Information Security
- Basic Approach
- Declaration of Information Security
- Promotion System
- Major Initiatives
- Managing External Vendors and Suppliers
Basic Approach
In recent years, cyber attacks on the Internet have become more sophisticated and malicious on a global scale, and threats such as cyber terrorism using computer viruses, large-scale information leaks, and business email fraud are escalating significantly.
As a corporate group responsible for the vital social infrastructure of air transportation, and to fulfill our societal responsibility, the ANA Group has built an information security management system based on the ANA Group Information Security Management Manual (Information Security Policy), and we are routinely improving information system functions and taking security measures through defense in depth.
This Policy comprehensively covers all information assets in our possession and strictly applies to all directors, executives, and employees, including contract, dispatched, and part-time personnel across the ANA Group, while also establishing information security requirements for third parties such as suppliers.
Along with routinely improving information system functions and implementing security measures through defense in depth, we have structured our information security rules based on the NIST-CSF (National Institute of Standards and Technology Cybersecurity Framework) and the global standard ISO/IEC 27001. We are committed to the continuous improvement of our information security systems, the monitoring of and response to information security threats, maintaining and enhancing the confidentiality, integrity, and availability of our information assets, and ensuring the protection and integrity of our data.
Declaration of Information Security
ANA Holdings Inc. (hereafter "ANAHD") and companies which are linked with ANAHD through ANA Group management rules (hereafter "ANA Group") are fully aware of the importance of protecting information assets, including the personal information of customers. Therefore, ANAHD and ANA Group take the following measures to ensure compliance with relevant regulations and technical standards, handle such information assets accurately, safely, and appropriately according to the risks involved, and prove to be worthy of stakeholders' trust.
- ANA Group strives to ensure the confidentiality, integrity, and availability of the information assets in its possession.
- ANA Group will not disclose any information assets unless there are reasonable requirements to do so (requested by law, etc.).
- ANA Group establishes a special organization that addresses improvement of information security for the purpose of protection of information asset, provides as manual the measures to ensure information security and always makes efforts for maintenance and improvement of information security by means education, evaluation of effectiveness and audit of status of compliance.
- If any ANA Group executive or employee commits any act which impairs the confidentiality, integrity, and availability of any information asset, ANA Group will respond to such cases strictly according to established procedures.
Promotion System
Within the ANA Group, the "Group ESG Management Promotion Committee" serves as the primary committee for deliberating on and driving information security. The ANA Group established the Group ESG Management Promotion Committee in accordance with Group ESG Management Promotion Committee Regulations. This committee, which operates under the guidance of the president and under the chairmanship of the director in charge of Group Risk and Compliance (CEPO: Chief ESG Promotion Officer), consists of ANA HOLDINGS INC. and group company directors, executive officers, and the full-time Audit & Supervisory Board members of ANA HOLDINGS INC. The committee discusses core policies and measures related to information security. In addition, important issues directly related to management are submitted to the Group Corporate Strategy Committee and reported to the Board of Directors and the Audit & Supervisory Board, thereby routinely monitoring the implementation, progress, and strategic direction of information security measures.
■ Chief ESG Promotion Officer (CEPO) / Executive Responsibility:
As the ANAHD Director in charge of driving risk management and compliance across the entire ANA Group, the CEPO holds executive-level responsibility for the oversight of the ANA Group's information security matters, fulfilling the strategic leadership role equivalent to a Chief Information Security Officer (CISO).
■ Group Chief Information Officer (Group CIO) :
Served by the Executive Officer in charge of the ANAHD Group IT Department, the Group CIO collaborates closely with the CEPO to provide advanced technical counsel. Furthermore, the Group CIO compiles a "Digital Governance Report" on a quarterly basis and presents it directly to the regular meetings of the ANA Board of Directors (attended by ANA Directors and Executive Officers, including certain Directors who concurrently serve as Directors of ANAHD), thereby ensuring stringent executive-led governance and oversight directly linked to the Board of Directors of ANAHD.
