TOP> >

Sustainability >

Governance >

Product Security

Product Security

Product Security Policy / Basic Approach

Product Security Basic Policy

Ensuring the security quality of the products and services we provide is one of our top priorities. To earn and maintain the trust of our customers, partners, and society, we implement appropriate risk-based security measures throughout the entire product lifecycle (planning, design, development, manufacturing, operation, maintenance, support, and disposal) and continuously improve our management framework to achieve this.

1. Product Security Management Structure

We have established a Product Security Incident Response Team (PSIRT) to ensure prompt and consistent responses to product-related vulnerabilities and security incidents. In collaboration with relevant departments, including Development, Quality Assurance, Procurement, Legal, and Public Relations, the PSIRT performs the following:

● Managing the end-to-end process of receiving, verifying, evaluating, remediating, and disclosing vulnerability information

● Providing timely and appropriate updates to potentially affected customers and stakeholders

● Continuously implementing recurrence prevention measures, process improvements, and training programs

 

2. Compliance with Laws, Regulations, and Contractual Requirements

We comply with the laws, regulations, standards, and contractual obligations of each country and region with respect to product security, including those with customers, suppliers, and other business partners.

3. Product Security Training

We continuously provide role-specific training to relevant personnel in Development, Operations, Support, Sales, Public Relations, and Legal, to ensure they possess the necessary knowledge and skills for product security.

4. Implementation of Countermeasures and Incident Response

We implement proactive product security measures to prevent security incidents. In the event of a serious security incident or the discovery of a critical vulnerability, we will promptly investigate the cause, contain the impact, conduct a post-incident evaluation, and implement measures to prevent recurrence.

5. Continuous Improvement

We periodically review our product security processes to ensure they are properly executed and maintained, driving continuous improvement across our security framework.

Product Security Policy Framework

We have established this “Product Security Basic Policy” to drive a consistent approach to cybersecurity risks across our products and services. To put this policy into practice, we have enacted our “Product Security Regulations” as core compliance rules. Guided by these regulations, we develop specific operational workflows, such as our “Product Security Procedures” to steadily strengthen our product security foundation.

製品セキュリティポリシー

Product Security Management Framework

Under the leadership of the Chief Cybersecurity Officer, we operate a structured product security management framework. We have established the Muratec-SIRT to oversee company-wide cybersecurity measures, including product security. For product security-related issues, our PSIRT collaborates with relevant departments, such as Development, Quality Assurance, Procurement, Legal, and Public Relations, to address security risks and vulnerabilities throughout the entire product lifecycle, from planning and design to development, manufacturing, operation, maintenance, support, and disposal. We properly receive product security information from internal and external sources, conduct impact assessments and corrective actions, and provide appropriate updates, while taking into account the impact on customers and society. Furthermore, we continuously improve our product security management framework and initiatives to adapt to technological developments and emerging threats.

Product Security Initiatives

As digital technology increasingly underpins society and industry, we regard product safety and reliability as important elements of our corporate social responsibility. To enable customers and society to use our products and services securely and with confidence, we are committed to establishing product security frameworks and driving continuous improvement. We advance product security through the following three core initiatives.

 

Initiatives for a Secure Development Lifecycle

We have established a secure development lifecycle that incorporates security considerations across the entire product lifecycle from planning and design to development, manufacturing, operation, maintenance, support, and disposal. Guided by our fundamental principle of “Security by Design”, we embed security from the initial design stage to enhance product safety and reliability. Furthermore, we maintain comprehensive product security regulations and procedures and have updated our QMS regulations to balance quality assurance with robust security measures. By promoting active participation across all relevant functions, not just our Development and Quality Assurance Departments, we are building a company-wide framework that supports secure development.

Appropriate Response to Vulnerability Information

Addressing vulnerabilities discovered after product release is critical to maintaining product security and fulfilling our social responsibility. We have established a comprehensive vulnerability handling process that spans data collection, impact assessment, countermeasure development, and reporting. Specifically, we have systematized our workflow to cover gathering vulnerability information, identifying affected products, evaluating product impacts, and determining and executing response policies. We also maintain clear reporting workflows for vulnerabilities and incidents to ensure prompt and appropriate responses. We have also implemented a company-wide Software Bill of Materials (SBOM) system to visualize software components.
By defining clear objectives for SBOM usage and structuring the necessary management and operation workflows, we accelerate our vulnerability responses and enhance risk assessment capabilities.

Promoting Product Security Training

Ensuring product security requires more than just policies and systems; it demands knowledgeable and aware personnel. We view the development of product security specialists as a key initiative and continuously drive training and awareness programs. Specifically, we have defined the ideal roles required for product security and clarified the skills needed at each stage of our secure development lifecycle. Based on these criteria, we have established a product security skills map and structured training programs to enhance expertise across development teams and related departments. Through these personnel development initiatives, we aim to raise security awareness and response capabilities across the entire organization, fostering a corporate culture where product security is autonomously maintained and improved.

 

Vulnerability Disclosure Policy

Introduction

To ensure our customers can use our products safely, we maintain a dedicated framework to appropriately address potential product vulnerabilities. This Vulnerability Disclosure Policy (hereinafter referred to as the “Policy”) outlines our guidelines for responding to vulnerabilities promptly and appropriately, continuously improving product safety, and ensuring transparent information disclosure.

How to Report Vulnerabilities

Contact Us
Please use the inquiries page below to report security issues or vulnerability information related to our products.

 

To help us investigate and respond appropriately, please include the following information in your report:
 Vulnerability Details:

 ● Impact or observable behavior caused by the vulnerability

 ● Product name and model

 ● Affected product and software/firmware version

 ● Steps to reproduce the issue, operating environment, and hardware configuration

 ● Potential attack scenarios

 ● Any other relevant supporting information

 

After confirming receipt of vulnerability information through the inquiry form, we will acknowledge receipt within approximately five business days.
Please note that responses may be delayed during weekends, public holidays, year-end and New Year holidays, or other company closures.
Any personal information provided will be handled securely in accordance with our Privacy Policy (Personal Information Protection Policy).
The inquiry form is fully encrypted using SSL/TLS.

 

Response Policy

We will thoroughly review the provided vulnerability information to investigate its scope of impact and severity.
Based on these findings, if corrective action is deemed necessary, we will develop and implement appropriate countermeasures.

Communication with the Reporting Party

We are committed to maintaining open and constructive communication with the reporting party.
We may contact the reporting party to request additional information or clarification if necessary. We will provide updates on the progress of our investigation and response activities, as appropriate.

Disclosure Policy

In consultation and coordination with relevant parties, vulnerability information will be published on our website or other official platforms. Disclosures will be timed and structured to prioritize customer safety and minimize potential impact.

Request to the Reporting Party

To safeguard customers using our products and services, we respectfully ask that you refrain from disclosing vulnerability details to third parties until we have released or otherwise provided official countermeasures or guidance.

Disclaimer

This Policy is subject to change without prior notice.
While we take appropriate action based on all submitted reports, we do not guarantee that every reported vulnerability will be addressed.
We assume no liability for any damages arising from activities conducted under this Policy.