
As computerization and the growth of networks progress in our advanced information society, the threats of illegal/unauthorized access to our computer systems increase, requiring a well-organized, comprehensive management system for information security.
The Chiyoda Group believes that the maintaining confidentiality and integrity of and maximizing the use of its own business and technical information resources entrusted to Chiyoda by its business partners such as clients, licensors and joint venture partners are fundamental to the Company’s reliability since its founding.
Chiyoda has established its Information Security Management System (ISMS) based on the British Standards Institution (BSI) of the United Kingdom for BS7799:1999, since 2001, and has been certified by the world-renowned certification body, the ANAB (The American National Standard Institute (ANSI) – American Society for Quality (ASQ) National accreditation Board) for ISO/IEC 27001:2005, since 2007.
Chiyoda Group companies have also established and implemented ISMS based on ISO/IEC 27001:2005 according to their respective business types. Two companies in Japan (Chiyoda Advanced Solutions Corporation and IT Engineering Limited) and two overseas (L&T-Chiyoda Limited and Chiyoda Philippines Corporation) that handle highly confidential technical information have acquired ISO/IEC 27001:2005 certification.
Recognizing that information security is one of its obligations to society and stakeholders, the Chiyoda Group conducts information security governance based on internal controls, both at an individual company level and as a group.
Governance includes internal audits independent from ISMS operations and outside audits by a third party (an international certification body). In addition to the above two check systems, the Chiyoda Group holds the Group ISMS Liaison Meeting, sharing information of information security risks/events/ incidents, ISMS operation, internal monitoring and other related matters.


The Chiyoda Group has established the Privacy Policy and personal information protection management systems (personal information protection compliance programs) at each Group company to comply with the Personal Information Protection Law enforced in April 2005.
Protection of personal information is promoted effectively together with the implementation of ISMS.

The Chiyoda Group continuously implements, maintains and improves ISMS to enhance its effectiveness in accordance with the Corporate Information Security Policy, as follows.

The Chiyoda Group conducts ISMS training each year to improve ISMS operation. Training consists of e-Learning for all employees, as well as ISMS group lectures including workshops.
The Chiyoda Group has designated every February and September as Information Security Check Months, when several programs are promoted for improvement of information security.
In the Information Security Check Months, examples of incidents that are likely to occur, explanations of information security rules and other items are compiled into “Information Security Checks I-VII” and posted on the Group intranet to train and raise awareness among all Group employees. If any incidents or events have occurred, preventive measures are similarly posted as reminders.
The Chiyoda Group maintains and improves information security with a system in which every department self-audits and checks the operation of information security each year based on an Information Security Self-Assessment Checklist consisting of 25 items.
The following Chiyoda Group companies have acquired ISO/IEC 27001:2005 certification of their ISMS and/or the Privacy Mark as evidence of their promotion of information security and protection of personal information, respectively.
【ISO/IEC 27001/2005】
| ・ Chiyoda Corporation | : certified in 2007 |
| ・ Chiyoda Advanced Solutions Corporation | : certified in 2008 |
| ・ IT Engineering Limited | : certified in 2009 |
| ・ L&T-Chiyoda Limited | : certified in 2005 |
| ・ Chiyoda Philippines Corp. | : certified in 2010 |
【Privacy Mark】
| ・ Arrow Human Resources Co., Ltd. | : acquired in 2005 |
| ・ IT Engineering Co., Ltd. | : acquired in 2007 |
Much of the Chiyoda Group’s work is executed with the use of information technology (IT) tools such as e-mail, the Internet and various applications. Therefore, the IT security used in information security is critically important.
Raising the level of IT infrastructure as well as users and administrators is necessary to improve IT security. For IT infrastructure, concrete measures to fulfill information security system (ISMS) requirements are continuously examined by the IT Infrastructure Committee. Users and administrators are given ongoing training on ISMS rules, which describe the ISMS requirements.


The Foreign Exchange and Foreign Trade Act was established based on international agreements controlling exports of goods and transfer of technology with the aim of maintaining international peace and security.
In order to comply with this law in overseas projects, Chiyoda established the compliance program (CP) regarding export-related laws and regulations and registered it with the Ministry of Economy, Trade and Industry. The CP defines the export control policy of Chiyoda, and detailed procedures, rules and manuals.
Based on the CP, Chiyoda organized the Export Control Committee and Export Control Office to enforce export control management such as inspection, education and internal auditing.
Chiyoda has also prepared an operational manual to inform and educate its employees on the Company’s response to the Export Administration Regulations of the United States, which have gained increasing attention at Japanese companies in recent years as regulations that are applied extraterritorially by US authorities.