Annex 4: References for Concrete Examples of Measures Annex 4: References for Concrete Examples of Measures Measures 4.1. The “Plan” Perspective 4.1.1. Perspective of the Organization’s Situation (1) Understanding the External and Internal Environments (2) Understanding the Requirements of Stakeholders References for concrete examples - -  Information Security Management Standard (2016 Revised version), 4.4.2.1  Information Security Management Standard (2016 Revised version), 4.4.3.1  JIS Q 27002:2014, 18.1.1 4.1.2. The “Leadership” Perspective (1) Commitment of the Management (2) Formulation of Information Security Policies (3) Assignment of Responsibilities and Authority for the Roles in the Organization -      Approaches to Cybersecurity for Corporate Management Cybersecurity Management Guidelines Ver.2.0 IoT Security Guidelines ver.1.0, Key Concept 1 JIS Q 27002:2014, 5.1.1, 5.1.2 Information Security Management Standard (2016 Revised version), 4.4.1.2 4.1.3. The “Plan” Perspective (1) Information Security Risk Assessments (2) Decision to Address Information Security Risks (A) Security for Human Resources (Outsourcing) ● Matters to be Addressed Before Outsourcing (Selection/Contract Conditions) ● Matters to be Addressed During the Contract Period (B) Asset Management ● Responsibility for Assets ● Categories of Information and the Handling of Information ● Data Management (C) Access Control ● Management of User Access ● Access Control for Information Systems, etc. (D) Encryption Codes -  Risk Assessment Guide Based on the Concept of Mission Assurance in Critical Infrastructure  Security Risk Assessment Guide for Industrial Control Systems  CSMS Certification Criteria Ver.2.0, 4.2, 4.3  CSMS User Guide Ver.1.2, 3.1, 4.1 - 4.4, 6.1  IoT Security Guidelines ver.1.0, Key Concept 3 - 7 - -  JIS Q 27002:2014, 7.1.1, 7.1.2, 7.2.1, 7.2.2, 7.3.1  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 4.1.1  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 4.1.1  Guide for the Formulation of Specifications for Supply Chain Risk Treatment in Information Security for External Contractors, 3.1, 3.2 -  JIS Q 27002:2014, 8.1.1 - 8.1.4  JIS Q 27002:2014, 8.2.1 - 8.2.3  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 3.1.1  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 3.1.1  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 4.1.4,7.2.4  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 4.1.4,7.2.4 -  JIS Q 27002:2014, 9.2.1 - 9.2.6  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 6.1.3  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 6.1.3  JIS Q 27002:2014, 9.4.1 - 9.4.3  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018),6.1.1, 6.1.2  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 6.1.1, 6.1.2 - 46

Select target paragraph3