paragraph by labeling etc. when information is provided, carried and sent across the Agencies. (Handling Restriction on Information) Article 13. Agency shall stipulate handling restrictions according to classifications of information. 2. Agency shall provide the handling restriction that is defined by the previous paragraph on the information to be handled. 3. Agency shall indicate the handling restriction of information when information is provided, carried and sent across the Agencies. (Information Lifecycle Management) Article 14. Agency shall provide necessary actions and implement them in order not to impair necessary handling in accordance with classifications of information and handling restrictions in each stage of creating, obtaining, using, saving, providing, carrying, sending and deleting information. (Information Handling Area) Article 15. Agency shall appropriately define the area scope in which measures need to be implemented for the facility and environment, which is under management of its own organization such as government offices managed by them, facilities borrowed by the organization other than own organizations and so forth, decide the measures specific to the characteristics and implement them. (Outsourcing) Article 16. Agency shall specify necessary actions and implement them when information processing task is outsourced. 2. When outsourcing task (excluding using external service on general terms and conditions), implementation of necessary information security measures shall be the criteria to select outsourcing parties including countermeasures against information leakage and management so that unintended change can’t be made to the information systems and Agencies shall include it in the specification content. 3. Agency shall not handle confidential information by using the external service on general terms and conditions. 4. In order to procure safe devices, Agency shall establish the selection criteria including appropriate handling to supply chain risks that countermeasures are not provided against known vulnerability, insecure technology is used, malware is embedded and so forth.

Select target paragraph3