II. Items that Should Ideally be Prescribed in the Safety Principles
Joint exercises and training include the cross-sectoral exercises organized by NISC, as well as
other programs organized by stakeholders such as responsible ministries for CIP and
information security related agencies.
4.3. The “Check” Perspective
4.3.1. The Evaluation Perspective
(1) Monitoring and Auditing
Ensure that the respective initiatives are progressing as planned by monitoring the progress
toward the achievement of goals that have been set based on the information security policy,
progress of the plans for information security risk treatment, and the progress of education and
training aimed at improving awareness of information security.
Risk owners should also periodically monitor changes in the risks accompanying in the
introduction and operation of security management measures (such as changes in the frequency
of occurrence of events, changes in the degree of impact that the consequences of events have,
etc.). In addition to visualizing the changes in the status of individual risks, it is also expected
that monitoring allows them to grasp the changes to the risk status for the organization as a
whole.
Furthermore, check that periodical internal audits are conducted (in cases where it is difficult
to do so, risk owners should conduct self-inspections at the very least), PDCA cycle for
information security measures is built appropriately based on information security policies, and
it is maintained in an effective state. In addition to putting effort into nurturing the internal audit
personnel necessary for this, it is also expected to check the situation where necessary with the
support of external parties who possess advanced expertise.17
(2) Review by the Management
The management of CI operators make use of system audits and other resources, periodically
check the status of information security measures for the organization, and identify areas where
improvements or reviews are necessary. In doing so, in addition to the results of monitoring and
audits conducted, also verify the status of measures taken based on the previous review results,
changes in the external and internal environments, and feedback from stakeholders.
Document the review results, check the current status of the resources needed for improvements
and reviews (human resources, budget, etc.), and issue instructions for improvements and
In METI’s Information Security Audit System, the Registry System for ledger of Information Security Audit Firms, which registers the
entities engaged in information security audits (audit companies, information security vendors, system vendors, information security specialist
companies, system audit companies, etc.), is prepared and published.
17
24