II. Items that Should Ideally be Prescribed in the Safety Principles
direction of information security measures, as well as present the commitment of the
management toward fulfilling the requirements of stakeholders related to the information
security measures and continual improvements on the information security measures.
The information security policies are communicated within the organization, and can also be
obtained by external stakeholders where necessary. In addition to checking, at regular intervals,
that the information security policies are relevant and effective, it is also necessary to check the
policies in the event of any significant changes to the situation surrounding the organization.
(3) Assignment of Responsibilities and Authority for the Roles in the Organization
In order to ensure the firm implementation of information security measures, the management
of CI operators decide on the departments and employees that will take on the role of promoting
information security measures. At the same time, the management also assigns the
corresponding responsibilities and authority within the appropriate scope, communicates the
assignment to all members of the organization, and ensures that all employees have the same
recognition of these responsibilities and authority.
In doing so, it is particularly important to clearly identify the risk owners from among the
personnel who have the role of promoting information security measures. These risk owners
have the responsibility of monitoring and addressing the risks identified through risk
assessments, and are required to provide clear explanations and take responsibility for the
contents of their explanations.
Besides, it is also expected to secure human resources who are able to connect the management
with the practitioners, plan the information security measures based on the business strategy,
and lead and direct the practitioners (CISO, etc.).
Furthermore, in cases where the organization has an environment in which control systems are
operated, they are expected to consider the need for human resources for departments related
to OT4 to prevent and recover from CISs outages caused by cyberattacks or other reasons.
In addition to the abovementioned, the following roles are also possible:
Responsible for the collection of threat information, etc. and the sharing of information
with stakeholders
Responsible for the management of security incidents (CSIRT, etc.)
Responsible for the execution of contingency plans and business continuity plans
4
In this guideline, it refers to operation technology such as control systems that make use of information and communication technology (IT).
9