Establishment of a reporting system, including the promotion of various agendas for the Privacy Policy Council and Working-level Council, and reporting the results of inspections on safety measures and legal compliance by the Chief Privacy Officer (CPO) to the CEO.
There is a need to establish and implement a self-audit system for personal information to conduct professional internal preliminary investigations and inspections regarding recent hacking and data breach incidents.
Recognizing that existing certification systems such as ISMS-P cannot prevent accidents.
Despite the need to develop audit checklists reflecting diverse services and industry characteristics and to carry out colorful and extensive tasks such as internal personal information files and business flow analysis for partners (over 1,000) and branches (over 100), these tasks are not being implemented. Furthermore, despite the need to defend various blind spots, experts are unable to do so due to a lack of knowledge.
Accidents continue to occur and risks remain because appropriate audits of existing security systems are not being carried out, and those previously considered experts in management systems are not actually experts.
Through this study, we aim to eliminate blind spots and strengthen the inspection of existing security systems (promoting detailed inspections), derive improvement measures, and proceed with reporting.