5.2.2 5.2.3 5.2.4 5.2.5 5.3 5.3.1 (4) Measures when outsourcing operation and maintenance of information systems ............................................................................................................. 32 Procurement and construction of information systems ............................................ 32 (1) Measures when selecting equipment, etc. ........................................................ 32 (2) Measures when constructing information systems........................................... 32 (3) Measures for inspections on delivery ............................................................... 32 Operation and maintenance of information security ................................................ 33 (1) Measures for information systems during operation and maintenance ............ 33 Update and disposal of information systems ........................................................... 33 (1) Measures for update and disposal of information systems .............................. 34 Review on measures for information systems ......................................................... 34 (1) Review on measures for information systems.................................................. 34 Operational Continuity Plan of Information Systems .............................................. 34 Ensuring consistency between information security measures for information systems and the systems’ operational continuity plans ............................................ 34 (1) Ensuring consistency between information security measures for information systems and the systems’ operational continuity plans ................ 35 Chapter 6 Security Requirements for Information Systems ................................................ 35 6.1 Security Functions of Information Systems ............................................................. 35 6.1.1 User/entity authentication functions ........................................................................ 35 (1) Implementation of the user/entity authentication functions ............................. 35 (2) Management of the identification code and the user/entity authentication information ....................................................................................................... 35 6.1.2 Access control functions .......................................................................................... 36 (1) Implementation of access control functions ..................................................... 36 6.1.3 Authority control ...................................................................................................... 36 (1) Authority control .............................................................................................. 36 6.1.4 System logs retrieval and management .................................................................... 37 (1) Event logs retrieval and management .............................................................. 37 6.1.5 Encryption and digital signatures ............................................................................. 37 (1) Implementation of encryption and digital signature functions ......................... 38 (2) Management of encryption and digital signature ............................................. 38 6.2 Measures against Information Security Threats ....................................................... 39 6.2.1 Measures against software vulnerabilities ............................................................... 39 (1) Implementation of measures against software vulnerabilities ......................... 39 6.2.2 Measures for protection against malware ................................................................ 39 (1) Implementations of measures against malware ................................................ 40 6.2.3 Measures against denial-of-service attacks .............................................................. 40 (1) Implementation of measures for denial-of-service attacks............................... 40 6.2.4 Measures against targeted attacks ............................................................................ 41 (1) Implementation of measures for targeted attacks ............................................. 41 6.3 Creation and provision of applications and contents ............................................... 41 6.3.1 Measures upon creating applications and contents .................................................. 41 (1) Establishment/maintenance of provisions related to creation of applications and contents ..................................................................................................... 42 (2) Formulation of security requirements for applications and contents ............... 42 6.3.2 Measures upon providing applications and contents................................................ 42 (1) Use of government domain name .................................................................... 42 (2) Prevention of users from being lured to malicious websites ............................ 43 (3) Notification of applications and contents ......................................................... 43 Chapter 7 Information Systems Components ....................................................................... 43 7.1 Terminals, Server Equipment ................................................................................... 43 7.1.1 Terminals.................................................................................................................. 43 Table of Contents - 3

Select target paragraph3