II. Items that Should Ideally be Prescribed in the Safety Principles
Furthermore, in addressing information security risks, the management is expected to recognize
the “Responsibility of Top Management at CI Operators” prescribed below, while taking
reference from the Approaches to Cybersecurity for Corporate Management 2 and the
Cybersecurity Management Guidelines.3
【Responsibility of Top Management at CI Operators】
Ensuring information security is a responsibility that should be fulfilled by the
management; therefore, commit themselves to exerting leadership and putting in
place information security measures based on the concept of mission assurance.
Recognize that the company’s activities contribute to the development of society as
a whole, and put in place security measures that include the supply-chain (business
partners, subsidiaries, and affiliated companies).
From the perspective of fostering trust and a sense of security among stakeholders
with regard to information security, take steps such as disclosing information about
a posture of readiness for information security measures during normal times and
responses when an incident occurs.
In addition to accurately collecting the necessary information for each of the
abovementioned efforts, continuously secure the necessary management resources
such as budget, systems, and human resources, and allocate them appropriately
based on a risk-based approach.
Taking into account the effect that responses to information security risks have on
the business and the verification results of the impact, make decisions on the need to
review further strategies for addressing information security risks and the contents,
at the Board of Directors’ meetings and other important management meetings.
* Partial revision and addition of items necessary for the formulation of this guideline, based on the contents
set out in the 4th Cybersecurity Policy.
(2) Formulation of Information security Policies
CI operators formulate information security policies, which are official documents for internal
and external parties. In the information security policies, CI operators, who have the social
responsibilities of ensuring the safe and continuous provision of CISs, set out the purposes and
2
Compiled by the Working Group for Corporate Management with a Security Mindset, established under the Human Resources Expert Panel
for Dissemination and Enlightenment (decided by the Cybersecurity Strategic Headquarters on 10 February 2015). It presents the basic stance
on cybersecurity for corporate management.
3
From the perspective of protecting the company from cyberattacks, this summarizes the principles that managers need to be aware of, and
the important items that should be issued as instructions to officers in charge (CISO, etc.) who are responsible for implementing information
security measures. Formulated by the Ministry of Economy, Trade, and Industry (METI) and Information-technology Promotion Agency (IPA).
8