I. Purposes and Positioning implementation of information security measures that are necessary or desirable, corresponding to the characteristics of CI sectors, it is also critical that CI operators continuously improve on information security measures by following the PDCA cycle, while capturing changes in the business environment and other factors. 2. What Are “Safety Principles?” CI operators engage in business in accordance with the relevant standards, under the legal systems that are related to their respective business domains. Based on the above fact, this guideline names documents that serve as standards or references for the decisions and actions taken by CI operators as “Safety Principles.” Safety Principles are classified into the following four categories. [1] Mandatory standards that are stipulated by the government based on the relevant laws [2] Recommended standards and guidelines that are stipulated by the government in accordance with the relevant laws [3] Industry standards and guidelines that cut across industries, stipulated by industrial organizations with the aim of fulfilling the expectations of the citizens and the relevant laws [4] Internal regulations, etc. stipulated by CI operators with the aim of fulfilling the expectations of citizens, users, and the relevant laws *Note that documents that correspond to Safety Principles are not limited to documents drawn up for the purpose of ensuring safety. In order to ensure the firm implementation of information security measures that are necessary or desirable for CI operators, it is required that items and standards related to information security measures be clearly presented in these Safety Principles. In short, by referring to the abovementioned [1] to [4], all parties that are involved in the CI business are expected to be able to understand what they should do, and to what extent they should do these things. 3. Positioning of the Guideline The aim of this guideline is to support the formulation and revision of Safety Principles by organizing and setting out items that should ideally be provided for in Safety Principles, from the perspective of realizing the safe and sustainable provision of CISs, taking into account the concept of mission assurance in CI. For this reason, this guideline sets out items for information security measures in accordance with the PDCA cycle, to enable easy referencing for CI operators when they are engaged in voluntary initiatives or continual improvements. (Figure 1 provides an overall image of the information security measures of CI in this guideline.) 2

Select target paragraph3