II. Items that Should Ideally be Prescribed in the Safety Principles
Responsible for internal audits on all information security measures
Responsible for the management of information security measures in the supply-chain
(suppliers, contractors, etc.)
Responsible for the management of the functional requirements for security personnel, and
for education and training
Responsible for the operation of information systems (including networks)
Responsible for the management of the respective assets (information systems, software,
information, etc.)
Responsible for the management of facilities that require physical security
10