II. Items that Should Ideally be Prescribed in the Safety Principles Furthermore, in addressing information security risks, the management is expected to recognize the “Responsibility of Top Management at CI Operators” prescribed below, while taking reference from the Approaches to Cybersecurity for Corporate Management 2 and the Cybersecurity Management Guidelines.3 【Responsibility of Top Management at CI Operators】  Ensuring information security is a responsibility that should be fulfilled by the management; therefore, commit themselves to exerting leadership and putting in place information security measures based on the concept of mission assurance.  Recognize that the company’s activities contribute to the development of society as a whole, and put in place security measures that include the supply-chain (business partners, subsidiaries, and affiliated companies).  From the perspective of fostering trust and a sense of security among stakeholders with regard to information security, take steps such as disclosing information about a posture of readiness for information security measures during normal times and responses when an incident occurs.  In addition to accurately collecting the necessary information for each of the abovementioned efforts, continuously secure the necessary management resources such as budget, systems, and human resources, and allocate them appropriately based on a risk-based approach.  Taking into account the effect that responses to information security risks have on the business and the verification results of the impact, make decisions on the need to review further strategies for addressing information security risks and the contents, at the Board of Directors’ meetings and other important management meetings. * Partial revision and addition of items necessary for the formulation of this guideline, based on the contents set out in the 4th Cybersecurity Policy. (2) Formulation of Information security Policies CI operators formulate information security policies, which are official documents for internal and external parties. In the information security policies, CI operators, who have the social responsibilities of ensuring the safe and continuous provision of CISs, set out the purposes and 2 Compiled by the Working Group for Corporate Management with a Security Mindset, established under the Human Resources Expert Panel for Dissemination and Enlightenment (decided by the Cybersecurity Strategic Headquarters on 10 February 2015). It presents the basic stance on cybersecurity for corporate management. 3 From the perspective of protecting the company from cyberattacks, this summarizes the principles that managers need to be aware of, and the important items that should be issued as instructions to officers in charge (CISO, etc.) who are responsible for implementing information security measures. Formulated by the Ministry of Economy, Trade, and Industry (METI) and Information-technology Promotion Agency (IPA). 8

Select target paragraph3