II. Items that Should Ideally be Prescribed in the Safety Principles Joint exercises and training include the cross-sectoral exercises organized by NISC, as well as other programs organized by stakeholders such as responsible ministries for CIP and information security related agencies. 4.3. The “Check” Perspective 4.3.1. The Evaluation Perspective (1) Monitoring and Auditing Ensure that the respective initiatives are progressing as planned by monitoring the progress toward the achievement of goals that have been set based on the information security policy, progress of the plans for information security risk treatment, and the progress of education and training aimed at improving awareness of information security. Risk owners should also periodically monitor changes in the risks accompanying in the introduction and operation of security management measures (such as changes in the frequency of occurrence of events, changes in the degree of impact that the consequences of events have, etc.). In addition to visualizing the changes in the status of individual risks, it is also expected that monitoring allows them to grasp the changes to the risk status for the organization as a whole. Furthermore, check that periodical internal audits are conducted (in cases where it is difficult to do so, risk owners should conduct self-inspections at the very least), PDCA cycle for information security measures is built appropriately based on information security policies, and it is maintained in an effective state. In addition to putting effort into nurturing the internal audit personnel necessary for this, it is also expected to check the situation where necessary with the support of external parties who possess advanced expertise.17 (2) Review by the Management The management of CI operators make use of system audits and other resources, periodically check the status of information security measures for the organization, and identify areas where improvements or reviews are necessary. In doing so, in addition to the results of monitoring and audits conducted, also verify the status of measures taken based on the previous review results, changes in the external and internal environments, and feedback from stakeholders. Document the review results, check the current status of the resources needed for improvements and reviews (human resources, budget, etc.), and issue instructions for improvements and In METI’s Information Security Audit System, the Registry System for ledger of Information Security Audit Firms, which registers the entities engaged in information security audits (audit companies, information security vendors, system vendors, information security specialist companies, system audit companies, etc.), is prepared and published. 17 24

Select target paragraph3