Initiatives for Product Security

Product Security Policy

We regard enabling our customers to use our products safely and secure of mind as our highest responsibility, and we are continuously working to ensure robust security.

This page presents our basic policy on product security and our Vulnerability Disclosure Policy, which governs the proper and timely disclosure of, and response to, vulnerabilities in our products.

Through these initiatives, we strive to earn the trust of our customers and society, and to provide products that can be used with confidence.

Declaration

We comply with all applicable laws and regulations in the regions where our products are sold. To ensure that customers can use our products and systems safely and secure of mind, we have established a basic policy and will continuously strive to ensure robust product security.

Basic Policy

1. Compliance with domestic and international laws and regulations on product safety and product security

We comply with laws and regulations related to product security. With regard to personal information, we take appropriate protective measures based on our internal policies.

2. Response to product cybersecurity incidents and vulnerabilities

If a security incident occurs in our products or services, or if a critical vulnerability is identified, we promptly report it to relevant authorities in accordance with applicable laws, regulations, and internal rules. At the same time, we verify the facts and investigate the root cause, strive to prevent the occurrence and escalation of damage, and take swift and appropriate action for customers and other affected parties. 

3. Collection and handling of vulnerability information related to products and services

We continuously collect information on vulnerabilities in our products and services from both internal and external sources, including customers. When a vulnerability is identified, we promptly implement countermeasures. We also provide customers with security advisory on measures to reduce security risks arising from discovered vulnerabilities.

4. Disclosure of security incident and vulnerability information related to products and services

Where necessary, we coordinate with relevant government agencies and regulatory authorities regarding security incident and vulnerability information affecting our products and services, and take appropriate steps to enable disclosure.

5. Prevention of security incidents at the product and service design and development stage

We establish internal security design and development standards that appropriately incorporate applicable industry standards, guidelines, and verification methods related to product security. Based on these standards, we carry out product development, implement measures to reduce security risks, and endeavor to remediate vulnerabilities before products are shipped. We also thoroughly analyze past security incidents and incorporate preventive and damage-mitigation measures into these internal standards to help prevent future incidents. 

6. Awareness-raising, cautions, and warnings to ensure safe use by customers

To ensure the safe use of our products and services, we include instructions on secure usage methods that help reduce security risks in user manuals and other documentation provided to customers. In addition, we proactively issue security advisories and cautions related to our products and services through our corporate website and other channels.

7. Reduction of security risks in the supply chain

To help ensure that product operations in our customers’ environments using our products and services are not interrupted, we work to reduce security risks across the supply chain, including customers and suppliers related to our business. Initiatives include providing machine-readable Software Bills of Materials (SBOMs) for components and libraries developed by our company, and collaborating closely with supply chain partners.

8. Education and training related to product security

To enhance knowledge and technical capabilities regarding the security of our products and services, and to improvement security awareness, we continuously provide security education and awareness-raising activities for our officers and employees.

