Information Security

Information Security Policy

Guided by its corporate philosophy, HIMACS conducts its business with the mission of remaining a company continually chosen by customers as their best partner by providing high-value-added solutions.

To fulfill this mission, the Company has established an information security management system. Based on the fundamental principles of ensuring the confidentiality, integrity, and availability of information, the Company seeks to maintain and enhance social trust by meeting the information security requirements of customers, business partners, and other stakeholders.

The Company hereby establishes this Information Security Policy as a framework for setting and reviewing information security objectives and targets, and as guidelines for appropriately managing all information assets handled during the Company’s business activities.

1. Information Security Measures

The President will establish an organizational framework to manage information security and enhance information security practices.

The Company identifies and evaluates the risks and opportunities associated with the information assets it handles, and implements appropriate information security measures accordingly.

The Company implements and continuously strengthens technical and organizational cybersecurity measures against threats such as cyberattacks and unauthorized access.

The Company operates its information security management system through the PDCA cycle, regularly evaluates its effectiveness, and makes continuous improvements.

2. Obligations of Personnel and Organizations

All personnel engaged in the Company’s business and all organizations within the Company must understand and comply with the Company’s Information Security Policy and related security policies, and act in accordance with them.

If any personnel engaged in the Company’s business violates the established security policies, the applicable disciplinary rules will apply.

3. Compliance with Relevant Laws and Regulations

The Company and all personnel engaged in the Company’s business must comply with all laws, regulations, and contractual requirements related to information security, and act in accordance with them.

4. Information Security Education

The Company systematically provides necessary information security education and training to personnel engaged in the Company’s business according to their respective duties, to raise awareness of information security and maintain and improve their competency.

The Company also verifies the effectiveness of its education and training and makes improvements as necessary.

Established: December 1, 2004
Revised: June 19, 2026

Kenji Takada
President and CEO
HIMACS, Ltd.