II. Items that Should Ideally be Prescribed in the Safety Principles
the adoption of each measure item, where necessary.
4.1. The “Plan” Perspective
4.1.1. Perspective of the Organization’s Situation
(1) Understanding the External and Internal Environments
Organize information about the condition of the external environment surrounding CI operators
(politics, economy, society, etc.) to which the impact on the necessary capacity for the safe and
continuous provision of CISs is assumed, and the internal environment of CI operators
(organizational structure, strategy, capabilities, etc.), including the situation in the near future.
When doing so, it is particularly important to get an accurate grasp of the dependency between
the supply-chain (suppliers, contractors, etc.) and one’s own organization, by extracting and
analyzing the various tasks associated with the provision of CISs.
(2) Understanding the Requirements of Stakeholders
Organize the requirements of stakeholders, customers, suppliers, contractors, etc. in relation to
the information security measures put in place by CI operators (including initial response and
recovery treatment during the occurrence of CISs outages). The requirements include tasks
stipulated by contracts or the relevant laws of the respective business domains, and restrictions
prescribed by suppliers or contractors.
The organized information, including the aforementioned status of the external and internal
environments, is an element that should be taken into consideration when formulating
information security policies and implementing information security risk assessments. From
the perspective of raising awareness of the information security measures among employees
(including staff of administrative organizations), the organized contents should be shared across
the entire organization.
4.1.2. The “Leadership” Perspective
(1) Commitment of the Management
The management of CI operators evaluates information security risks1 and declares, within and
outside the organization, the appropriate response to these risks, in order to realize business
management based on the “Concept of Mission Assurance,” which is required of CI operators.
In making the declaration, the information security policies set out in item (2) on the following
page should be utilized.
1
Refers to the risks identified by CI operators based on CISs outages caused by cyberattacks or other causes, that is, the consequences of
events related to information assets (such as information, information systems, and control systems that make use of IT) that are owned, used
or managed for the purpose of executing the businesses necessary for the provision of their services.
7