| Certification standard | ISO/IEC 27001:2022+Amd 1:2024(JIS Q 27001:2025) |
|---|---|
| Registered organization name | NHK Enterprises, Inc. (excluding operations of the Archive Business Department at the NHK Archives in Kawaguchi and operations of the General Archives Desk at the NHK Broadcasting Center as well as all branch offices) |
| Address | 4-14 Kamiyama-cho, Shibuya-ku, Tokyo 150-0047, Japan |
| Departments in scope |
|
| Business activities in scope |
|
| Date of initial registration | August 9, 2010 |
| Certification determination date | October 10, 2025 |
Information Security Policy
Introduction – Information security objectives of NHK ENTERPRISES
NHK ENTERPRISES, INC. (“the Company”) conducts its business based on the trust of its customers by contributing to the realization of a prosperous society and the creation of culture through diverse businesses, including the production and sales of various content such as NHK broadcast programs, and the planning and implementation of events.
In the environment surrounding the Company, convenience has improved through advances in IT technology, cloud services and the use of AI. At the same time, risks related to information security have been increasing due to the rising sophistication and complexity of cyberattacks, the expansion of information distribution, and other factors.
Amid such an environment, the Company positions information security as a foundation for business continuity and value creation and implements appropriate measures based on proper risk assessments, aiming to strike a balance between the protection and utilization of information assets.
Moreover, information security is underpinned not only by the Company’s organizational structure, but also by the awareness and actions of each individual involved in the Company’s activities. Accordingly, it is important for everyone associated with the Company to work proactively to maintain and enhance information security.
The Company will continually improve its initiatives through the operation of its Information Security Management System (ISMS) to pursue trustworthy business activities and continuously deliver the value of compelling content.
Basic Policy for ISMS Operation
-
Operation of the Information Security Management System (ISMS)
To achieve its information security objectives, the Company regards its ISMS as an integral part of integrated risk management. This system protects our information and related assets from all threats, whether internal or external, intentional or accidental, while also serving as a means to actively leverage them. -
Information Security Initiatives
Officers and employees of the Company, as well as all other persons engaged in its business activities, recognize the importance of protecting and utilizing information assets. We will undertake concerted efforts to implement information security measures, keeping the following points in mind.- We swiftly and accurately identify changes in both internal and external environments and assess their impact on business operations.
- We implement appropriate information security management commensurate with risks and strive to prevent information security incidents before they occur.
- In the event of an incident, we will minimize damage, ensure a prompt response and recovery, and prevent recurrence.
- We will ensure the availability of information assets, enabling access to necessary information when it is needed.
-
Compliance with Information Security-related Standards and Contracts
We will comply with laws and regulations such as the Act on the Protection of Personal Information and the Copyright Act as well as norms and contracts related to information security, such as agreements with business partners. -
Establishment and Revision of Information Security Procedures
We will establish and implement appropriate procedures to maintain and enhance information security. We will also continually revise the content in response to future changes in the environment and risks. -
Education and Training on Information Security
To maintain and enhance information security, we will implement necessary education and training for officers and employees, as well as all other persons engaged in our business activities, aiming to raise awareness of information security and ensure it is put into practice. -
Audits and Improvement
In addition to undergoing third-party audits based on JIS Q 27001, we conduct regular internal audits, using the results to evaluate the effectiveness of our ISMS and ensure continuous improvement. -
Establishment of System
An ISMS Committee will be established to operate the information security management system, and an appropriate system will be maintained by clearly defining responsibilities and authority through the appointment of an ISMS Management Representative and other actions.
Establishment date: March 9, 2010
Revision date: June 23, 2026
NHK ENTERPRISES, INC.
Naoki MIZUNO, Executive Managing Director (CDXO)

