uSonar has established an advanced security framework to protect our extensive database.
We have appointed a manager responsible for the handling of personal information, clarified the scope of employees who handle personal information and the personal information they manage, and established a reporting and communication system to the responsible manager in the event that any facts or signs of violations of the Personal Information Protection Act or internal regulations are identified.
Development of Organizational Structure
To manage personal information securely, we have appointed a Chief Privacy Officer (CPO), an audit manager, and various operational managers, clearly defining their responsibilities and roles.
Development and Operation of Compliance Programs (Personal Information Protection Regulations)
We have established a compliance program as a code of conduct for personal information protection (including provisions based on the determination that Japan ensures an adequate level of protection for personal information in accordance with GDPR). We conduct regular education and training for all personnel engaged in uSonar's business to ensure thorough awareness and promote continuous improvement.
Means to Monitor the Handling Status of Entrusted Data
We have built a system that centralizes the handling status of entrusted media using a management ledger. When data is entrusted, we issue a "Customer Information Deposit and Return Receipt," store the data on servers with access restrictions, and manage physical media under lock and key.
Evaluation, Review, and Improvement (Establishment and Operation of the Security Center)
We have assigned responsible personnel and staff for personal information and execute ongoing evaluations, reviews, and improvements through our Security Center (Management Committee Chairperson: Representative Director Nami Fukutomi).
Response to Incidents or Violations
In the unlikely event that an incident or violation is discovered, our Security Center has established a workflow to conduct fact-finding investigations, determine root causes, identify the scope of impact, implement recurrence prevention measures, and execute appropriate corrective actions.
We conduct regular training for employees regarding considerations for handling personal information and include confidentiality requirements for personal information in our employment regulations. We implement personnel security management measures by requiring employees to sign non-disclosure agreements for designated confidential personal information and by providing ongoing education and training.
We implement physical security management measures, including access control for buildings and rooms, and the prevention of theft of personal information, to protect against unauthorized access, loss, destruction, alteration, and leakage of information.
Prevention of Theft and Other Incidents
• Surveillance Cameras
We monitor for unauthorized intruders and illicit activities 24 hours a day, 365 days a year using surveillance cameras. Recorded image data is retained for a minimum of three months for log management purposes.
• Locked Storage for Electronic Media
In addition to physical locking mechanisms, access to areas containing storage cabinets is restricted via our access control system.
• After-Hours and Holiday Security
We maintain 24/7, 365-day security through a combination of building security personnel and monitoring equipment, including surveillance cameras and access control systems.
• Prohibition of Removing Equipment from the Office
Removing equipment such as PCs from the office is prohibited. Exceptions are permitted only following a formal application to and approval by the CIO.
• Implementation of Personal Belongings Inspections
We conduct random inspections of personal belongings to regularly check for unauthorized items, such as personal PCs, storage media, unapproved smartphones, or hazardous materials.
We have implemented mechanisms to protect information systems that handle personal data from unauthorized external access or malicious software.
Access Control
• Login Control
uSonar grants access to personal information only to authorized personnel. Data is not duplicated, and access logs are maintained and monitored. Furthermore, at uSonar, each individual sets their own password for logging into their personal terminal. Electronic documentation is managed on a shared server, with access control implemented at the folder level within the system.
• ID Management and Deletion
We immediately modify or revoke access rights, including IDs and building access cards, for employees who transfer or resign.
Software Security Measures
Malware Protection
To defend against both known and unknown malware, we have installed multiple security software solutions on all terminals.
Blacklisting
Each user is granted only standard user privileges on their terminal and is prohibited from installing applications. We maintain a blacklist of unauthorized software and have implemented controls to prevent such software from launching, even if it were to be installed.
For security reasons, other measures are not disclosed. Please contact us for further details. We will provide explanations as necessary.
uSonar has obtained three ISO certifications.
December 15, 2021: Partially Revised
July 19, 2022: Updated company name from Landscape Co., Ltd. to uSonar Co., Ltd.