![]()
Ensuring Information Security
- Promoting information security management
- NTT Group-wide initiatives to safeguard customers' personal information
Promoting information security management
As a leader in the information and telecommunications industry, the NTT Group recognizes its responsibility to promote information security management. In addition to implementing the secure management of the personal information of our customers, we also focus on initial prevention, minimization of damage, and prevention of reoccurrence of security incidents such as virus infection and unauthorized access under the leadership of NTT-CERT (see below). The number of NTT Group company sites that acquired Information Security Management System (ISMS) and Privacy Mark certifications also grew considerably in fiscal 2007.NTT COMWARE is focusing on in-house security diagnosis and in fiscal 2007 also carried out a diagnosis of company databases.
In addition to NTT Group internal security measures, NTT Communications has launched an Information Security Guide website to provide its corporate customers with information on IT system security.
ISMS and Privacy Mark certifications
| - The above figures are totals for NTT EAST, NTT WEST, NTT Communications, NTT DATA, NTT COMWARE, and NTT FACILITIES. |
NTT-CERTAs the Computer Security Incident Response Team (CSIRT) for the entire NTT Group, the NTT-CERT team operated by the NTT Information Sharing Platform Laboratories works with security managers and systems administrators to deal with incidents and vulnerabilities in NTT Group network/information systems, also coordinating responses and providing technical support.NTT-CERT started to develop a prototype for a diagnostic security risk management system in 2005, and launched pilot operations at some of NTT Group companies in fiscal 2007. These efforts resulted in a working system that incorporates frontline expertise and addresses frontline needs. The NTT-CERT team plans to expand use of the system groupwide. NTT-CERT has also worked to systemize security guidelines, configuration standards and checklists.
|
| Activities | Company |
|---|---|
| information security management | NTT Communications |
| Thoroughgoing employee education on information security | NTT Communications |
Protecting customers' personal information
The NTT Group has established an NTT Group Information Security Policy that states its position on information security, and is doing its utmost on a groupwide basis to protect the personal information of its customers. Each of the NTT Group companies has established a privacy policy for protecting customers' personal information. As an example of this, NTT EAST and NTT WEST conduct departmental workplace inspections, some of which are carried out by personnel from other departments, to verify the proper protection of customers' personal information. NTT DoCoMo too provided employees with instruction on personal information security using information booklets, training videos and e-learning, and NTT COMWARE conducted employee education activities related to file sharing software.The NTT Group will continue to strengthen its efforts to protect its customers' personal information.
![]()

