II. Items that Should Ideally be Prescribed in the Safety Principles
Define and implement the necessary handling restrictions (for example, prohibition of
duplication, prohibition of taking out, and prohibition of distribution), based on the life cycle
of the information, such as creation, access, use, storage, transportation, transmission, provision,
and deletion.
● Data Management
Based on the risk assessment of systems, conduct desirable data management that takes into
consideration appropriate data protection and data storage location etc.
When considering changes in business environment and adopting a new technique such as an
internet-based service (such as cloud services), pay attention to the presence of Japanese and
foreign laws and evaluation systems.
(C) Access Control
● Management of User Access
In order to appropriately manage the users accessing information systems and information, etc.
that is associated with the provision of CISs, as well as their access rights, clearly define the
application routes, authorizer, and worker in relation to the official processes of the registration,
change, and deletion of users and their access rights. At the same time, periodically review the
access right of users during operation. In particular, manage strictly the assignment and use of
privileged access rights to information systems.
● Access Control for Information Systems, etc.
Based on the principles of the least privilege and the separation of duty, restrict the access to
information and to information systems that are associated with the provision of CISs (including
remote access).
Establish systems that ensure compliance with secure log-on procedures (for example,
restriction on the number of failed log-in) and the use of strong passwords (for example, type
and number of characters to strengthen security). At the same time, depending on the level of
importance of the information systems and information, consider also utilizing advanced means
of authentication, such as multi-factor authentication.
(D) Encryption Codes
● Information Management that Makes Use of Encryption Codes
When making use of encryption technology to protect the confidentiality of information that is
associated with the provision of CISs, formulate policies for the use of encryption codes and
management policies for the keys that are used for the codes (encryption keys). Pay attention
to the presence of Japanese and foreign laws and regulations related to encryption technology.
14