Product Security Policy
We have established this Product Security Policy to safeguard the information and ensure the safety of all customers utilizing our products and services. We are committed to strengthening the security of our products and services across the entire supply chain and responding appropriately to vulnerabilities.
We will appropriately protect all information assets related to our products and services, striving to mitigate threats to and minimize risks regarding these assets.
We comply with all relevant laws, regulations, industry standards, and guidelines, embedding these requirements into every phase of our product lifecycle: design, development, procurement, manufacturing, and maintenance. We will ensure our product security management rules comply with laws and conduct regular audits.
Spearheaded by the Product Security Committee, we champion "Secure by Design" methodologies to proactively eliminate vulnerabilities during the design and development phases, well before products or services reach the market. We will establish and operate policies regarding the collection, investigation, mitigation, and disclosure of vulnerability information. Furthermore, we will set up a point of contact to receive vulnerability information. We strive to prevent product security incidents; in the event of an incident, we will respond promptly and appropriately, working with customers to investigate the cause and implement measures to prevent recurrence. We will establish a PSIRT (Product Security Incident Response Team) to promote activities related to product security.
We will work on risk management and ensuring product security across the entire supply chain, including procurement, manufacturing, and maintenance.
Vulnerability and incident information regarding our products and services will be shared and communicated appropriately and promptly with customers and relevant parties. Should a vulnerability impact specific customers, we will proactively contact them individually via our sales representatives.
We will provide planned and continuous product security education and training to employees involved in the development, manufacturing, and operation of our products.
To ensure the security of our products and services, we will formulate plans, implement measures, evaluate their effectiveness, and make continuous improvements.
To facilitate the early identification and remediation of product security issues (vulnerabilities), Fuji Electric collects vulnerability information from both internal and external sources and promotes a framework that enables effective collaboration with relevant stakeholders to address such issues.
-
We welcome vulnerability reports and related information from security researchers, industry experts, customers, and other stakeholders.
-
Reported vulnerability information is handled with strict confidentiality and is evaluated and verified through our internal review process.
-
Where necessary, we promptly prepare and provide remediation measures, including security patches and workarounds.
-
Personal information of reporters and the contents of vulnerability reports are managed appropriately in accordance with our Privacy Policy.
-
Such information will not be used for purposes other than those intended, nor disclosed to inappropriate third parties.
-
We publish information regarding identified vulnerabilities, including their potential impact and available mitigation measures.
-
Vulnerability information is disclosed at an appropriate time, taking into account the risk of exploitation and allowing customers sufficient time to prepare and implement countermeasures.
-
When appropriate, we share information concerning identified vulnerabilities with relevant authorities and organizations, including “JPCERT/CC” and the CERT of each country.
-
For vulnerabilities affecting purchased hardware or software, we work closely with suppliers and vendors to coordinate and implement appropriate remediation measures.
-
We periodically review this policy and continuously strive to improve our vulnerability management processes.
For information regarding our Coordinated Vulnerability Disclosure (CVD) Policy, please click [here].
About JPCERT/CC
JPCERT Coordination Center (JPCERT/CC) is a non-profit organization independent of any specific government agency or private company. As a neutral organization, it works to promote the stable operation of information systems and minimize damage caused by computer security incidents.
If you have discovered a vulnerability affecting a Fuji Electric product, please report it by email using the contact information below.
Email Address:
fe-psirt@fujielectric.com
Information Requested:
Required
・Product name and model number
・Detailed description of the vulnerability
Optional
・Your name (a pseudonym or handle name is acceptable)
・Email address (if you would like us to respond to a specific address)
・Telephone number
Please note that the information requested above may be revised from time to time.
The following describes Fuji Electric Group's policy and requests regarding the submission of vulnerability information.
-
Any vulnerability information and personal information submitted to us will be handled in accordance with the Fuji Electric Privacy Policy.
-
Please refrain from publicly disclosing vulnerability information to third parties until coordination between Fuji Electric and relevant stakeholders has been completed.
-
When verifying a vulnerability, please take reasonable care to avoid causing harm to Fuji Electric, our customers, or any third party.
-
In accordance with our Coordinated Vulnerability Disclosure (CVD) Policy, Fuji Electric does not intend to initiate legal action solely on the basis of a vulnerability report submitted in good faith.
For more information, please refer to our Coordinated Vulnerability Disclosure (CVD) Policy