Table of contents Chapter 1 General Provisions ................................................................................................... 1 1.1 Purpose and Scope of these Common Standards for Measures ................................. 1 (1) Purpose of these Standards ................................................................................ 1 (2) Scope of these Standards.................................................................................... 1 (3) Revisions of these Standards.............................................................................. 1 (4) Compliance with laws and regulations .............................................................. 2 (5) Contents of the measures ................................................................................... 2 1.2 Classification of Information and Handling Restrictions ........................................... 2 (1) Classification of information ............................................................................. 2 (2) Types of handling restrictions ............................................................................ 4 1.3 Definition of Terms .................................................................................................... 5 Chapter 2 Basic Framework of Information Security Measures ........................................... 8 2.1 Introduction and Plan ................................................................................................. 8 2.1.1 Establishment of organizations and systems .............................................................. 8 (1) Designation of the chief information security officer and deputy chief information security officer................................................................................ 8 (2) Establishment of the Information Security Committee ...................................... 9 (3) Designation of the chief information security auditor ....................................... 9 (4) Designation of the head information security officer and information security officers .................................................................................................. 9 (5) Designation of the chief information security advisor ....................................... 9 (7) Establishment of the system for information security incidents ........................ 9 (8) The roles that should not be concurrently undertaken by the same person ...... 10 2.1.2 Establishment of standards for measures and promotion plan of measures ............. 10 (1) Establishment of the government agency’s own standards .............................. 10 (2) Establishment of the promotion plan of measures ........................................... 10 2.2 Operation ................................................................................................................. 11 2.2.1 Enforcement of information security related provisions .......................................... 11 (1) Operation of information security measures ................................................... 11 (2) Handling violations .......................................................................................... 12 2.2.2 Exceptional measures............................................................................................... 12 (1) Maintenance of exceptional measures ............................................................. 12 (2) Operation of exceptional measure.................................................................... 12 2.2.3 Education ................................................................................................................. 13 (1) Establishment of structures for information security measures education and formulation of education implementation plans............................................... 13 (2) Enforcement of information security measures education ............................... 13 2.2.4 Handling of information security incidents.............................................................. 14 (1) Preparation for information security incidents ................................................. 14 (2) Handling of information security incidents ...................................................... 14 (3) Prevention of recurrence of information security incidents and sharing of lessons learned ................................................................................................. 15 2.3 Assessment............................................................................................................... 16 2.3.1 Self-check of information security measures ........................................................... 16 (1) Formulation of self-check plans and establishment of procedures .................. 16 (2) Conducting self-check...................................................................................... 16 (3) Evaluations and improvements based on self-check ........................................ 16 2.3.2 Information security audit ........................................................................................ 17 (1) Formulation of audit plans ............................................................................... 17 (2) Conducting information security audit............................................................. 17 Table of Contents - 1

Select target paragraph3