29.12.2014 Views

Information Security Report 2010 - Nec

Information Security Report 2010 - Nec

Information Security Report 2010 - Nec

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

■ Utilizing Results from Organizational and Individual Assessment<br />

The Pdca Cycle Depends on the Day-to-Day Workplace Management Level<br />

Management cycle at individual workplace level maintained between supervisors<br />

and subordinates via a gap analysis of organizational and individual assessment<br />

<strong>Report</strong> to<br />

■ Division Head,<br />

■ Upper<br />

Management,<br />

etc.<br />

Organizational Assessment<br />

Assessment by<br />

Organization’s Manager,<br />

Promotion Manager, etc.<br />

Individual Assessment<br />

Assessment by Supervisor,<br />

Results Confirmed<br />

Confirmation<br />

Guidance<br />

Self-Assessment by<br />

Subordinates<br />

Comparison<br />

Comparison of Results by<br />

Organizational Manager<br />

(Gap analysis)<br />

Feedback for<br />

corrective action<br />

<strong>Information</strong> <strong>Security</strong> Audits<br />

<strong>Information</strong> security audits center on NEC’s Corporate<br />

Auditing Bureau, which conducts ISMS and Privacy<br />

Mark-related audits. The Corporate Auditing Bureau<br />

conducts internal audits of each business division regularly,<br />

based on ISO/IEC 27001 and JIS Q 15001 audit standards.<br />

Efforts to Obtain <strong>Information</strong> <strong>Security</strong> Management System (ISMS) Certification<br />

For those organizations which need to obtain ISMS certification,<br />

the NEC Group provides a system to support<br />

the obtainment and management of the certification.<br />

Specifically, services are centered on standard ISMS<br />

content, and include consultation, audit structure development,<br />

training, and effective assessment methods<br />

(differential assessments, etc.). Standard ISMS content is<br />

designed to completely meet portions required under ISO<br />

specifications. NEC Group Promotional Office added<br />

Group Policy to the content. It is also possible to add<br />

independent components of each organization to the<br />

content. Through support for the obtainment and management<br />

of ISMS certification, NEC has unified Group<br />

policies and is making use of best practices from organizations<br />

that have already obtained certification.<br />

To date, this system has been used by 72 organizations<br />

throughout the NEC Group. The know-how that has been<br />

gained as a result is being provided as solutions (the<br />

NetSociety for ISMS service) to our customers and<br />

suppliers.<br />

■ Support for obtainment of ISMS Certification Using “NetSociety for ISMS”<br />

NEC Group<br />

NetSociety for ISMS<br />

Individual<br />

Assessment<br />

Organization<br />

a<br />

Organization<br />

B<br />

Organization<br />

N<br />

NEC Group<br />

Promotional<br />

Office<br />

Preliminary Survey and<br />

Group Assessment<br />

Assessment by<br />

Certification<br />

Organization<br />

Business Architect<br />

■ Business Planning Support<br />

■ Operational Support, etc.<br />

<strong>Information</strong> <strong>Security</strong><br />

Management Consultant<br />

■ Consulting<br />

■ Training Support<br />

IT Infrastructure<br />

■ Asp Service<br />

■ Operational Service<br />

NEC CORPORATION<br />

<strong>Information</strong> <strong>Security</strong> <strong>Report</strong> <strong>2010</strong> 07

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!