information system and information of Agency’s own. The same shall apply hereinafter) in
light of characteristics of its own agency. Agency can decide the name of Agency’s basic
policy and Agency’s own standards (hereinafter referred to as “Agency’s policy”) by
themselves.
2.
Agency’s basic policy shall provide a basic idea on information security including purpose
of information security measures and target scopes to ensure information security.
3. The standards shall be stipulated to enable information security measures that are the same
as or higher than the Common Standards for Information Security Measures for Government
Agencies and Related Agencies (hereinafter referred to as the “Common Standards”) that are
separately defined.
4.
National administrative organs shall require that the Incorporated Administrative Agencies
and Designated Corporations under their control refer to the organ’s own policies when said
agencies and corporations establish policies as needed.
5.
Incorporated Administrative Agencies and Designated Corporations shall comply with the
requirements from the previous paragraph.
6.
Agency shall evaluate and review Agency’s policy by considering the evaluation result of the
Paragraph 1 of the previous article.
Chapter 3.
Basic Measures of Information Security Measures for Government Agencies and
Related Agencies
(Management System)
Article 5. Agency shall establish organization and system to implement information security
measures.
2.
Agency shall designate chief information security officer.
3. The chief information security officer shall organize information security committee with
function of discussing Agency’s own standards and assign a chairperson and members of the
committee.
4. The chief information security officer directs and is responsible for tasks associated with
information security measures at Agency provided by this model.
5. The chief information security officer can delegate their own responsible tasks defined by the
Common Standards to a responsible person defined by the Common Standards.
(Promotion Plan of Measures)
Article 6. The chief information security officer shall establish the plan (hereinafter referred to
as “promotion plan of measures”) to comprehensively promote information security measures