Business Continuity PolicyOur foundational stance on business continuity and how we prepare for it.
関連
This policy is an individual policy established under Section 8 (Business Continuity) of the CSR Policy. Please refer to both together.
Read the CSR Policy →
Purpose
This policy exists so that, when a large-scale disaster, an infectious disease, an accident, a cyberattack, or any other unforeseen event occurs, we first secure the safety of our employees and stakeholders, then keep the impact on the services we provide to clients (contract development, quasi-mandate, operations and maintenance, and the like) to a minimum, and recover and continue our business at the earliest opportunity.
Principles & structure
Risks we anticipate
Earthquakes, tsunamis, floods, typhoons, and the like, together with the power outages, water outages, and transport disruptions that accompany them.
Loss of use of the office or work environment due to fire, equipment failure, and the like.
Restrictions on commuting, movement, and travel caused by a widespread outbreak of an infectious disease.
Information-security threats such as unauthorized access, malware, and information leakage.
Suspension or degraded performance of communications, power, cloud, and external services.
Shortages of critical personnel, supply constraints from partner companies and external services, and the like.
The structure that supports continuity
By maintaining, in normal times, an operating structure that does not depend on any particular place or individual, we are prepared to continue our business even in unforeseen situations.
We manage business data, documents, and communication on cloud services, maintaining an operating structure that does not depend on any single office.
Every employee has an environment in which remote work is possible, so we maintain the ability to continue operations even when coming into the office is restricted.
We make use of a two-location structure — the Osaka headquarters and the overseas development center — anticipating alternatives should continuity become difficult in one region.
We manage business data appropriately within approved environments, in accordance with our contracts and our clients’ requirements.
Through multiple means of contact, we maintain the ability to reliably reach our employees and key stakeholders.
From activation
to recovery
When an unforeseen event occurs, we make securing safety our highest priority and then work to continue critical operations and recover early, following the flow below.
As for recovery targets, where a contract or project plan sets terms, those terms take precedence; where none are set, we coordinate with the client based on the degree of impact and the available alternatives.
Cybersecurity
preparedness
In preparation for cyberattacks and information leakage, we maintain an incident-response structure. Should an incident occur, we work to prevent the spread of damage and to grasp its scope, and where it concerns a client’s operations, we report promptly in accordance with our contracts and applicable law. In recovering, we confirm safety and work on preventing recurrence.
Education, training & review
We make this policy known to all employees and conduct training and confirmation on emergency response roughly once a year. We also review this policy roughly once a year in response to changes in our business, structure, contracts, laws, and the results of our training.
詳細
A more detailed Business Continuity Plan (BCP) is maintained as an internal document. At a client’s request, we provide it individually under a non-disclosure agreement (NDA).
Contact us →