Annex 4: References for Concrete Examples of Measures 7.2.1 (H) System Acquisition, Development, and Maintenance ● Acquisition of Systems Based on Information Security Requirements (I) Supplier Relations ● Information Security in Supplier Relations ● Management of Service Provision by Suppliers (J) Information Security Incident Management ● Management and Improvement of Information Security Incidents (3) Formulation of Separate Policies for Security Management Measures (4) Formulation of Plans for Addressing Information Security Risks -  JIS Q 27002:2014, 14.1.1 - 14.1.3, 14.2.1 - 14.2.9, 14.3.1  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 5.2.1, 5.2.2  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 5.2.1, 5.2.2  Guide for the Formulation of Specifications for Supply Chain Risk Treatment in Information Security for External Contractors, 4.1, 4.2  List of Requirements for Ensuring Security in Procurement of IT Products  Guidebook for the Utilization of the List of Requirements for Ensuring Security in Procurement of IT Products  Manual for the Formulation of Security Requirements in the Government Procurement of Information Systems  IoT Security Guidelines ver.1.0, Key Concepts 8 - 16 -  JIS Q 27002:2014, 15.1.1 - 15.1.3  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 4.1.1, 4.1.4  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 4.1.1, 4.1.4  JIS Q 27002:2014, 15.2.1, 15.2.2  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 4.1.1, 4.1.4  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 4.1.1, 4.1.4 -  JIS Q 27002:2014, 16.1.1, 16.1.2, 16.1.6, 16.1.7  Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2018), 2.2.4  The Guidelines for Establishing Agencies’ Standards for Information Security Measures (FY2018), 2.2.4  JIS Q 27002:2014, 5.1.1, 5.1.2  Information Security Management Standard (2016 Revised version), 4.4.8.4, 4.4.8.5 4.1.4. The “Support” Perspective (1) Securing Resources (2) Human Resource Development and Awareness-Raising (3) Communication -  Information Security Management Standard (2016 Revised version), 4.5.1.1, 4.5.1.2  Information Security Management Standard (2016 Revised version), 4.5.2.3, 4.5.2.4, 4.5.2.6 - 4.5.2.8  Information Security Management Standard (2016 Revised version), 4.5.3.1  JIS Q 27014:2015, 5.3.2 - 5.3.4 4.2. The “Do” Perspective 4.2.1. The Operational Perspective (1) Introduction and Operation of Information Security Measures (2) Addressing CISs Outages - -  JIS Q 27002:2014, 16.1.1, 16.1.2, 16.1.4, 16.1.5  Preparing for Advanced Persistent Threats (APT): A Process Guide for Companies and Organizations  Incident Handling Manual  JIS Q 22301:2013  JIS Q 27002:2014, 17.1.1 - 17.1.3, 17.2.1  Guidelines for Information System Operation Continuity Planning in Central Government Agencies ~ A Guide to Formulation (2nd Edition) 48

Select target paragraph3