II. Items that Should Ideally be Prescribed in the Safety Principles
● Matters to Be Addressed before Outsourcing (Selection/Contract Conditions)
When selecting the external contractor for tasks that are related to CISs, consider the categories
of information that will be accessed as well as the risks identified, in addition to the business
requirements.
In the outsourcing agreement between the organization and the contractor, incorporate the
contractor’s responsibility for implementing information security measures that fulfill the
information security requirements of the organization, the responsibility for providing
education and training to raise the awareness of employees, and the responsibility and tasks
associated with effective information security even after the end of the contract.
As there may be cases where the review of contract wording is necessary depending on the
results of the risk assessments that have been implemented continuously, it is desirable for the
security department or legal department to regularly establish spaces for the exchange of
information.
● Matters to Be Addressed during the Contract Period
To ensure the steady execution of information security requirements by the contractor, regularly
verify the implementation status of measures by the contractor, and request for the necessary
improvements to be put in place.
(B) Asset Management
● Responsibility for Assets
After specifying assets such as information systems, software, and information that are
associated with the provision of CISs, draw up an asset record that clearly sets out the parties
responsible for the management of and the usage limit of each asset (scope within which use is
permitted), and maintain and manage this record. Along with this, also draw up network
configuration diagrams, data flow charts, and other figures. In cases where facilities such as
information systems and their operation are replaced by services provided by an external
supplier (for example, a supplier of IT services or of the components of IT infrastructure), draw
up a list of services, and maintain and manage this list.
● Categories of Information and the Handling of Information
With regard to the information handled by CI operators, corresponding to the level of
importance, legal requirements, impact on sense of security among citizens, and other factors,
assign ratings to the information from the perspective of confidentiality, integrity, and
availability, and label the information medium (paper, electronic).
13