paragraph by labeling etc. when information is provided, carried and sent across the Agencies.
(Handling Restriction on Information)
Article 13.
Agency shall stipulate handling restrictions according to classifications of
information.
2.
Agency shall provide the handling restriction that is defined by the previous paragraph on the
information to be handled.
3.
Agency shall indicate the handling restriction of information when information is provided,
carried and sent across the Agencies.
(Information Lifecycle Management)
Article 14.
Agency shall provide necessary actions and implement them in order not to impair
necessary handling in accordance with classifications of information and handling restrictions
in each stage of creating, obtaining, using, saving, providing, carrying, sending and deleting
information.
(Information Handling Area)
Article 15.
Agency shall appropriately define the area scope in which measures need to be
implemented for the facility and environment, which is under management of its own
organization such as government offices managed by them, facilities borrowed by the
organization other than own organizations and so forth, decide the measures specific to the
characteristics and implement them.
(Outsourcing)
Article 16.
Agency shall specify necessary actions and implement them when information
processing task is outsourced.
2.
When outsourcing task (excluding using external service on general terms and conditions),
implementation of necessary information security measures shall be the criteria to select
outsourcing parties including countermeasures against information leakage and management
so that unintended change can’t be made to the information systems and Agencies shall
include it in the specification content.
3.
Agency shall not handle confidential information by using the external service on general
terms and conditions.
4.
In order to procure safe devices, Agency shall establish the selection criteria including
appropriate handling to supply chain risks that countermeasures are not provided against
known vulnerability, insecure technology is used, malware is embedded and so forth.