II. Items that Should Ideally be Prescribed in the Safety Principles
In addition, manage the logs to prevent intentional tampering or deletion by malicious persons
or malware. At the same time, check for the presence of any fraudulent behavior in relation to
the logs through periodic checks corresponding to the nature of the logs.
● Management of Operation Software
Software that is used in information systems associated with the provision of CISs is exposed
to the potential of attacks that exploit any vulnerable configuration settings. As such, grasp and
understand, as far as possible, the individual settings, and strive to ensure safety.
In the event of the occurrence of CISs outages or when the signs of a cyberattack are identified,
systematically implement updates to versions that are eligible for support, so that it is possible
to receive prompt support from a software vendor. In cases where it is difficult to update to a
version that is eligible for support, put in place complementary measures to prevent CISs
outages and cyberattacks.
● Management of Technological Vulnerability
Collect, on a regular basis, information on technological vulnerabilities of information systems
provided by information security related agencies, and check for any impact on information
systems that are in operation. Periodical implementation of scans for vulnerabilities is also
expected.
To address technological vulnerabilities, establish work policies and contents in advance, taking
into account the need to check for the impact of applying patches on existing information
systems. For example, even in situations that call for applying patches urgently, organize the
verification test items that should be carried out at the minimum, and implement these tests. In
cases where applying patches is difficult even in the event of an emergency, put in place
complementary measures such as strengthening the monitoring of information systems.
(G) Security of Communications
● Management of Network Security
From the perspective of protecting the confidentiality and integrity of information handled by
information systems that are associated with the provision of CISs, ensure strong network
security through means such as using dedicated lines and encryption technology, segregation
of networks, maintaining logs, and detecting cyberattacks through monitoring.
● Transmission of Information
When using means of communication such as e-mail, electronic data interchange (EDI), and
17