Product Security
Product Security Initiatives
- 1.As part of our internal structure to address the information security quality of our products and services, PSIRT (Product Security Incident Response Team) is established in the Hioki management system organizational chart. We are committed to addressing the information security of our products and services.
- 2.Hioki is responsible for widely collecting information on vulnerabilities in the products and services provided to customers, and for promptly addressing any vulnerabilities discovered in cooperation among its product design, manufacturing, and service operation departments. Also, we disclose the vulnerabilities information and countermeasures widely to our customers.
- 3.We will promote the introduction of design and development methods that prevent vulnerabilities from being introduced before providing products and services to our customers. We will provide necessary security training to all executives and employees involved in development of products and services.
- 4.Hioki implements efficient vulnerability handling with external stakeholders through its CVE (Common Vulnerabilities and Exposures) Program.
Product Security Policy
As a company providing products and services, we consider that it is our responsibility to ensure the security related to our products and services (hereinafter referred to as "product security") and to take appropriate measures to prevent causing significant harm or impact to our customers.
To ensure that our customers can use our products and services securely, we will thoroughly inform all our executives and employees involved with our products and services of the importance of product security, and strive to implement the following measures, as well as to improve and maintain them through regular inspections and reviews.
1. Legal Compliance
We comply with the laws and regulations of each country relating to product security, and take appropriate protective measures for personal information in accordance with our “Personal Information Protection Policy.”
2. Organization
PSIRT (Product Security Incident Response Team) is established at our Headquarters to manage the product security activities.
3. Education and Training
To improve knowledge and skills for product security and to foster a culture that ensures thorough implementation of these activities, we will continuously implement measures of education and awareness program for product security to all officers and employees involved with our products and services.
4. Product Development
We appropriately incorporate the requirements and verification methods of industry standards, guidelines, and regulations related to product security into our product development.
5. Action for security issue
In the event of a product security issue, we investigate the cause, take corrective measures, and strive to prevent recurrence. We provide information to our customers as necessary, in cooperation with government agencies and other relevant organizations, and through methods such as posting information on our website.
Product Security Response Structure
Establish PSIRT (Product Security Incident Response Team) headed by the Director of Quality Assurance Department at Headquarters as contact point for customers, and address the security quality of products and services of our group.
Vulnerability Disclosure Policy
To ensure product security and protect our customers from cyberattacks, we disclose information regarding product vulnerabilities through the following process, based on "ISO/IEC 29147" --> "ISO/IEC AWI 29147" and the "Information Security Early Warning Partnership Guidelines"
(issued by IPA).
1. Obtaining Information about Vulnerabilities
To improve the information security quality of our products, collect public information of product vulnerabilities from external security researchers and coordinating organizations (such as domestic and international CERT [Computer Emergency Response Team]).
Information of our product vulnerabilities is obtained by confirming with the coordinating organization, using the contact form on our website, or through our internal HiNET system.
After confirming receipt of vulnerability information, we will notify the reporter of receipt within 5 business days from the date of receipt.
We only accept product vulnerability reports for undisclosed vulnerabilities in our products.
2. Investigation and countermeasures
Information received about product vulnerabilities is investigated by the product design and development department. If the following three points are confirmed, it is determined as a new vulnerability, and we notify the findings to the reporter as soon as possible after confirmation.
- The issue affecting to the security of product
- Reproducible
- Not publicly disclosed
If a new vulnerability is confirmed, implement countermeasures and prepare information disclosure. If it is confirmed that the vulnerability is not new, agree with the reporter to end investigation. However, vulnerability investigations will not be conducted for EOL (End Of Life) products (*1).
- *1:EOL (End of Life) products are products whose lifecycle has ended, and which are no longer supported by the manufacturer.
3. Publication of security advisories
If a new vulnerability is identified in any of our products, assign a CVE number and publish a security advisory on our website to let customers take appropriate measures as soon as possible, to release the information after coordinating the date with the reporter and other relevant parties.
Furthermore, the vulnerability is reported to JPCERT/CC (Japan Computer Emergency Response Team Coordination Center) and if necessary, to overseas CERTs simultaneously with its public release. In accordance with the Information Security Early Warning Partnership Guidelines, vulnerability information is not disclosed to any third party other than the reporter, coordinating body and the product developer before its public release.
For individuals who have contributed to discovering or to solving vulnerabilities of our products, include an acknowledgment in the relevant security advisory upon their consent. If multiple individuals or organizations report the same vulnerability, we will include an acknowledgment for the first reporter.
