provide planned and continuous product security education and training to employees involved in the development, manufacturing, and operation of our products.
Continuous Improvement
To ensure the security of our products and services, we will formulate plans, implement measures, evaluate their effectiveness, and make continuous improvements.