Annex 4: References for Concrete Examples of Measures ● Information Management that Makes Use of Encryption Codes (E) Physical and Environmental Security ● Domains that Require Security ● Installation and Management of facilities that make an outage resulting from a disaster less likely to occur ● Management of Devices (F) Security Management During Operation ● Procedures of Operation and Responsibilities ● Protection from Malware ● Back-ups ● Maintaining Logs  JIS Q 27002:2014, 10.1.1, 10.1.2, 18.1.5  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 6.1.5  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 6.1.5  Export Trade Control Order, Appended Table 1, Item 9(7) Information security equipment or components therefor -  JIS Q 27002:2014, 11.1.1 - 11.1.6  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 3.2.1  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 3.2.1  IoT Security Guidelines ver.1.0, Key Concept 2  JIS Q 27002:2014, 11.1.4  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 3.2.1  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 3.2.1  JIS Q 27002:2014, 11.2.1, 11.2.3, 11.2.5  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 7.1.1, 7.1.2  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 7.1.1, 7.1.2  IoT Security Guidelines ver.1.0, Key Concept 2 -  JIS Q 27002:2014, 12.1.1, 12.1.2, 12.1.4       ● Management of Operation Software     ● Management of Technological Vulnerability     (G) Security of Communications ● Management of Network Security    ● Transmission of Information    JIS Q 27002:2014, 12.2.1 JIS Q 27002:2014, 12.3.1 JIS Q 27002:2014, 12.4.1 - 12.4.4 Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 6.1.4 The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 6.1.4 Use and method of analysis of log in relation to response against advanced cyberattack IoT Security Guidelines ver.1.0, Key Concept 2 JIS Q 27002:2014, 12.5.1 Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 5.2.3, 6.2.1 The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 5.2.3, 6.2.1 JIS Q 27002:2014, 12.6.1 Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 6.2.1 The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 6.2.1 IoT Security Guidelines ver.1.0, Key Concepts 17, 18, 21 - JIS Q 27002:2014, 13.1.1 - 13.1.3 Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 7.3.1 The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 7.3.1 JIS Q 27002:2014, 13.2.1 - 13.2.3 Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 7.1.3, 7.2.1 The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 7.1.3, 47

Select target paragraph3