rule of Paragraph 1, Article 29 of the Act on General Rules for Incorporated Administrative
Agencies (Act No. 103 of 1999), mid and long-term objectives of the item indicated by the
rule of item (1), Paragraph 4 of Article 35, or in annual objective of the item indicated by the
item (1), Paragraph 9 of Article 35, according to policies established based on the Common
Standards Group. The national administrative organ overseeing Designated Corporations
makes the necessary recommendations on information security measures for the designated
corporations in question based on the individual governing laws.
(2) Evaluation
The competent minister in charge of Incorporated Administrative Agencies also evaluates the
implementation status of information security measures and publishes the evaluation result
when operations’ actual performance is assessed based on the Act on General Rule of
Incorporated Administrative Agencies. The national administrative organ in charge of
Designated Corporations evaluates the implementation status of information security
measures for the designated corporations in question based on the individual governing laws.
The NISC also confirms the evaluation results regarding the information security measures
of Incorporated Administrative Agencies and Designated Corporations and advises the
national administrative organs holding jurisdiction over these corporations as necessary.
4.
Information Security Measures of Information Systems Shared by Multiple Agencies
Common platform systems are operated and managed in cooperation with the information
systems at each organization using the platform systems. Thus, careless mistakes need to be
prevented for the information security measures across each organization. Considering the
possibility that information security incidents of partial information system linked to common
platform system impacts on other information systems, information security management
should be implemented decently and information security levels for the overall information
system should be ensured properly.
Consequently, organizations that conduct development and operation management of
common platform systems to serve as a foundation and organizations that manage information
systems linked to the common platform system (hereinafter referred to as “development and
operation management organizations”) need to clarify roles and responsibilities of each
organization for preparation of the system to conduct operation management of the
infrastructure information system to serve as a foundation and to establish the system to be