II. Items that Should Ideally be Prescribed in the Safety Principles
instant messaging services, to transmit important information associated with the provision of
CISs, organize in advance the policies and procedures related to ensuring security, such as
confidentiality and integrity. At the same time, work to reach an agreement with the
stakeholders who are the recipient party in these transmissions regarding the policies and
procedures.
(H) System Acquisition, Development, and Maintenance
● Acquisition of Systems Based on Information Security Requirements
When acquiring or developing new information systems associated with the provision of CISs,
and when improving existing information systems, conduct a review that incorporates
requirements for information security among the requirements for the system, based on the
concept of “security by design.”12 (Where necessary, also conduct a review that incorporates
requirements from the perspective of the aforementioned HSE.) As third-party authentication
systems that comply with international standards on the security of information systems are
also available depending on the CI sector, consider also utilizing authenticated information
systems where necessary.
Establish policies, procedures, and environments to realize the development or building of
systems that take information security into consideration. In particular, when checking the
acceptance of the information system, in addition to checking the requirements related to
information security, also consider the need to conduct a vulnerability diagnostic test
corresponding to the level of importance of the information system. Furthermore, when
outsourcing system development, periodically check with the contractor on the status of
compliance with development policies that take information security into consideration.
(I) Supplier Relations
● Information Security in Supplier Relations
In cases where facilities such as information systems that are associated with the provision of
CISs, as well as their operation, are replaced by services provided by external suppliers (for
example, suppliers of IT services and the components of IT infrastructure), organize
information security requirements to reduce the risk of access to the assets of CI operators by
suppliers and their subcontractors, and obtain the agreement of the suppliers to these
requirements in advance.
In cases where different levels of suppliers are present, improve information security in the
supply-chain by ensuring that a certain supplier expects the supplier at the level below them to
comply with the same requirements.
12
Refers to policies aimed at ensuring information security from the planning and design phases.
18