  • 国内外の製品安全・製品セキュリティに関する法令の遵守
    当社は、製品セキュリティに関する法令・規制を遵守し、個人情報については当社の方針に基づき、適切な保護措置を講じます。
  • 製品サイバーセキュリティ上の事故・脆弱性への対応
    当社は、製品及びサービスにおいてセキュリティ上のインシデントが発生した場合、または重大な脆弱性を確認した場合には、関係法令や社内規程に基づき、速やかに関係機関へ報告します。合わせて、事実関係の確認と原因の究明を行い、被害の発生および拡大の防止に努め、お客さま等へ迅速かつ適切な対応を実施します。
  • 製品及びサービスに関連する脆弱性情報の収集・対応
    当社製品及びサービスの脆弱性に関する情報について、お客様を含めた社内外から継続的に収集し、発見された脆弱性は速やかに対策を講じます。また、お客様に対して発見された脆弱性に対するセキュリティリスク低減策及び適切な情報提供を行います。
  • 製品及びサービスのセキュリティインシデント情報、脆弱性情報の開示
    当社製品及びサービスにおけるセキュリティインシデント情報及び脆弱性情報は、必要に応じて政府関係機関、管理当局と連携し、開示に向けた対応を適宜実施します。
  • 製品及びサービスの設計開発段階でのセキュリティインシデントの未然防止
    製品セキュリティに関連する業界標準の規格やガイドラインの要求及び検証方法を適宜適切に取り入れた対策標準を策定し、これに基づいた製品開発を行い、セキュリティリスクの低減策を実装すると共に、製品出荷前に脆弱性の解消に努めます。また、過去に発生したセキュリティインシデントを徹底的に分析し、被害の発生・拡大の防止措置を対策標準へ取り込み、事故の未然防止に努めます。
  • お客様の安全を確保する使い方の啓発や注意喚起、警告表示
    当社製品及びサービスをお客様に安全にご使用いただくため、お客様に提供する取扱説明書にセキュリティリスクを低減するための安全な使用方法を記載するなどの取り組みを行います。また、当社製品及びサービスに関わるセキュリティ上の注意喚起は、積極的に当社ウェブサイト等を通じて行います。
  • サプライチェーン上のセキュリティリスクの低減
    当社製品・サービスを利用したお客様環境における製品製造が止まることがないよう、当社が開発するコンポーネント・ライブラリにおける機械可読形式でのソフトウェア部品表:SBOM(Software Bill of Materials)の提供を行う等、当社が関連するお客様や仕入れ先様も含めたサプライチェーンパートナーとの協調により、セキュリティリスクの低減に努めます。
  • 製品セキュリティに関わる教育訓練の実施
    当社は、製品・サービスのセキュリティに関する知識と技術の向上を図り、安全意識を高めるため、役員および従業員に対して、セキュリティ教育や啓発活動を継続的に実施します。

Vulnerability Disclosure Policy

1. Our initiatives

We have established a Product Security Incident Response Team (PSIRT) to ensure that customers can use our products and services safely. Our PSIRT responds to vulnerabilities related to our products and services.

In order to provide appropriate mitigation measures for vulnerabilities and help reduce security risks for our customers, we disclose vulnerability-related information in accordance with ISO/IEC 29147 and the “Information Security Early Warning Partnership Guideline” (Japan).

2. Scope of accepted vulnerability reports

We accept reports of vulnerabilities not only for current products, but also for products that are no longer in production. Please note, however, that for products that are no longer in production, technical or support-related constraints may prevent us from conducting investigations or implementing countermeasures.

3. Verification of reported information and communication with reporters

Vulnerability information regarding our products and services that is reported to us is promptly reviewed and investigated by the responsible department in cooperation with the design and development departments.

4. Investigation and countermeasures

In the course of investigation and remediation, we may ask the reporter to provide additional information or clarification, such as technical details and procedures to reproduce the issue.

5. Response process after receipt of a report

For vulnerability information regarding our products and services reported to us, we work with coordination organizations such as the Innovation Platform Agency, Japan (IPA) and JPCERT Coordination Center (JPCERT/CC), as necessary, to implement appropriate measures.

Where an impact is confirmed, we take countermeasures such as providing patches, and/or guidance on configuration changes or workarounds.

Where necessary, we publish vulnerability information and remediation measures via our corporate website and platforms such as JVN (Japan Vulnerability Notes). If a particular customer is expected to be significantly affected, we may also contact them individually through our sales channels.

We provide the reporter, to the extent reasonably possible, with periodic updates on the status of our response until the measures are completed. However, for security or other reasons, we may not be able to disclose all details of our investigation.

6. Publication of security advisories

When a new vulnerability affecting our products is identified, we publish a security advisory on our corporate website, including details of the vulnerability and countermeasure information, once preparations for mitigation and public disclosure have been completed.

The publication date will be coordinated with the reporter and relevant parties, and with coordination organizations where necessary, and a CVE ID will be assigned before publication.

7. Response and disclosure timeline

When we receive a vulnerability report, we will, in principle, acknowledge receipt within five business days after confirming the notification.

Please note that notifications received on Saturdays, Sundays, national holidays, or during extended holiday periods such as summer vacation or the New Year holidays will be handled from the next business day onward, and our response may therefore be delayed.

