II. Items that Should Ideally be Prescribed in the Safety Principles With regard to changes to the information systems and peripheral equipment (maintenance, repairs, etc.), as adverse impact on information security measures during implementation is also conceivable, define the processes for managing changes in advance, including procedures for authorizing the persons-in-charge, and implement changes based on these processes. In principle, the tools used for maintenance and repairs should be authorized and managed. Furthermore, from the perspective of preventing unauthorized access to the operating environment of CISs, segregate the operating environment from other environments such as the development and test environments. ● Protection from Malware As malware, which infects information systems through means such as targeted attack e-mails or USB drives, can potentially cause CISs outages, take preemptive steps to establish systems to detect and guard against malware. At the same time, establish measures and procedures to achieve early recovery even in cases of a malware infection. Also consider the possibility for malware infection through the computers and devices brought in by contractors, which is difficult for CI operators to manage directly. For critical information systems with a high level of priority, it is also desirable to make use of multi-engine malware detection software that is expected to improve the detection rate of malware, as well as whitelist-type malware disabling functions, which are characterized by their ability to address unknown threats while at the same time reducing load on the systems. ●Back-ups Establish back-up policies and procedures in advance for system images and data, based on the possibility of mistaken deletion of important data or the anomalous condition of information systems associated with the provision of CISs (including improper data encryption by ransomware, etc.). From the perspective of ensuring availability, a sufficient volume of backups should be made. As the back-ups that have been made should be usable without any issues where necessary, periodically carry out backup recovery tests. ●Maintaining Logs From the perspective of monitoring illegal access and operations for information systems that are associated with the provision of CISs, maintain event logs of the information systems and work logs of the personnel in charge of operations. When considering the capacity for the log storage device, the availability of the logs should also be considered. 16

Select target paragraph3