information system and information of Agency’s own. The same shall apply hereinafter) in light of characteristics of its own agency. Agency can decide the name of Agency’s basic policy and Agency’s own standards (hereinafter referred to as “Agency’s policy”) by themselves. 2. Agency’s basic policy shall provide a basic idea on information security including purpose of information security measures and target scopes to ensure information security. 3. The standards shall be stipulated to enable information security measures that are the same as or higher than the Common Standards for Information Security Measures for Government Agencies and Related Agencies (hereinafter referred to as the “Common Standards”) that are separately defined. 4. National administrative organs shall require that the Incorporated Administrative Agencies and Designated Corporations under their control refer to the organ’s own policies when said agencies and corporations establish policies as needed. 5. Incorporated Administrative Agencies and Designated Corporations shall comply with the requirements from the previous paragraph. 6. Agency shall evaluate and review Agency’s policy by considering the evaluation result of the Paragraph 1 of the previous article. Chapter 3. Basic Measures of Information Security Measures for Government Agencies and Related Agencies (Management System) Article 5. Agency shall establish organization and system to implement information security measures. 2. Agency shall designate chief information security officer. 3. The chief information security officer shall organize information security committee with function of discussing Agency’s own standards and assign a chairperson and members of the committee. 4. The chief information security officer directs and is responsible for tasks associated with information security measures at Agency provided by this model. 5. The chief information security officer can delegate their own responsible tasks defined by the Common Standards to a responsible person defined by the Common Standards. (Promotion Plan of Measures) Article 6. The chief information security officer shall establish the plan (hereinafter referred to as “promotion plan of measures”) to comprehensively promote information security measures

Select target paragraph3