II. Items that Should Ideally be Prescribed in the Safety Principles Define and implement the necessary handling restrictions (for example, prohibition of duplication, prohibition of taking out, and prohibition of distribution), based on the life cycle of the information, such as creation, access, use, storage, transportation, transmission, provision, and deletion. ● Data Management Based on the risk assessment of systems, conduct desirable data management that takes into consideration appropriate data protection and data storage location etc. When considering changes in business environment and adopting a new technique such as an internet-based service (such as cloud services), pay attention to the presence of Japanese and foreign laws and evaluation systems. (C) Access Control ● Management of User Access In order to appropriately manage the users accessing information systems and information, etc. that is associated with the provision of CISs, as well as their access rights, clearly define the application routes, authorizer, and worker in relation to the official processes of the registration, change, and deletion of users and their access rights. At the same time, periodically review the access right of users during operation. In particular, manage strictly the assignment and use of privileged access rights to information systems. ● Access Control for Information Systems, etc. Based on the principles of the least privilege and the separation of duty, restrict the access to information and to information systems that are associated with the provision of CISs (including remote access). Establish systems that ensure compliance with secure log-on procedures (for example, restriction on the number of failed log-in) and the use of strong passwords (for example, type and number of characters to strengthen security). At the same time, depending on the level of importance of the information systems and information, consider also utilizing advanced means of authentication, such as multi-factor authentication. (D) Encryption Codes ● Information Management that Makes Use of Encryption Codes When making use of encryption technology to protect the confidentiality of information that is associated with the provision of CISs, formulate policies for the use of encryption codes and management policies for the keys that are used for the codes (encryption keys). Pay attention to the presence of Japanese and foreign laws and regulations related to encryption technology. 14

Select target paragraph3