■ Affiliate Promotion Framework:
Each group company designates an "ESG Promotion Officer (EPO)" as the head of information security, supported by an "ESG Promotion Leader (EPL)" driving frontline execution in the workplace. They cooperate seamlessly to enforce security compliance and proactively mitigate risk events.
■ ANA Group CSIRT (Cyber Security Incident Response Team) :
Operating under the technical oversight of the Group CIO for routine and initial response levels, and scaling under the executive leadership of the CEPO when transitioning to a crisis management posture, the ANA Group CSIRT functions as a specialized body that drives preventive security actions, aggregates cyber threat intelligence, leads rapid recovery operations during security events, and formulates necessary strategies to fortify information security infrastructure.
■ ANA Group Information Security Desk:
Serving as the centralized consultation and reporting portal for all information security matters, this desk conducts routine security self-assessments, executes employee awareness initiatives, and provides daily technical support.


Incident Response Flow
In the event that an information security incident occurs—such as a data breach, cyber attack, or system failure—or when a situation with the "potential risk" of such an incident (such as vulnerabilities or suspicious activities) is detected or discovered, the affected department will promptly report and coordinate directly with the constituent departments of the "ANA Group CSIRT" based on an established escalation process for reporting incidents, vulnerabilities, and suspicious activities. We have established a robust framework to ensure this immediate response.
The ANA Group CSIRT evaluates the severity tier of the reported event and directs containment, eradication, and rapid recovery operations to minimize business impact. In the event that an incident is classified as a critical crisis affecting business continuity or data privacy, a centralized crisis response task force is mobilized immediately under the 'Crisis Management Manual'. Led by the CEPO and executive leadership, this task force manages containment in close coordination with external regulatory bodies and law enforcement, ensuring transparent and prompt public disclosure to stakeholders. All root-cause analyses and lessons learned are formally documented and integrated into our continuous improvement loop to fortify our preventive posture against reoccurrences.
![[Discovery/Notification] After recognizing the occurrence of an incident, the department in charge of the incident conducts fact-finding to understand the situation. The department then organizes the information, assesses the severity of the incident, and reports to the Group CSIRT. The Group CSIRT reports to the Chief ESG Promotion Officer and the Group IT officer. The Chief ESG Promotion Officer assesses corporate risks, while the Group IT officer assesses IT risks. [Triage] Upon receiving the report, the Group CSIRT considers triage support, coordination with external parties, and the necessity of external disclosure based on the received report. [Incident Response] The department in charge of the incident conducts an analysis of the incident, identifies the root cause and scope of impact, and establishes a response plan. The Group CSIRT confirms the effectiveness of the response plan and provides support such as revising the plan if necessary. The Chief ESG Promotion Officer and the Group IT officer collaborate closely to make decisions on response plan implementation, external disclosure, and provide instructions to the Group CSIRT. [Improvement/Prevention] Group CIRT and the department in charge of the incident will organize the remaining issues and manage medium- to long-term issues.](/group/en/csr/risk_management/security/image/image_02_2407.png)
Major Initiatives
Cybersecurity Measures and Supply Chain Risk Management
ANA is designated as a critical social infrastructure provider under national laws and regulations in Japan. In strict accordance with guidelines enforced by relevant ministries, we have implemented a robust, multi-layered defense architecture monitored continuously 24 hours a day, 365 days a year. As cyberattacks become increasingly advanced and sophisticated, the proactive utilization of cyber threat intelligence (early warning data) serves as our most critical preventive control, especially in staying highly alert to emerging threats such as the malicious use of high-performance AI. We actively leverage intelligence from the Aviation-ISAC (Information Sharing and Analysis Center), the Transport-ISAC, geopolitical risk updates, and dark web monitoring to thoroughly fortify our preventive measures. Furthermore, we have comprehensively implemented a Zero-Trust architecture for our defenses, ensuring absolute reliability by continuously verifying three key dimensions: the identity of the operator, the device initiating communication, and the system processing context.
