Abstract
Companies which have achieved success by utilizing internet are actively working on the development of platform business model for taking advantage of the economic efficiency of network and its size. However, as the size of network has expanded, the effect of information security incident such as personal information leakage on corporate management has significantly increased. In this paper, the example of the expansion of information sharing platform business and the case of past information security accidents are studied, and the importance of risk management and information security management in the planning phase of program (scheme model) for companies to work on the development and operation project of platform is reconfirmed, and, as a part of an approach to IS027001, the framework for top and middle management of the company to understand the presence of risk in a practical manner is suggested.