Would you like to visit another country's site?

Security Policy Ecount has obtained ISO 27001 certification, the international standard for information security,
and uses a cloud environment based on Amazon Web Services (AWS).

ISO 27001 Certification Obtained

  • ISO 27001 is an international information security standard established by the International Organization for Standardization (ISO)
    that assesses a company’s information security capabilities based on 93 controls.

Ecount obtains and renews security certifications
through the security framework described below.

1. Internal and External Security Audits

  • We conduct annual audits by an external security specialist firm to review our internal security processes.
  • We diagnose system vulnerabilities through penetration testing and address them.
  • Internally, we appoint an information security officer who establishes and manages the plan.

2. Established Security Inspection and Training Programs for Employees

  • We conduct daily and monthly security inspections to verify whether customer information is stored on employee PCs and whether unauthorized programs are installed.
  • All employees sign a security pledge before commencing work and complete annual information security training.
  • We assign different security levels to each employee and restrict information access by unauthorized personnel.
  • When employees are transferred, access rights to information are revoked as part of our personnel security management procedures.
  • We manage antivirus software on employee PCs to prevent information leakage caused by malware.

3. Encryption of Customer Information

  • Data entered by customers into Ecount is transmitted using encrypted communication.
  • Important personal information, such as resident registration numbers, account numbers, and card numbers, is encrypted using algorithms before being stored on the server.

4. Systematic Management of Information Assets and Systems

  • Ecount manages customers' information assets while monitoring system operations in real time.
  • We classify corporate information assets according to their importance and manage the data by applying different security levels.
  • We have a system in place to manage potential risks such as information breaches and service disruptions.
  • When risks to information assets are identified through inspections, we improve our systems to enhance stability.

5. Information Access Control

  • We operate a system that detects and automatically blocks external threats, managed by security specialists.
  • Access control systems and CCTV cameras are installed in all offices and the server rooms to prevent unauthorized entry by outsiders.
  • We minimize and manage authorizations to access data using security systems such as firewalls.

6. Data Backup and System Upgrades

  • We perform periodic backups so that customers' valuable data is not lost due to accidents or mistakes.
  • We periodically inspect our systems, update system versions, and apply security patches to address vulnerabilities.
  • System changes, such as program upgrades, are carried out under the thorough analysis and management of specialists.

7. Establishment of a Disaster Recovery Framework

  • Ecount has built a disaster recovery system to ensure service continuity in the event of a disaster.
  • We conduct disaster recovery drills to verify the effectiveness of the data recovery plan.

Servers Hosted on
Amazon Web Services (AWS)

  • Ecount uses a cloud environment based on
    Amazon Web Services (AWS).
  • With AWS's server security systems in place,
    we operate a security framework designed to protect
    against external threats such as DDoS attacks.
  • Ecount's security specialists monitor servers
    and data and block potential security threats.
Server Stored in Amazon Web Services (AWS)

Users Can Configure
Security Settings Directly

  • Users can directly allow or block logins from
    specific IP addresses.
  • Program access time limits can be set for each ID.
  • Two-factor authentication can be enabled to
    strengthen identity verification during login.
  • You can set the password change interval.
Users Can Configure Security Settings Directly