II. Items that Should Ideally be Prescribed in the Safety Principles
With regard to changes to the information systems and peripheral equipment (maintenance,
repairs, etc.), as adverse impact on information security measures during implementation is also
conceivable, define the processes for managing changes in advance, including procedures for
authorizing the persons-in-charge, and implement changes based on these processes. In
principle, the tools used for maintenance and repairs should be authorized and managed.
Furthermore, from the perspective of preventing unauthorized access to the operating
environment of CISs, segregate the operating environment from other environments such as the
development and test environments.
● Protection from Malware
As malware, which infects information systems through means such as targeted attack e-mails
or USB drives, can potentially cause CISs outages, take preemptive steps to establish systems
to detect and guard against malware. At the same time, establish measures and procedures to
achieve early recovery even in cases of a malware infection. Also consider the possibility for
malware infection through the computers and devices brought in by contractors, which is
difficult for CI operators to manage directly.
For critical information systems with a high level of priority, it is also desirable to make use of
multi-engine malware detection software that is expected to improve the detection rate of
malware, as well as whitelist-type malware disabling functions, which are characterized by their
ability to address unknown threats while at the same time reducing load on the systems.
●Back-ups
Establish back-up policies and procedures in advance for system images and data, based on the
possibility of mistaken deletion of important data or the anomalous condition of information
systems associated with the provision of CISs (including improper data encryption by
ransomware, etc.). From the perspective of ensuring availability, a sufficient volume of backups should be made.
As the back-ups that have been made should be usable without any issues where necessary,
periodically carry out backup recovery tests.
●Maintaining Logs
From the perspective of monitoring illegal access and operations for information systems that
are associated with the provision of CISs, maintain event logs of the information systems and
work logs of the personnel in charge of operations. When considering the capacity for the log
storage device, the availability of the logs should also be considered.
16