II. Items that Should Ideally be Prescribed in the Safety Principles
(E) Physical and Environmental Security
● Domains that Require Security
To protect domains with information and information systems that are associated with the
provision of CISs (domains that require the ensuring of information security and safety),
establish a physical security boundary. At the same time, build a system to monitor the physical
environment, and to conduct the appropriate entry/exit management, in order to allow access
only to authorized employees and contractors.
From the perspective of preventing malicious activities, restrict the carrying in of unauthorized
items into this domain. In addition, it is also effective to restrict personnel from working alone
for CI operators that are able to secure multiple workers for the task.
● Installation and Management of facilities that make an outage resulting from a disaster less
likely to occur
With regard to facilities such as datacenter and information systems that are associated with the
provision of CISs, build a mechanism to enable the appropriate installation and management of
facilities, by considering and taking preventive measures in advance in order to mitigate damage
in case of the disaster, such as considering a deployment that reduces the possibility of an outage
resulting from a disaster.
● Management of Devices
Set up devices that are associated with the provision of CISs (such as information systems) in
a way that reduces opportunities for unauthorized access, while, at the same time, carrying out
maintenance appropriately to continuously maintain availability and integrity. Lay out
communications cables and power cables in consideration of the possibility of interception and
damage.
To prevent the leakage of confidential information led by the theft of devices such as removable
external storage devices, restrict the use of such devices, and establish systems for the prior
authorization of the taking out of such devices. Consider also the possibility of information
leakage through the disposal and reuse of the devices.
(F) Security Management during Operation
● Procedures of Operation and Responsibilities
Prepare procedure manuals on the operation of information systems that are associated with the
provision of CISs while taking into account the points of ensuring the operations fulfill security
standards in addition to ensuring accuracy in work.
15