II. Items that Should Ideally be Prescribed in the Safety Principles
● Management of Service Provision by Suppliers
To ensure compliance with the information security requirements that have been agreed upon,
constantly monitor the provision of services by suppliers, and conduct reviews and audits on
reports drawn up by the suppliers. Due to the need to reassess risks, manage changes in the
services provided by suppliers.
(J) Information Security Incident Management
●Management and Improvement of Information Security Incidents
To respond promptly and effectively to information security incidents that have an impact on
the safe and continuous provision of CISs, define who the responsible managers of incidents
are, and establish procedures such as reporting to internal and external parties and collecting
evidence.
In addition, establish systems that enable the application of knowledge gained through incident
responses toward ensuring readiness for future incidents.
(3) Formulation of Individual Policies for Security Management Measures
Consolidate standards, such as actions that should be complied with and decisions in individual
security management measures that have been decided upon during the process of addressing
information security risks, as separate policies (for example, access control policy, information
classification policy, etc.), and transmit these within the organization. Where necessary, also
communicate these to contractors.
In the same way as information security policies, verify the validity and effectiveness of the
contents of separate policies at regular intervals, and check them in the event that any significant
environmental changes have occurred.
(4) Formulation of Plans for Addressing Information Security Risks
Formulate plans for addressing information security risks, which set out goals based on the
contents of the information security policies and the criteria for determining the status of
achievement of the goals, as well as implementation items and schedule toward the introduction
of the security management measures that have been decided upon.
4.1.4. The “Support” Perspective
(1) Securing Resources
In promoting the PDCA cycle for information security measures, or in other words, the
establishment, implementation, maintenance, and continual improvement of the PDCA cycle,
19