In the event of any discrepancy between this translated version and the Japanese version, the Japanese version shall prevail.
Information Security Policy
株式会社フォーク (hereinafter referred to as “the Company”) recognizes information as an extremely important asset for the sustainable growth of society. To earn our customers’ trust and give them peace of mind, and to ensure our employees can work together in an environment of mutual trust and security, we have established and shall comply with the following Information Security Policy.
Scope
This policy applies to all business operations and all information handled by the Company.
Establishment of Continuous Improvement Systems (Management System)
All officers and employees of the Company (including part-time workers and partner companies) shall understand this policy and comply with all regulations. Furthermore, we believe the importance of information should not merely be taught passively, but proactively embraced, communicated, and passed down; therefore, we engage in continuous review and improvement activities. This policy and its supporting systems are reviewed and decided upon by the Management Meeting on an annual basis or as necessary. We appoint responsible managers and conduct planned audits, inspections, and training.
Compliance with Laws and Contracts
We comply with all applicable laws and regulations, national guidelines, other norms, and contractual obligations regarding the information handled by the Company.
Implementation of Risk Assessment
The Company continues to maintain high standards of information security within the information industry and contributes to the formulation and realization of social frameworks. Furthermore, while maintaining strict confidentiality, we encourage sharing information so that knowledge becomes explicit.
Established: August 22, 2013
Last Revised: May 1, 2015
Go Sato, President and Representative Director, 株式会社フォーク
Information Security Initiatives
To provide our customers with safe, secure, and high-quality services and to maintain a high level of trust with them, we take the necessary security control measures. These measures protect information obtained through our services, as well as our systems and information assets, from threats such as unauthorized access, crime, negligence, and disasters.
1. Organizational Security Control Measures
- Establishment of various regulations (Work Rules, Information Security Regulations, Personal Information Protection Regulations, etc.)
- Stipulation of disciplinary actions for violations within the Work Rules
- Implementation of information classification (Classifications: General, Internal Use Only/Restricted to Relevant Parties, Confidential, Strictly Confidential)
- Appointment of necessary roles and authorities (Security Committee, Security Manager/Personal Information Protection Manager, Audit Manager, System Administrator, Facility Manager, etc.)
- Implementation of audits (Internal and External)
- Internal Audits (twice a year): Conducted by internal auditors. ※Internal auditors undergo auditor training.
- External Audits (twice a year): Audits by third-party certification bodies (ISMS, Privacy Mark), and platform diagnostics for FORTS servers.
- Periodic reviews by management (twice a year)
- Establishment of various usage rules (teleworking, cloud services, PCs, smartphones, generative AI, social media, etc.)
- Enrollment in IT Professional Liability Insurance and Cyber Insurance (including personal information leakage)
2. Physical Security Control Measures
- Access control to facilities via entry systems
- Zoning of office areas according to security levels
- Installation of security cameras within the office
- Locked storage of paper and recording media containing confidential or personal information
- Disposal of paper and recording media containing confidential or personal information via shredding or pulping
- Physical destruction of PC/server hard drives by selected vendors and receipt of destruction certificates
3. Technical Security Control Measures
- Configuration of user-specific login passwords for business PCs
- Installation of security software on business PCs (virus definition files are updated automatically every day)
- Configuration of firewalls via security software (to defend against unauthorized access from external sources)
- Implementation of hard drive encryption for laptops
- Implementation of loss prevention measures for mobile devices via MDM tools
- Logging of USB and other recording media connected to PCs
- Disposal of information using disk initialization tools when PC data is no longer required
- Access control and logging for internal file servers
- Implementation of regular backups for internal file servers
- Use of Google Workspace for internal groupware (managing email, chat, storage, video conferencing, calendar, remote desktop, etc., within the company)
- Access control, data retention, and record retention for Google (Google Vault)
- Protection of Google accounts with 2-Step Verification
4. Human Security Control Measures
- Implementation of regular training (twice a year) and training upon joining the company
- Implementation of emergency response drills (once a year)
- Mandatory carrying of emergency contact information and safety cards
- Confidentiality agreements signed upon joining and leaving the company
- Monthly comprehension tests for all employees
Initiatives for Personal Information Protection
1. Organizational Security Control Measures
- Classification by confidentiality level and establishment of handling rules (Personal information entrusted by clients is classified as “Strictly Confidential”)
- Maintenance of a personal information management ledger
- Operation in accordance with the Personal Information Protection Regulations, etc.
- Establishment of rules for entry/exit and other procedures for the secretariat handling strictly confidential personal information
- Establishment of rules for transporting media containing strictly confidential personal information
2. Physical Security Control Measures
- Restriction of strictly confidential personal information handling to the secretariat area
- Installation of task-specific terminals within the secretariat area (e.g., terminals dedicated to extracting personal information)
3. Technical Security Control Measures
- Use of SSL-encrypted communication when collecting personal information
- Detection of improper storage using the personal information detection tool “P-Pointer”
- Establishment of file server areas specifically for the processing and storage of strictly confidential personal information
- Installation of web filtering software on secretariat business PCs that handle personal information
- Installation of EDR on secretariat business PCs that handle personal information
4. Human Security Control Measures
- Encouraging employees to obtain the Personal Information Protection Specialist qualification (assigning qualified individuals to personal information projects)
5. Understanding the External Environment
- Understanding foreign personal information protection systems and implementing appropriate security control measures
When storing personal data in foreign countries, we will implement appropriate security control measures after understanding the systems of the respective country.
The location of foreign entities entrusted by the Company and the overview of the personal information protection systems in those countries are as follows:
United States /
System Overview (Refer to Federal and California state information from the Personal Information Protection Commission)
※Regarding the storage of personal information handled in entrusted work, we limit storage to the Tokyo Region.
※For services whose server location cannot be identified due to fault-tolerance measures, etc., we use them only after confirming the security control measures of the service provider.
Services with unidentifiable server locations: Google Workspace /
Service Provider Security Control Measures
Initiatives for Teleworking
Remote work is our basic working style (security-sensitive areas and similar spaces are set up in the office).
- Use of company-provided devices (security software installed)
- Taking devices out of the home is prohibited (requires approval from a supervisor, hard drives must be encrypted, and devices must be registered in MDM tools)
- Saving information directly onto the device is prohibited (must be stored in company-designated storage, etc.)
- Wireless LAN must meet specific encryption and password requirements (Encryption: WPA2 or higher; Password: at least 8 characters mixing letters, numbers, and symbols)
- Storage and disposal of paper and recording media must be conducted within the company
- Rules explicitly state that family members must not use the devices
- Working with personal information is prohibited (when handling such information, users must operate internal devices via remote access)