II. Items that Should Ideally be Prescribed in the Safety Principles instant messaging services, to transmit important information associated with the provision of CISs, organize in advance the policies and procedures related to ensuring security, such as confidentiality and integrity. At the same time, work to reach an agreement with the stakeholders who are the recipient party in these transmissions regarding the policies and procedures. (H) System Acquisition, Development, and Maintenance ● Acquisition of Systems Based on Information Security Requirements When acquiring or developing new information systems associated with the provision of CISs, and when improving existing information systems, conduct a review that incorporates requirements for information security among the requirements for the system, based on the concept of “security by design.”12 (Where necessary, also conduct a review that incorporates requirements from the perspective of the aforementioned HSE.) As third-party authentication systems that comply with international standards on the security of information systems are also available depending on the CI sector, consider also utilizing authenticated information systems where necessary. Establish policies, procedures, and environments to realize the development or building of systems that take information security into consideration. In particular, when checking the acceptance of the information system, in addition to checking the requirements related to information security, also consider the need to conduct a vulnerability diagnostic test corresponding to the level of importance of the information system. Furthermore, when outsourcing system development, periodically check with the contractor on the status of compliance with development policies that take information security into consideration. (I) Supplier Relations ● Information Security in Supplier Relations In cases where facilities such as information systems that are associated with the provision of CISs, as well as their operation, are replaced by services provided by external suppliers (for example, suppliers of IT services and the components of IT infrastructure), organize information security requirements to reduce the risk of access to the assets of CI operators by suppliers and their subcontractors, and obtain the agreement of the suppliers to these requirements in advance. In cases where different levels of suppliers are present, improve information security in the supply-chain by ensuring that a certain supplier expects the supplier at the level below them to comply with the same requirements. 12 Refers to policies aimed at ensuring information security from the planning and design phases. 18

Select target paragraph3