II. Items that Should Ideally be Prescribed in the Safety Principles ● Matters to Be Addressed before Outsourcing (Selection/Contract Conditions) When selecting the external contractor for tasks that are related to CISs, consider the categories of information that will be accessed as well as the risks identified, in addition to the business requirements. In the outsourcing agreement between the organization and the contractor, incorporate the contractor’s responsibility for implementing information security measures that fulfill the information security requirements of the organization, the responsibility for providing education and training to raise the awareness of employees, and the responsibility and tasks associated with effective information security even after the end of the contract. As there may be cases where the review of contract wording is necessary depending on the results of the risk assessments that have been implemented continuously, it is desirable for the security department or legal department to regularly establish spaces for the exchange of information. ● Matters to Be Addressed during the Contract Period To ensure the steady execution of information security requirements by the contractor, regularly verify the implementation status of measures by the contractor, and request for the necessary improvements to be put in place. (B) Asset Management ● Responsibility for Assets After specifying assets such as information systems, software, and information that are associated with the provision of CISs, draw up an asset record that clearly sets out the parties responsible for the management of and the usage limit of each asset (scope within which use is permitted), and maintain and manage this record. Along with this, also draw up network configuration diagrams, data flow charts, and other figures. In cases where facilities such as information systems and their operation are replaced by services provided by an external supplier (for example, a supplier of IT services or of the components of IT infrastructure), draw up a list of services, and maintain and manage this list. ● Categories of Information and the Handling of Information With regard to the information handled by CI operators, corresponding to the level of importance, legal requirements, impact on sense of security among citizens, and other factors, assign ratings to the information from the perspective of confidentiality, integrity, and availability, and label the information medium (paper, electronic). 13

Select target paragraph3