II. Items that Should Ideally be Prescribed in the Safety Principles Verify the threat information that is provided regularly by information security related agencies and information on the analysis and countermeasures on the threat information. In cases where the threat information is assessed to have a high degree of urgency, conduct an information security risk assessment urgently, and decide on the need for additional risk treatment measures. (D) Participation in Information Sharing Activities for Sectors with a High Level of Expertise With cyberattackers constantly coming up with new means to carry out cyberattacks, the possibility for high-level cyberattacks that target specific CI sectors is also conceivable. Hence, one of the countermeasures is to participate in information sharing activities for sectors with a high level of expertise, such as ISAC,13 and to apply the information collected through these activities to daily efforts toward risk treatment. (2) Addressing CISs Outages (A) Formulation of Contingency Plans and Business Continuity Plans in Preparation for Cyberattacks In the event of CISs outages, in addition to securing safety, it is also necessary to restore conditions to an acceptable level within an acceptable timeframe. As such, it is important to ensure incident readiness in preparation against the occurrence of CISs outages. In view of that, formulate a contingency plan,14 which sets out the policies for initial response (response during an emergency), and the business continuity plan,15 which sets out the policies for recovery measures aimed at ensuring continuity of the business (or formulate plans that sets out the same policies as these plans), and establish the necessary organizational systems to execute these plans. In particular, when formulating or revising contingency plans and business continuity plans with the aim of ensuring readiness against cyberattacks, which is one of the events that can lead to CISs outages, it is recommended to refer to Annex 3: Characteristics of Cyberattack Risks Associated with Incident Readiness, and Matters to Be Considered in the Response and Countermeasures. CI operators that have already prepared a business continuity plan should also draw up a separate plan aimed at achieving complete restoration from the target restoration level to normal service level (business recovery plan). 13 Abbreviation for Information Sharing and Analysis Center. The ICT-ISAC JAPAN includes ICT-ISAC, Financials ISAC Japan, and JEISAC, among others. 14 In the 4th Cybersecurity Policy, it refers to plans that specifically set out beforehand, from the implementation aspect, the policies, procedures, and readiness on the initial response (emergency response) that should be taken by the management and employees after the occurrence of CISs outages in a CI operator, or after identifying the possibility for the occurrence of CISs outages. 15 In the 4th Cybersecurity Policy, it refers to plans that aim to restore CISs that have been impacted by CISs outages in a CI operator to an acceptable level within an acceptable timeframe, based on the concept of mission assurance, and which sets out beforehand the target level, order of priority, and other policies, procedures, and readiness toward recovery. 22

Select target paragraph3