(Preparation of Document and Ledger on Information System) Article 17. Agency shall prepare document and inventory of competent information systems. (Ensuring Information Security for Overall Information System Lifecycle) Article 18. Agency shall stipulate actions to ensure information security in each stage to plan, procure/construct, operate/maintain, renew/dispose and review competent information systems and implement them. (Operational Continuity Plan of Information System) Article 19. Agency shall consider information security measures in emergency cases when preparing the plan for continuously operating of competent information system (it is hereinafter referred to as “operational continuity plan”). 2. When training is provided for operational continuity plan, Agency shall confirm whether it is possible to operate information security measures in emergency cases or not. (Encryption and Digital Signature) Article 20. Agency shall stipulate necessary actions for use of encryption and digital signature in their own organizations and implement them. (Provision of Administrative Service Using the Internet) Article 21. When an administrative service is provided by using the internet, Agency shall stipulate necessary actions to prevent any conduct that leads lowering information security level of user devices and implement them. (Use of Information System) Article 22. When an information system is used, Agency shall stipulate necessary actions that need to be implemented by employees and implement them to ensure information security. (Entrustment to the Common Standards) Article 23. Common Standards stipulate the requirements needed for the implementation of this model other than the provisions defined by this model. Supplementary provisions Common Model of Information Security Measures for Government Agencies (Information Security Policy Council decision on 21st April 2011) is abolished.

Select target paragraph3