Information Security Policy
HITEC CO., LTD. (hereinafter referred to as "the Company") recognizes that the appropriate protection of information assets is essential to fulfilling its social responsibility. In order to properly manage and protect all information assets, including the personal information of customers, business partners and employees, the Company addresses information security on a company-wide basis in accordance with the policy set out below, and endeavors to ensure the confidentiality, integrity and availability of its information assets. This Policy applies to all persons working for the Company, regardless of their form of employment, and to all information assets held or managed by the Company.
1. Responsibility of Management
Under the leadership of its management, the Company endeavors to improve and enhance information security in an organized and continuous manner.
2. Establishment of an Internal Framework
The Company establishes a management framework for maintaining and improving information security, and sets out information security measures as formal internal rules.
3. Commitment of Employees
Employees of the Company acquire the knowledge and skills required for information security, thereby ensuring that the Company's information security efforts are effective.
4. Compliance with Legal and Contractual Requirements
The Company recognizes its information assets, including customer and employee information and design data under development, as confidential information. The Company complies with laws, regulations, standards and contractual obligations relating to information security, and meets the expectations of its customers.
5. Response to Violations and Incidents
In the event of an information security incident or accident, the Company responds and restores operations promptly, investigates the cause, and endeavors to prevent any recurrence.
6. Management of Contractors and Business Partners
Where the Company outsources part of its operations to external parties, it requires its contractors to implement information security measures equivalent to the Company's own standard, and exercises appropriate management and supervision through contracts and other means.
7. Protection of Personal Information
The Company complies with the Act on the Protection of Personal Information and other relevant laws and regulations, and appropriately acquires, uses and manages the personal information of customers, business partners and employees. The handling of personal information is governed by the Privacy Policy established separately.
8. Review and Continual Improvement of the Policy
The Company reviews this Policy periodically and improves it on a continual basis in response to changes in the social environment and in laws and regulations, advances in technology, and changes in its business activities.