in aligning with evaluation results of Paragraph 1 of Article 3. 2. Agency shall implement information security measures based on promotion plan of measure. 3. The chief information security officer shall evaluate implementation status of the previous paragraph and review the promotion plan of measures by considering any critical changes on information security. (Exceptional Actions) Article 7. Agency shall decide the procedure and employees in charge for request, examination and approval required for applying exceptional actions for implementation of information security measures provided by Agency’s policy. (Education) Article 8. Agency shall be in charge of education for information security so that employees can implement information security measures defined by the Agency’s policy with awareness. (Handling Information Security Incident) Article 9. Agency shall establish an appropriate system, decide necessary actions and implement them to address information security incidents (information security incident in JIS Q 27000:2014. The same shall apply hereinafter). 2. Employees who recognize any possibility of information security incident shall report to the points of contact that is provided by Agency’s policy. 3. Responsible person who are defined by Agency’s policy shall take necessary actions when an information security incident is reported or recognized. (Self-check) Article 10. Agency shall conduct self-check for information security measures. (Audit) Article 11. Agency shall conduct information security audits to confirm whether Agency’s own standards comply with this model and Common Standards and whether the actual operations comply with Agency’s own standards. (Classification of Information) Article 12. Agency shall determine the classification of information to handle with confidentiality, integrity and availability points of view. 2. Agency shall indicate the applied classification of information that is defined by the previous

Select target paragraph3