Security Supporting Business Continuity
- TOP
- Our Strengths
- Security Supporting Business Continuity
Robust Infrastructure and Security as a Platform Company Supporting Economic Activity
As many commercial transactions move to the digital realm, we believe that the stable, continuous operation of our platform is directly linked to the sustainability of economic activity. In the face of various risks—such as increasingly sophisticated cyberattacks and large-scale natural disasters—we maintain a robust security framework with our top priority being "never stopping our clients' business" (maintaining availability). Furthermore, we will continue to invest in security and strengthen our countermeasures to keep pace with evolving external threats and new technological trends.
1.Disaster and System Failure Countermeasures
As an infrastructure supporting commercial transactions for over one million companies, we have built a multi-layered backup environment to ensure service continuity, even in the event of system failures or large-scale disasters. In addition to our primary operating environment, we maintain a robust system configuration that combines a "Standby Environment," a "DR (Disaster Recovery) Site," and an independent "Emergency Environment."
System Configuration
For our BtoB Platform services, we maintain a robust system architecture designed for system failures and disasters.In addition to our primary operating environment, we have established a "Standby Environment" and a "DR Site," both of which synchronize data in real time. Therefore, even if a failure occurs in the primary environment, users can continue using our services by switching over to these backup environments.
Furthermore, for BtoB Platform Ordering, we have an independent "Emergency Environment" dedicated exclusively to failure mitigation, ensuring that ordering and order-receiving operations can continue even if all the above environments become inoperable. We are currently considering implementing a similar environment for BtoB Platform Invoicing as well. Additionally, we conduct regular system failure drills to prepare for unexpected events.
2.External and Internal Access Controls (Protection of Systems and Data)
To securely protect commercial transaction data across a vast number of companies, we have implemented an integrated security framework that combines "multi-layered defense" to prevent external cyberattacks with "strict access management" to mitigate internal risks.
As an infrastructure company, we comprehensively and rigorously enforce essential security measures, including detecting and blocking unauthorized intrusion via "multi-layered network security" optimized for cloud environments, encrypting transmitted and stored data, conducting regular vulnerability assessments by external entities, and restricting access rights to production environments.
3.Incident Response Framework and Drills Centered on the CSIRT
We have established a response framework centered on our CSIRT (Computer Security Incident Response Team) to ensure prompt and effective responses in the event of a security incident. In an emergency, under this structure, we execute a comprehensive process—from collaboration and information sharing with relevant departments to root-cause analysis and recurrence prevention, striving to ensure business continuity.
In addition to preventive measures based on past incidents, we participate as a member in annual exercises hosted by the Nippon CSIRT Association (NCA). By conducting incident response drills using scenarios that reflect the latest threats, we continually work to enhance our practical response capabilities for emergencies.
4.External Certifications and Memberships
We undergo rigorous audits by independent third-party expert organizations and have obtained numerous major security certifications to ensure that our clients can use our services with peace of mind. Furthermore, by joining and collaborating with major security organizations, we quickly capture the latest cyber threat information to continuously update our defense architecture.
Acquisition of Security Standards and Certifications
-
Government-approved cloud security standard "ISMAP"※1
-
International security standards "ISMS (ISO 27001)" and "ISMS Cloud Security (ISO 27017)"※2
-
Public certification "ASP/SaaS Safety and Reliability Information Disclosure Certification System" that meets government safety standards
※1 ISMAP registration applies to 4 services: BtoB Platform TRADE, Invoices, Contracts, and BP Workflow.
※2 The scope of ISMS certification covers 15 services: BtoB Platform Ordering, Ordering Lite, Database, Matching, TRADE, Invoices, Industry Channels, Estimates, Contracts, Ordering for Manufacturing, BtoB eSmart, V-Manage, BP Workflow, Early Payment of Electronic Invoices, and Credit Settlement.
Implementation of Internal Control Evaluations
Updating and sharing knowledge through memberships in industry organizations
-
Membership in the "Nippon CSIRT Association (NCA)," a collaborative community linking incident response organizations
-
Membership in the "Japan Cloud Industry Association (ASPIC)," an organization specializing in security and cloud services