Information Security Policy

Chino Corporation (hereinafter referred to as "the Company") is committed to maintaining and improving the trust of its customers, business partners, and society.
With the aim of ensuring the confidentiality, integrity, and availability of information assets, maintaining business continuity, and fulfilling social responsibility,
This Information Security Basic Policy (hereinafter referred to as "this Policy") is established hereby.
Furthermore, based on this policy and the separately posted "Handling of Personal Information" (hereinafter referred to as the "Privacy Policy"),
We strive to maintain and improve information security.

1. Applicable Subjects and Scope

This policy applies to the information assets and information systems that our company acquires, possesses, manages, or handles in the course of its business activities.
All of our officers, employees, and our business partners and their employees who handle our information assets,
We will abide by this policy and privacy policy.

2. Information Security Management System

Our company has established an information security management system to protect and properly manage information assets.
The management team will provide the necessary resources and collaborate with the information management officers of each organization.
We will strive to maintain and improve our information security management system and promote information security measures.
These management systems allow us to accurately assess the information security situation and promptly implement necessary countermeasures.

3. Risk Management

Our company assesses threats and vulnerabilities to information assets, information systems, and services we use.
We will continuously conduct risk assessments that take into account the impact on our business.
Based on the results, we will implement appropriate risk mitigation measures and periodically review their effectiveness.
Our company strives to maintain and improve information security level throughout our entire group and to manage risks.

4. Compliance with Laws and Regulations and Internal Rules

Our company complies with domestic and international laws, regulations, guidelines, and customer requirements regarding information security.
We will establish regulations based on this policy and privacy policy, and ensure strict adherence to them.
We will take appropriate action against any violations in accordance with our internal regulations, and we will prevent accidents by making the details of these regulations known in advance.

5. Protection of Information Assets

Our company takes measures to prevent incidents such as unauthorized access, leakage, alteration, loss, destruction, and service interruptions to information assets.
We will implement organizational, human, physical, and technical safety management measures.

6. Management of Cloud Services and External Services

Our company assesses the risks associated with the use of cloud services and implements appropriate security measures according to the purpose of use.
We will clearly define the division of responsibilities with the provider, continuously monitor usage, and strive to maintain safety.

7. Incident Management

Our company has established a system for preventing information security incidents and responding to them, striving to minimize damage, achieve rapid recovery, and prevent recurrence.
In the event of an incident, we will promptly and appropriately report it to the relevant parties and organizations, and take necessary action.

8. Business Continuity Measures

Our company develops business continuity plans (BCPs) and recovery plans, and conducts regular training and reviews to prepare for disasters, cyberattacks, and other events.

9. Education/Training

Our company aims to improve the information security literacy of all officers, employees, and related parties.
To ensure proper management of information assets, we will continuously and regularly conduct education and training to raise awareness.

10. Supply Chain Management

When selecting stakeholders that configuration our supply chain (outsourcing partners, external partners, cloud service providers, etc.),
We will thoroughly review their eligibility.
We require an appropriate level security for each target, and clarify responsibilities and obligations through contract signing, verification of external certifications, or other means.
Audits and reviews will be conducted to ensure that the required security level is properly maintained.

11. Auditing and continuous improvement

Our company ensures that all laws, internal regulations, and operational procedure related to information security are complied with in the course of our business operations.
We will conduct an internal audit of information security to verify that it is functioning effectively.
Furthermore, in order to maintain and improve the effectiveness of the Information Security Management System (ISMS),
We will strive for continuous improvement through management reviews and corrective actions.


This policy will be communicated to all of our officers, employees, and related parties, and will be made public as necessary.
Furthermore, we will review our policies as needed in response to changes in the information security environment and our business operations.

Revised September 1, 2026
Chino Corporation
Representative Director and President: Mikio Toyoda

If you have any problems with temperature control,
 please feel free to contact us.

Membership
CHINO Web Membership Information

If you register as a CHINO Web member, you will be able to view the product's instruction manual.
If you wish, we will send you the latest information on CHINO products via email.

You must be a login to download.