Information Security Policy

Established February 1, 2021
Neural Group Inc.
Representative Director: Michitake Shigematsu

Basic Philosophy

Information assets handled in the course of the business of Neural Group Inc. (hereinafter referred to as the “Company”), including customer information, are of vital importance as the foundation of the Company’s management. Recognizing the importance of protecting information assets against risks such as leakage, damage, and loss, all persons who handle information assets, including officers and employees,
shall comply with this Policy and carry out activities to maintain information security, including the confidentiality, integrity, and availability of information assets.

Basic Policy

1. To protect information assets, the Company shall establish an information security policy and related rules, conduct its operations in accordance with them, and comply with laws, regulations, and other standards relating to information security, as well as its contractual obligations to customers.

2. The Company shall clearly define criteria for analyzing and evaluating risks to information assets, including leakage, damage, and loss; establish a systematic risk assessment methodology; and conduct risk assessments periodically. Based on the results, the Company shall implement necessary and appropriate security measures.

3. The Company shall establish an information security framework led by the responsible officer and clearly define authority and responsibilities relating to information security. The Company shall also provide regular education, training, and awareness activities to ensure that all personnel recognize the importance of information security and properly handle information assets.

4. The Company shall periodically inspect and audit compliance with the Information Security Policy and the handling of information assets, and shall promptly take corrective action regarding any deficiencies or areas for improvement identified.

5. The Company shall take appropriate measures to address information security events and incidents. In preparation for any such event or incident, the Company shall establish response procedures in advance to minimize damage, respond promptly in an emergency, and take appropriate corrective action. In particular, for incidents that may cause business interruption, the Company shall establish a management framework and review it periodically to ensure business continuity.

6. The Company shall establish and implement an information security management system with objectives designed to realize the Basic Philosophy, and shall continuously review and improve the system.

If you have any questions, please contact us at the address below.

contact@neural-group.com