8. Acknowledgments

If a person who has contributed to the discovery or resolution of a vulnerability in our products or services agrees, we will publish an acknowledgment of their contribution in the relevant advisory or on our corporate website.

If we receive multiple reports regarding the same vulnerability, we will, in principle, acknowledge the first valid report.

9. Personal information and legal considerations

Personal information provided to us is appropriately protected in accordance with our internal rules.

For details, please refer to our Privacy Policy.

10. Protection of communications containing report details

Vulnerability reports are accepted via the “Report Form.” Communication through this form is protected by SSL/TLS encryption.

  • 当社の取り組み
    当社(日本無線株式会社、以下「当社」)は、お客様に当社製品・サービスを安全にご利用いただくため、PSIRT(Product Security Incident Response Team)を設置し、当社製品・サービスに関わる脆弱性への対応を行っています。脆弱性の対策方法を適切に提供し、お客様のセキュリティリスク低減に貢献するため、「ISO/IEC 29147」および「情報セキュリティ早期警戒パートナーシップガイドライン」に則り、脆弱性関連情報を公開いたします。
  • 脆弱性報告の受付対象
    当社は、現行製品に加え、生産完了品についても脆弱性情報のご報告を受け付けております。なお、EOL(End of Life)製品については、技術的・サポート体制上の制約により、脆弱性の調査や対策ができない場合がありますので、あらかじめご了承ください。
  • 報告内容の確認および報告者との連絡
    当社へご報告いただいた当社製品・サービスの脆弱性情報は、担当部門および設計・開発部門にて速やかに確認・調査します。
  • 調査および対策
    調査および対策の実施にあたっては、技術的な詳細や再現手順などについて、ご報告者様へ追加の確認や情報提供をお願いする場合があります。
  • 報告受領後の対応プロセス
    当社へご報告いただいた当社製品・サービスの脆弱性情報については、必要に応じて独立行政法人情報処理推進機構(IPA)や一般社団法人JPCERTコーディネーションセンター(JPCERT/CC)等の調整機関と連携し、適切な対応を実施します。
    影響がある場合には、修正プログラムの提供や設定変更・回避策のご案内等の対策を講じます。
    必要に応じて、当社ウェブサイトや JVN(Japan Vulnerability Notes)等を通じて脆弱性情報および対処方法を公表し、特定のお客様に重大な影響が見込まれる場合には、営業窓口等を通じて個別にご連絡します。
    ご報告者様には、措置対応が完了するまでの状況について、可能な範囲で適宜ご連絡します。ただし、セキュリティ上の理由等により、すべての調査内容を詳細に開示できない場合があります。
  • セキュリティアドバイザリの公開
    当社製品に新たな脆弱性が確認された場合、お客様が適切な対策を講じられるよう、対策および情報公開の準備が整い次第、ご報告者様など関係者および必要に応じて調整機関と公開日を調整し、CVE番号を採番のうえ、当該脆弱性の内容と対策情報をセキュリティアドバイザリとして当社ウェブサイトで公開いたします。
  • 回答・開示タイムライン
    当社へ脆弱性情報をご報告いただいた場合、受信確認後、原則5営業日以内に受領した旨をご連絡します。 土曜・日曜・祝日および夏季休暇・年末年始休暇などの長期休暇中にいただいたご連絡については、翌営業日以降の対応となるため、返信が遅れる場合があります。
  • 謝辞の掲載
    当社製品・サービスの脆弱性の発見または解決にご協力いただいた方について、謝辞の掲載に同意をいただいた場合、当該脆弱性に関するアドバイザリや当社ウェブサイト上に謝辞を掲載します。同一の脆弱性について複数のご報告をいただいた場合は、原則として最初の有効なご報告者様を謝辞掲載の対象といたします。
  • 個人情報および法的考慮事項
    ご提供いただいた個人情報は、当社の定める規則に従って適切に保護いたします。
    詳細は、当社のプライバシーポリシーをご参照ください。
  • 報告内容の通信保護
    脆弱性情報のご報告については、「報告フォーム」により受け付けており、通信は SSL/TLS により暗号化されています。

Vulnerability Reporting Contact

To report a vulnerability, please contact us using the form below.
Contact Us

Company Information List