- Loading
Product Security Vulnerability Disclosure Policy
1. Introduction
Hitachi Industrial Equipment Systems Co., Ltd. (hereinafter referred to as "the Company") recognizes the maintenance and improvement of the security quality of its products as an important issue. In order to appropriately receive information regarding security vulnerabilities or suspected vulnerabilities related to our products and to conduct necessary investigations and responses, we have established this policy.
2. Security Vulnerability Disclosure Policy
This policy outlines our basic response policy regarding security vulnerabilities or suspected vulnerabilities in our products.
Furthermore, this policy presents our basic approach from the receipt of vulnerability information to investigation, response, and disclosure as necessary, as part of our compliance with security-related laws and regulations. It does not represent or imply indicate the acquisition or planned acquisition of any specific laws, regulations, certifications, or conformity labels.
(1) Scope of Application
This policy applies to security vulnerabilities or suspected vulnerabilities related to products provided by our company.
For our websites, information systems, services, or other subjects, if there are separately designated contact points or instructions, please follow those instructions to contact us. If you are unsure about the scope of application, please contact us at the "Contact Information for Reporting and Inquiries" below.
(2) Response to Security Vulnerabilities
Regarding security vulnerabilities or suspected vulnerabilities in our products, based on our own detection*1 or reported information, we will investigate, within the necessary scope, whether our products are affected by the vulnerability, the extent of the impact, and whether a response is required. If, as a result of the investigation, it is determined that our products are affected, we will consider and implement countermeasures such as patches, workarounds, mitigation measures, or other actions as necessary, taking into account the nature of the vulnerability, the degree of impact, product usage status, coordination with relevant parties, and other circumstances.
- 1 For our policy on our own detection, please refer to "1.2 Acquisition of Vulnerability Information" in the Hitachi Group Product Vulnerability Disclosure Process (HIRT-PUB10008).
The status of our response to security vulnerabilities in our products is managed by the relevant department within our company. Additionally, when necessary, we may coordinate with relevant parties regarding the publication date and content, and disclose security information through our website or other means. When publishing security information, we may include the following items as needed:
- Details of the vulnerability
- Affected products
- Impacted versions
- Potential impact
- Countermeasures
- Workarounds or mitigation measures
- Update history
However, the timing, content, and method of disclosing information about vulnerabilities will be determined by our company, taking into account user protection, prevention of misuse risks, coordination with stakeholders, legal and regulatory requirements, and other circumstances, and considering the principle of coordinated disclosure*2 as necessary.
- 2 The principle of coordinated disclosure refers to the concept of releasing information at a coordinated time among stakeholders when a vulnerability affects multiple parties or products. For details, please refer to "1.4 Information Disclosure" in the Hitachi Group's Product Vulnerability Information Disclosure Process (HIRT-PUB10008).
3. Response to Reporters and Requests
We appreciate your good faith reports of vulnerability information.
Regarding the information you provide to the contact below, we may request additional information as necessary.
We kindly ask for your cooperation. When making a report, please comply with the following:
- Do not access our or third-party systems, networks, products, or services without authorization, place excessive load, conduct verification that results in service outages, alter or delete data, or engage in any other unauthorized or harmful acts.
- Do not obtain, view, store, disclose, or use personal information, confidential information, trade secrets, or any other information belonging to third parties during vulnerability verification.
-
Do not disclose or publish information regarding vulnerabilities to third parties before our investigation, countermeasures, or official announcement.
-
Do not exploit vulnerabilities or engage in any acts that encourage exploitation by third parties.
We do not plan to provide any rewards, gratuities, compensation, or other monetary benefits to the reporter.
4. Policy for Protecting Provided Personal Information
Any personal information included in the content you provide, such as your name, contact information, workplace, and other personal details, will be handled appropriately in accordance with privacy policy. For details about privacy policy, please refer to "About Personal Information Protection (Privacy Policy)".
The personal information you provide will be used for the following purposes:
- Confirmation, receipt, and management of the reported content
- Investigation, confirmation, and response regarding vulnerabilities or suspected vulnerabilities
- Additional confirmation, notification of results, and other necessary communications with the reporter
- Sharing with relevant departments within our company, affiliated companies, contractors, external experts, and other necessary parties
- Reporting or responding to inquiries to authorities, regulatory bodies, institutions, or related organizations in accordance with laws, regulations, and systems
- Enhancement of security quality and prevention of recurrence
5. Contact Information for Reporting and Inquiries
For inquiries regarding the security of products and services, please contact us via the form or email below.
Please note that this contact point is for receiving vulnerability information related to our products. It does not substitute for reporting to Hitachi, Ltd.'s HIRT (Hitachi Incident Response Team) or other contact points within the Hitachi Group.
• If contacting us via the form
Please write "Inquiry regarding the security of products and services" at the beginning of the inquiry field.
• If contacting us via email
Please include "Inquiry regarding the security of products and services" in the subject line and provide the following information:
Email address: QAcenter-box@hitachi-ies.co.jp
When contacting us by email, please provide the following information:
- Include "Inquiry regarding the security of products and services" in the subject line
- Reporter information (name, contact email address, employer information [company name, phone number, etc.])
- Name of the product in which the vulnerability was found
- Details of the vulnerability or suspected vulnerability
- Product model, version, firmware version, and other information to identify the product
- Background of how the vulnerability was discovered
- Potential impact expected from the vulnerability
- Steps to reproduce the vulnerability
- Any other information considered useful for investigation
6. Security Information
Security information related to our products will be posted here.
If a response to a vulnerability becomes necessary, we will provide information on the affected products and countermeasures on this page.