II. Items that Should Ideally be Prescribed in the Safety Principles
clearly define the resources required (human resources, budget, etc.), and allocate them
appropriately within the organization under the leadership of the management.
From the perspective of addressing the issue of a decline in the standard of information security
measures due to environmental changes, the management strives to continuously secure the
necessary resources.
(2) Human Resource Development and Awareness-Raising
With regard to the security personnel who will be responsible for promoting information
security measures, from the perspective of securing and maintaining the capacity and number
of staff necessary for the safe and continuous provision of CISs, it is important to consider
beforehand the career paths and wage policies of these security personnel within the CI operator.
Furthermore, as the employees of CI operators fulfill their obligations and responsibilities based
on the respective individual information security policies and security management measures,
provide employees with sufficient education and training in the area of information security
(where necessary, the training can also be conducted by a contractor). In particular, in
developing security personnel who will be responsible for promoting information security
measures, it is also expected to utilize, for example, human resource development programs
conducted by government organizations and training programs provided by security vendors,
participate in exercises and training in collaboration with stakeholders (*refer to 4.2.1. (3)), and
obtain qualifications such as the Registered Information Security Specialist certificate. These
initiatives are also effective in the objective evaluation and verification of the status of progress
in human resource development.
In addition to promoting understanding of information security policies, it is also important to
raise awareness through methods such as presenting examples of the consequences that could
arise in the event that inadequate efforts are put in, in order to make employees themselves
recognize the importance and need to be involved in such information security measures.
(3) Communication
It is important to establish regular opportunities for dialogue between the management, which
is responsible for addressing information security risks, and the practitioners, who promote
information security measures under the supervision (instructions, monitoring, evaluation, etc.)
of the management, and to vitalize communication. When doing so, it is important for the
practitioners to share accurate information and offer suggestions through opportunities for
dialogue, so as to enable the management to get an accurate grasp of the status in addressing
information security risks, and to make accurate decisions and adjustments in responding to
20