I. Purposes and Positioning
Plan
“Organization’s situation” perspective
・Understanding of the external and internal environments
・Understanding of the requirements of stakeholders
“Leadership” perspective
・Commitment of the management
・Formulation of information security policies
・Assignment of responsibilities and authority for the roles in the
organization
“Plan” perspective
・Information security risk assessment
・Decision on responses to information security risks
・Formulation of individual policies related to security
management measures
・Formulation of plans for responses to information security risks
“Support” Perspective
・Securing resources
・Human resource development and raising awareness
・Communication
Do
“Operation” perspective
・Adoption and operation of information security measures
・Response to CISs outages
・Implementation of exercises and training
Check
“Evaluation” perspective
・Monitoring and audits
・Reviews by the management
Act
“Improvement” perspective
・Corrective measures and continuous improvement
Figure 1: Overall image of information security measures in CI
4