We maintain and improve information security and the management of protecting personal information, working further increase our trust with customers.
The Benesse Group continues to gain external certifications and implement internal training and other initiatives to strengthen its information security based on our determination to become the company with the strictest security for customer information.
(April 1, 2015)
In addition, details on the purposes for which personal information is obtained, the provision of personal information to third parties, procedures for responding to requests for disclosure, etc. and matters relating to the receipt of complaints / handling of browsing history, etc. are also published and can be found below.
We manage the plans and status of the enforcement of information security and protection of personal information through the Compliance Security Headquarters, led by a managing executive officer CLRO and executive general manager of compliance and information security. An information security chief is appointed in each operating company to implement and promote information security. We have created a system to promote information security, plans to respond to emergencies, and steps to respond to incidents. We have also established an information security surveillance committee as an outside organization. We aim to create world-class information security by being regularly audited by outside experts.
The Benesse Group has established a reporting route and has created a system to quickly take appropriate action when responding to incidents in an emergency.
Employees who discover any anomalies in information security or the handling of personal information or who have received a report of an abnormality from a contractor quickly report to the head of their department. The department head then quickly reports to the Information Security Reporting Office or the Emergency Case Reporting Office (the Benesse Group Hotline). A situation-dependent direct reporting route to the Emergency Case Reporting Office by the person who discovered the abnormality has also been established for reporting emergency cases that are especially urgent. The Compliance Security Headquarters gathers the information and reports the overall status of the incident to the president of Benesse Holdings while also establishing a system to take appropriate measures for the issue that has arisen.
The Information Security Surveillance Committee regular checks data, system operation and maintenance, appropriate security standards for date usage and management, the state of the establishment of rules on usage and management, corresponding standards in Group companies and the state of compliance of rules, etc. within the Benesse Group. Our mission is to make fair decisions from the customer’s point of view, including taking necessary measures for improvement. The committee was established on October 15, 2014, and regularly meets once every quarter. Checks are continuously implemented by outside experts. Members are made up of outside experienced academics who are authorities on information security and the protection of personal information, and they also offer suggestions on how to further strengthen our information security.
Information Security Surveillance Committee Members (FY2024)
Committee Chair | Ryoichi Sasaki |
Current position | … | Professor Emeritus at Tokyo Denki University and Visiting Professor at Tokyo Denki University Cyber Security Laboratory, Honorary president of the Japan Society of Security Management, Director and advisor at the Institute of Digital Forensics, Fellow at the Information Processing Society of Japan, Chief information security advisor at the Board of Audit of Japan |
Career summary | … | Graduated from University of Tokyo in March Joined Hitachi, Ltd. in April 1971. Engaged in research into reliable system technology, security technology, and network management systems at the systems development lab. Appointed as head of the 4th department at the lab (network department), security system research center head, and chief researcher. Moved to Tokyo Denki University in April 2001, assuming the role of professor and Doctor of Engineering (University of Tokyo). He was also appointed as a cyber security aide to the Cabinet Secretariat. |
Awards received | … | IPSJ Outstanding Paper Award, IPSJ Contribution Award, IEEJ Distinguished Paper Award, Ministry of Internal Affairs and Communications Minster's Award, Information Security Culture Award, etc. |
Committee Member | Atsuo Inomata | Professor, Osaka University of Office for Information Security |
Committee Member | Tetsutaro Uehara | Professor, Ritsumeikan University College of Information Science and Engineering |
Committee Member | Harumichi Yuas | Professor, Meiji University of Governance Studies, Graduate School |
(Honorific titles omitted)
We continue our initiatives to strengthen the operation and monitoring of our systems and to strengthen our system security with technological measures based on the latest information so that our customers will feel safe and have the confidence in Benesse to entrust their personal information to us. In addition, we will achieve the world's highest level of information security by receiving audits and advice from outside experts.
New technologies arise every day in our internet-based society. We are implementing measures from the following viewpoints and work to continuously improve.
We continue to implement measures to strengthen our security environment to realize the world's highest level of security. The following are some specific examples.
The Benesse Group clarifies the purpose of use of personal information entrusted to us by our stakeholders and ensures the appropriate management of personal information in a transparent manner at each stage (acquisition, use, utilization, and deletion). In addition, we have established a contact point for requests for disclosure, etc., and respond promptly to such requests.
Please see below for details.
To ensure that our products and services can be used with peace of mind, we are continually reviewing our privacy policy and response based on the feedback we receive.
We set July 7 as Security Day in the wake of the breach on personal information that was discovered in 2014. Benesse Corporation carries out activities on this day each year where all employees pledge to remember incident training and work to strengthen information security. This includes holding morning meetings on information security, presenting internal initiatives, and having lectures from outside specialists.
Benesse Holdings and Benesse Corporation require all people who work for Benesse (i.e., from directors to part-time staff) to attend information security training. Through the training, all employees annually reconfirm the rules and behaviours they should follow and their basic knowledge of information security, particularly with regard to personal information. The training had a 100% attendance rate in FY2023. We have also prepared a system to ensure that security standards and operations are maintained even when employees work from home and conduct training to reconfirm security rules at the start of telecommuting. Other training is also provided in dedicated programmes in the departments responsible for system management in the Group.
After being assessed by JIPDEC, the Benesse Corporation was registered as a business approved to display the PrivacyMark symbol in November 2016.
We will continue to work to maintain and improve our information security and the management and protection of personal information and to further increase our customers' trust.
After ISO27001 (ISMS) certification was acquired by Benesse Corporation School Headquarters and Benesse BASE COM in May 2015, the same certification was also acquired by Benesse Holdings, Benesse Corporation (excluding some offices), and Benesse InfoShell in March 2016. Since the initial registration, we have continued to undergo external audits as annual maintenance audits and renewal audits every three years.
Last updated : 2024/07/18