Annex 4: References for Concrete Examples of Measures
Annex 4: References for Concrete Examples of Measures
Measures
4.1. The “Plan” Perspective
4.1.1. Perspective of the Organization’s
Situation
(1) Understanding the External and Internal
Environments
(2) Understanding the Requirements of
Stakeholders
References for concrete examples
-
-
Information Security Management Standard (2016 Revised
version), 4.4.2.1
Information Security Management Standard (2016 Revised
version), 4.4.3.1
JIS Q 27002:2014, 18.1.1
4.1.2. The “Leadership” Perspective
(1) Commitment of the Management
(2) Formulation of Information Security Policies
(3) Assignment of Responsibilities and Authority
for the Roles in the Organization
-
Approaches to Cybersecurity for Corporate Management
Cybersecurity Management Guidelines Ver.2.0
IoT Security Guidelines ver.1.0, Key Concept 1
JIS Q 27002:2014, 5.1.1, 5.1.2
Information Security Management Standard (2016 Revised
version), 4.4.1.2
4.1.3. The “Plan” Perspective
(1) Information Security Risk Assessments
(2) Decision to Address Information Security
Risks
(A) Security for Human Resources
(Outsourcing)
● Matters to be Addressed Before
Outsourcing (Selection/Contract
Conditions)
● Matters to be Addressed During the
Contract Period
(B) Asset Management
● Responsibility for Assets
● Categories of Information and the Handling
of Information
● Data Management
(C) Access Control
● Management of User Access
● Access Control for Information Systems,
etc.
(D) Encryption Codes
-
Risk Assessment Guide Based on the Concept of Mission
Assurance in Critical Infrastructure
Security Risk Assessment Guide for Industrial Control
Systems
CSMS Certification Criteria Ver.2.0, 4.2, 4.3
CSMS User Guide Ver.1.2, 3.1, 4.1 - 4.4, 6.1
IoT Security Guidelines ver.1.0, Key Concept 3 - 7
-
-
JIS Q 27002:2014, 7.1.1, 7.1.2, 7.2.1, 7.2.2, 7.3.1
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018), 4.1.1
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 4.1.1
Guide for the Formulation of Specifications for Supply Chain
Risk Treatment in Information Security for External
Contractors, 3.1, 3.2
-
JIS Q 27002:2014, 8.1.1 - 8.1.4
JIS Q 27002:2014, 8.2.1 - 8.2.3
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018), 3.1.1
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 3.1.1
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018),
4.1.4,7.2.4
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 4.1.4,7.2.4
-
JIS Q 27002:2014, 9.2.1 - 9.2.6
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018), 6.1.3
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 6.1.3
JIS Q 27002:2014, 9.4.1 - 9.4.3
Common Standards for Information Security Measures for
Government Agencies and Related Agencies (FY2018),6.1.1,
6.1.2
The Guidelines for Establishing Agencies’ Standards
for Information Security Measures (FY2018), 6.1.1,
6.1.2
-
46