Information Security Policy

Tohoku Electric Power Group Information Security Policy

Established in April 2007

To ensure information security, the Tohoku Electric Power Group is committed to the following principles.

1. Compliance

We observe laws on information security as well as this policy and standards established by individual group companies.

2. Information management

We shall establish an information security management system led by management executives in order to secure any information handled in our business activities appropriately according to its importance and risk.

3. Technical measures

To prevent unauthorized access to information, and loss, falsification, leakage or disappearance of information, we shall take appropriate technical and environmental measures and strive to maintain information security.

4. Education and awareness raising

We shall provide employees with education and training on information security to ensure their observance of laws, this policy, and standards. Violation shall be handled appropriately.

5. Management of third-party contractors

When outsourcing work to third-party contractors, we shall make them fully aware of this policy and include a confidentiality clause in the outsourcing contract to ensure their strict information security management.

6. Response to accidents

We shall establish a system to respond to incidents and crimes related to information security so that we can minimize damage and prevent their recurrence.

7. Maintenance and improvement

We shall respond appropriately to changes in laws and social environment to ensure continuous information security management.