In recent years, cyber risks targeting supply chains have grown increasingly complex, making cyber resilience essential not just for the ANA Group alone, but across our entire operational network. Therefore, we collaborate closely with relevant ministries and industry associations, such as Keidanren (Japan Business Federation), to take a leading role in raising security awareness and elevating security standards across the entire industry.
Concurrently, within the ANA Group companies that form our most immediate supply chain, the absolute visualization of information and IT assets is managed as our highest priority. By implementing centralized Attack Surface Management (ASM) to monitor external vulnerability vectors across each group company, we apply rigorous priority filtering (severity triage) to discovered anomalies and vulnerabilities. To ensure that every affiliate can execute effective countermeasures in a timely manner, we maintain direct lines of communication and advisory channels through a seamless process of reporting, notification, and consultation. Concurrently, we reinforce group-wide IT governance through the "ANA Group IT Karte"—a proprietary management document uniquely designed to track and centrally manage each company's IT infrastructure baseline, including operating system versions, security audit status, and software license expirations.
Coordinated by the "ANA Group CSIRT," which exercises oversight over the entire group ecosystem, real-time information sharing with key stakeholders, including senior executive management, has been enhanced, highly optimizing the speed of incident triage and mitigation capabilities.
Moving forward, the ANA Group is evolving from our previous approach of "Security for ALL" to a new paradigm: "Security by ALL." Beyond merely acquiring knowledge, we actively promote a strong security culture where every employee views cybersecurity as a personal responsibility and takes proactive initiative in their daily operations. Through regular education and "Plus Security" training that integrates security perspectives into routine operations, we continuously enhance the defensive capabilities of our entire organization. At the same time, securing and developing specialized security talent capable of adapting to the DX and AI era remains an urgent priority. In addition to ongoing strategic mid-career recruitment, we are accelerating the capacity building of oversight leadership to drive our group’s security forward by providing advanced professional training and encouraging active participation in external cybersecurity communities. Regarding regulatory compliance, we are systematically adapting to global privacy laws while working in close alignment with the government and industry organizations like Keidanren to actively drive and promote the development of a highly advanced security infrastructure required by Japan's Economic Security Promotion Act in full compliance with national guidelines.

Implementation of Security Awareness Education and Training
In order to understand the importance of information security, including the protection of personal information, and the threat of cyber attacks, and to ensure that actions are taken to protect information assets, we have established a permanent e-learning system for Group employees and regularly provide them with security awareness training that incorporates the latest threat examples. Completion of this information security training program is mandatory for all active personnel across the group.
In the IT sector and specialized security teams, CSIRT training is conducted monthly as training in preparation for security incidents, while cyber-range simulation and tabletop training for management and relevant departments is conducted at least once a year, verifying our organizational response and crisis decision-making under realistic incident conditions.
Information Security Risk Assessment, Self-Assessments, and Audits
To rigorously validate our security posture across multiple dimensions, the ANA Group deploys a triple-layered verification approach:
・Annual Internal Self-Assessments: We have established an annual self-assessment system to review compliance with regulations, striving to enhance information security across all organizations.
・Independent Internal Audits: The 'ANAHD Group Internal Audit Department', acting as an independent audit body, collaborates with the Group General Administration Department to perform structured internal audits of IT infrastructure and information security management systems across group companies and business units, reporting findings directly to executive management to drive corrective actions.
・Technical Risk Assessments and External Verifications: The ANA Group regularly conducts information security vulnerability assessments and penetration tests, performing these quarterly for key systems to mitigate risks. Moreover, in certain business areas, we obtain PCI DSS compliance certification and ISO27001 certification through external audits.
Protection of Personal Information
Managing External Vendors and Third-Party Suppliers
By establishing information security requirements for third parties (e.g. suppliers), the ANA Group maintains stringent information security and personal data protection standards across our operational network. To achieve this, the ANA Group Information Security Management Rules define strict selection criteria for contractors and required clauses for contracts, along with ongoing oversight. Beyond contractual safeguards, we operate a dedicated vendor management function that conducts periodic security performance reviews, continuous monitoring, and remediation support, ensuring comprehensive supply chain risk management.