Information Security Policy

1. Purpose

In carrying out the provision of diverse information services in the health field (the "Consultation Support Business" and the "Stress Check Business") as well as the management of its employees (hereinafter the "Business"), WorkWay Inc. (hereinafter the "Company") uses a large amount of information assets. The Company therefore recognizes that appropriately achieving information security and striving to protect information assets is an indispensable requirement for promoting corporate activities under the trust of society, as well as a significant social responsibility. Accordingly, in light of the importance of information security, the Company establishes this Information Security Policy (hereinafter the "Policy") and will establish, implement, maintain, and improve an information security management system to put it into practice concretely.

2. Definition of Information Security

Information security is defined as maintaining confidentiality, integrity, and availability.

(1)Confidentiality

This means protecting information assets from unauthorized access and the like, and not disclosing them to those who do not have authorization to view them.

(The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.)

(2)Integrity

This means protecting information assets from tampering and errors, and maintaining them accurately and completely.

(The property of accuracy and completeness.)

(3)Availability

This means protecting information assets from loss, damage, system outages, and the like, so that they can be used when needed.

(The property of being accessible and usable upon demand by an authorized entity.)

3. Scope of Application

This Policy applies to all information assets managed by the Company.

The scope of information assets is not limited to electronic devices and electronic data; it includes all forms, including paper media.

(1)Organization

WorkWay Inc. (all employees)

(2)Facilities

Head office (Address: 1-7-8 Sendagaya, Shibuya-ku, Tokyo)

(3)Operations

Consultation Support Business and Stress Check Business

(4)Assets

Documents, data, information systems, and networks related to the above operations and various services

4. Items to Be Implemented

In accordance with this Policy and the Company's information security management system, we will implement the following items.

(1)Regarding Information Security Objectives

We will formulate information security objectives that are consistent with this Policy and that take into account the applicable information security requirements as well as the results of risk assessment and risk treatment, communicate them to all employees, and review them as needed in response to changes in the Company's environment, and periodically even when there are no changes.

(2)Regarding the Handling of Information Assets

a) Access rights will be granted only to those who require them for their work.

b) Management will be carried out in accordance with legal and regulatory requirements and contractual requirements, as well as the provisions of the Company's information security management system.

c) Information assets will be appropriately classified and managed according to their importance from the perspectives of value, confidentiality, integrity, and availability.

d) Continuous monitoring will be carried out to confirm that information assets are appropriately managed.

(3)Regarding Risk Assessment

a) We will conduct risk assessments and, for the information assets determined to be most important given the characteristics of our business, implement appropriate risk treatment and introduce controls.

b) We will analyze the causes of incidents related to information security and take measures to prevent recurrence.

(4)Regarding Business Continuity Management

We will minimize business interruptions caused by disasters, failures, and the like, and ensure business continuity capabilities.

(5)Regarding Education

We will provide information security education and training to all employees.

(6)Compliance With Rules and Procedures

We will comply with the rules and procedures of the information security management system.

(7)Compliance With Legal and Regulatory Requirements and Contractual Requirements

We will comply with the legal and regulatory requirements and contractual requirements related to information security.

(8)Continual Improvement

We will work toward the continual improvement of the information security management system.

(9)Set of Policies for Information Security

As a set of policies for information security related to the Information Security Policy, we establish the following.

  • Policies for mobile devices
  • Access control
  • Policy on the use of cryptographic controls
  • Clear desk and clear screen policy
  • Policy on information transfer
  • Policy for secure development
  • Information security policy for supplier relationships

5. Responsibilities, Obligations, and Penalties

Responsibility for the information security management system, including this Policy, rests with top management, and employees within the scope of application are obligated to comply with the established rules and procedures. Employees who neglect these obligations and engage in violations will be disciplined in accordance with the provisions of the work rules. With regard to employees of partner companies, action will be taken in accordance with separately defined contracts and the like.

6. Periodic Review

The information security management system will be reviewed periodically and as necessary, and will be maintained and managed accordingly.

Established: March 1, 2021
Last revised: April 1, 2022
WorkWay Inc.
Representative Director and President: Shinya Hanada