II. Items that Should Ideally be Prescribed in the Safety Principles that status. From the perspective of realizing the safe and continuous provision of CISs across the entire CI sector that the organization belongs to, it is also effective to exchange opinions with other stakeholders, including other CI operators and responsible ministries for CIP and agencies with jurisdiction, on the respective roles and the sharing of responsibility, and structure of information sharing and reporting. 4.2. The “Do” Perspective 4.2.1. The Operational Perspective (1) Introduction and Operation of Information Security Measures (A) The Introduction of Security Management Measures, and Establishment and Execution of Operational Processes Based on the plans for addressing information security risks, move forward on the introduction of the security management measures that have been decided upon in the information security risk treatment, and establish and execute processes to ensure the effective and secure operation of these measures. (B) Detection of Events That Lead to CISs Outages, and Making Prompt Decisions to Tackle the Problem In addition to building mechanisms that are capable of the early detection of events that could lead to CISs outages (such as cyberattacks and the anomalous condition of information systems) by grasping the baseline for data that shows the operational status of information systems related to the provision of CISs and combining multiple monitoring results such as alerts and logs, continue sharing events with the relevant departments, etc. following detection, and establish operational processes such as triage (conducting an impact analysis of events such as cyberattacks, and assigning degree of priority for responses). Through the aforementioned monitoring and detection systems, in situations where specific signs of cyberattack have been identified, it is important to make a prompt decision on the advisability of taking action against the cyberattack through security management measures that have already been introduced (deployment of monitoring functions). At the same time, corresponding to the results of the decision, it is also important to implement dynamic response measures, such as by reviewing the security management measures that have already been introduced (including tuning work for the various devices), or by introducing new security management measures. (C) Threat Information, Its Analysis, and Verification of Information on Countermeasures 21

Select target paragraph3