II. Items that Should Ideally be Prescribed in the Safety Principles  Responsible for internal audits on all information security measures  Responsible for the management of information security measures in the supply-chain (suppliers, contractors, etc.)  Responsible for the management of the functional requirements for security personnel, and for education and training  Responsible for the operation of information systems (including networks)  Responsible for the management of the respective assets (information systems, software, information, etc.)  Responsible for the management of facilities that require physical security 10

Select target paragraph3