Annex 4: References for Concrete Examples of Measures
7.2.1
(H) System Acquisition, Development, and
Maintenance
● Acquisition of Systems Based on
Information Security Requirements
(I) Supplier Relations
● Information Security in Supplier Relations
● Management of Service Provision by
Suppliers
(J) Information Security Incident Management
● Management and Improvement of
Information Security Incidents
(3) Formulation of Separate Policies for Security
Management Measures
(4) Formulation of Plans for Addressing
Information Security Risks
-
JIS Q 27002:2014, 14.1.1 - 14.1.3, 14.2.1 - 14.2.9, 14.3.1
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018), 5.2.1,
5.2.2
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 5.2.1,
5.2.2
Guide for the Formulation of Specifications for Supply Chain
Risk Treatment in Information Security for External
Contractors, 4.1, 4.2
List of Requirements for Ensuring Security in Procurement of
IT Products
Guidebook for the Utilization of the List of Requirements for
Ensuring Security in Procurement of IT Products
Manual for the Formulation of Security Requirements in the
Government Procurement of Information Systems
IoT Security Guidelines ver.1.0, Key Concepts 8 - 16
-
JIS Q 27002:2014, 15.1.1 - 15.1.3
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018), 4.1.1,
4.1.4
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 4.1.1,
4.1.4
JIS Q 27002:2014, 15.2.1, 15.2.2
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018), 4.1.1,
4.1.4
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 4.1.1,
4.1.4
-
JIS Q 27002:2014, 16.1.1, 16.1.2, 16.1.6, 16.1.7
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018), 2.2.4
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 2.2.4
JIS Q 27002:2014, 5.1.1, 5.1.2
Information Security Management Standard (2016 Revised
version), 4.4.8.4, 4.4.8.5
4.1.4. The “Support” Perspective
(1) Securing Resources
(2) Human Resource Development and
Awareness-Raising
(3) Communication
-
Information Security Management Standard (2016 Revised
version), 4.5.1.1, 4.5.1.2
Information Security Management Standard (2016 Revised
version), 4.5.2.3, 4.5.2.4, 4.5.2.6 - 4.5.2.8
Information Security Management Standard (2016 Revised
version), 4.5.3.1
JIS Q 27014:2015, 5.3.2 - 5.3.4
4.2. The “Do” Perspective
4.2.1. The Operational Perspective
(1) Introduction and Operation of Information
Security Measures
(2) Addressing CISs Outages
-
-
JIS Q 27002:2014, 16.1.1, 16.1.2, 16.1.4, 16.1.5
Preparing for Advanced Persistent Threats (APT): A Process
Guide for Companies and Organizations
Incident Handling Manual
JIS Q 22301:2013
JIS Q 27002:2014, 17.1.1 - 17.1.3, 17.2.1
Guidelines for Information System Operation Continuity
Planning in Central Government Agencies ~ A Guide to
Formulation (2nd Edition)
48