II. Items that Should Ideally be Prescribed in the Safety Principles For the safe and continuous provision of CISs, depending on the CI sectors and characteristics of the services, it is desirable to identify the risks from the perspective of HSE,7 etc. in addition to information security risks, and to conduct an analysis and evaluation. The HSE perspective can possibly cover, for example, ensuring occupational health and safety for the employees who are responsible for the provision of CISs, ensuring the health and safety of CISs users, and reducing the environmental burden that accompanies the provision of CISs. It is also necessary to manage risks that were not identified as subjects for risk treatment in the abovementioned methods. In cases where the said risks are managed under the responsibility of the department in charge, it is desirable to establish a system that enables the timely verification of the management status (whether or not security management measures have been introduced, etc.) in each department. (2) Decision on Information Security Risk Treatment Decide on the concrete method for the information security risk treatment that have been identified through the risk assessments. The options of risk treatment include mitigation, 8 avoidance,9 transfer (sharing),10 and retention (acceptance).11 Taking into consideration the degree of impact that the consequences of an event has on the business and the probability for the occurrence of an event, select the option that is perceived as the most appropriate. Next, decide on the security management measures as a means for realizing the selected method for the risk treatment. As a reference, points (A) Security for Human Resources (Outsourcing) to (J) Information Security Incident Management below present the security management measures that are expected to be incorporated into the safety principles, from the perspective of critical infrastructure protection (CIP). The ISO/IEC 27000 Family of Standards, Framework for Improving Critical Infrastructure Cybersecurity (NIST), and CSMS Certification Criteria (IEC62443-2-1) are also some of the references that provide security management measures. In addition to these standards, it is desirable to also continuously check if any security management measures that are necessary to the organization have been overlooked, referring to examples of the introduction of security management measures by CI operators in the same industry. (A) Security for Human Resources (Outsourcing) 7 Refers to health, safety, and environment. In the CSMS Certification Criteria (Ver. 2.0), which is a cybersecurity management system for industrial automation and control systems, the integration of the results of the assessment of physical risks, with the results of the assessment of HSE risks and the results of cybersecurity risk assessments, is required. 8 Applying appropriate management measures to risks. 9 Avoiding risks by deciding not to commence or continue with activities that give rise to risks. 10 Sharing all or part of the risks with one or more other parties. 11 Retaining (accepting) risks through decision-making based on information. 12

Select target paragraph3