Fujikin Incorporated and its group companies (also known as Fujikin Carp Group, hereinafter Fujikin) established PSIRT (Product Security Incident Response Team)as an internal incident response framework related to information security quality of our products, and are actively driving our product security initiatives.
Fujikin PSIRT is responsible for collecting a wide range of information related to vulnerabilities of our products provided to customers and, in corporation with our product design / manufacturing / procurement departments, promptly taking action against discovered vulnerabilities. Vulnerability-related information and security measures will be publicly disclosed to customers.
1.Vulnerability Disclosure Policy
In order to ensure product security and protect our customers against cyber attacks, Fujikin discloses vulnerability information related to our products with following steps.
- Collecting vulnerability information
Fujikin is widely collecting vulnerability information from internal / external security researchers and coordinating bodies (including domestic / international Computer Emergency Response Team “CERT”) to improve the information security quality of our products. In the event of finding one of our products having a potential vulnerability, please contact one of these coordinating bodies or contact us directly using report form link below, which is protected with encryption protocol.
Fujikin Carp Group Product Security Vulnerability Report Form
Upon receiving the vulnerability information via the report form, we will respond back within 5 business days. Please note that our response will be delayed during Japan public holidays and Fujikin company holidays.
After the reporter contacts us via the report form, we will communicate with the reporter by e-mail. If the e-mail and/or attachments contain sensitive information about undisclosed vulnerabilities, please encrypt the e-mail and/or attachments with PGP to prevent unintentional disclosure. We will inform reporters individually how to use PGP encryption.
- Investigation and security measures
Fujikin product design and development department will investigate the vulnerability information the reporter provided (true product security identified, reproducible, and undisclosed). Upon determining that it is a new vulnerability, we will notify the reporter of the investigation results immediately. Security measures will be implemented and vulnerability disclosure preparation will begin.
- Publication of Security Advisory
Upon security measures ready, we will prepare a security advisory to publish the vulnerability. We will coordinate the advisory publication date with the reporter and other stakeholders as soon as the advisory is ready for publication, and publish it on our website. Acknowledgements to the contributors on discovery or resolution of the vulnerability in our products will be posted in the security advisory after agreement with those contributors.
2.Vulnerability Information
- No information as of this moment.