Information Security Policy
1. Purpose
In carrying out the provision of diverse information services in the health field (the "Consultation Support Business" and the "Stress Check Business") as well as the management of its employees (hereinafter the "Business"), WorkWay Inc. (hereinafter the "Company") uses a large amount of information assets. The Company therefore recognizes that appropriately achieving information security and striving to protect information assets is an indispensable requirement for promoting corporate activities under the trust of society, as well as a significant social responsibility. Accordingly, in light of the importance of information security, the Company establishes this Information Security Policy (hereinafter the "Policy") and will establish, implement, maintain, and improve an information security management system to put it into practice concretely.
2. Definition of Information Security
Information security is defined as maintaining confidentiality, integrity, and availability.
This means protecting information assets from unauthorized access and the like, and not disclosing them to those who do not have authorization to view them.
(The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.)
This means protecting information assets from tampering and errors, and maintaining them accurately and completely.
(The property of accuracy and completeness.)
This means protecting information assets from loss, damage, system outages, and the like, so that they can be used when needed.
(The property of being accessible and usable upon demand by an authorized entity.)
3. Scope of Application
This Policy applies to all information assets managed by the Company.
The scope of information assets is not limited to electronic devices and electronic data; it includes all forms, including paper media.
WorkWay Inc. (all employees)
Head office (Address: 1-7-8 Sendagaya, Shibuya-ku, Tokyo)
Consultation Support Business and Stress Check Business
Documents, data, information systems, and networks related to the above operations and various services
4. Items to Be Implemented
In accordance with this Policy and the Company's information security management system, we will implement the following items.
We will formulate information security objectives that are consistent with this Policy and that take into account the applicable information security requirements as well as the results of risk assessment and risk treatment, communicate them to all employees, and review them as needed in response to changes in the Company's environment, and periodically even when there are no changes.
a) Access rights will be granted only to those who require them for their work.
b) Management will be carried out in accordance with legal and regulatory requirements and contractual requirements, as well as the provisions of the Company's information security management system.
c) Information assets will be appropriately classified and managed according to their importance from the perspectives of value, confidentiality, integrity, and availability.
d) Continuous monitoring will be carried out to confirm that information assets are appropriately managed.
a) We will conduct risk assessments and, for the information assets determined to be most important given the characteristics of our business, implement appropriate risk treatment and introduce controls.
b) We will analyze the causes of incidents related to information security and take measures to prevent recurrence.
We will minimize business interruptions caused by disasters, failures, and the like, and ensure business continuity capabilities.
We will provide information security education and training to all employees.
We will comply with the rules and procedures of the information security management system.
We will comply with the legal and regulatory requirements and contractual requirements related to information security.
We will work toward the continual improvement of the information security management system.
As a set of policies for information security related to the Information Security Policy, we establish the following.
- Policies for mobile devices
- Access control
- Policy on the use of cryptographic controls
- Clear desk and clear screen policy
- Policy on information transfer
- Policy for secure development
- Information security policy for supplier relationships
5. Responsibilities, Obligations, and Penalties
Responsibility for the information security management system, including this Policy, rests with top management, and employees within the scope of application are obligated to comply with the established rules and procedures. Employees who neglect these obligations and engage in violations will be disciplined in accordance with the provisions of the work rules. With regard to employees of partner companies, action will be taken in accordance with separately defined contracts and the like.
6. Periodic Review
The information security management system will be reviewed periodically and as necessary, and will be maintained and managed accordingly.
Last revised: April 1, 2022
WorkWay Inc.
Representative Director and President: Shinya Hanada

