II. Items that Should Ideally be Prescribed in the Safety Principles ● Management of Service Provision by Suppliers To ensure compliance with the information security requirements that have been agreed upon, constantly monitor the provision of services by suppliers, and conduct reviews and audits on reports drawn up by the suppliers. Due to the need to reassess risks, manage changes in the services provided by suppliers. (J) Information Security Incident Management ●Management and Improvement of Information Security Incidents To respond promptly and effectively to information security incidents that have an impact on the safe and continuous provision of CISs, define who the responsible managers of incidents are, and establish procedures such as reporting to internal and external parties and collecting evidence. In addition, establish systems that enable the application of knowledge gained through incident responses toward ensuring readiness for future incidents. (3) Formulation of Individual Policies for Security Management Measures Consolidate standards, such as actions that should be complied with and decisions in individual security management measures that have been decided upon during the process of addressing information security risks, as separate policies (for example, access control policy, information classification policy, etc.), and transmit these within the organization. Where necessary, also communicate these to contractors. In the same way as information security policies, verify the validity and effectiveness of the contents of separate policies at regular intervals, and check them in the event that any significant environmental changes have occurred. (4) Formulation of Plans for Addressing Information Security Risks Formulate plans for addressing information security risks, which set out goals based on the contents of the information security policies and the criteria for determining the status of achievement of the goals, as well as implementation items and schedule toward the introduction of the security management measures that have been decided upon. 4.1.4. The “Support” Perspective (1) Securing Resources In promoting the PDCA cycle for information security measures, or in other words, the establishment, implementation, maintenance, and continual improvement of the PDCA cycle, 19

Select target paragraph3