II. Items that Should Ideally be Prescribed in the Safety Principles
II. Items That Should Ideally Be Prescribed in the Safety Principles
1. Purpose of Formulating the Safety Principles
Based on the concept of mission assurance, the safety principles set out the need to implement
the PDCA cycle for information security measures in reference to the contents of the safety
principles, in order to eliminate, as far as possible, the occurrence of CISs outages in CI that
have an impact on the safe and continuous provision of CISs, as well as to ensure their swift
recovery in the occurrence of such an event.
2. Applicable Scope
Based on the examples of applicable CI provided in “Annex 1: Applicable CI Operators and
Examples of Critical Information Systems,” as well as the CISs (including procedures),
examples of CISs outages, and service maintenance levels provided in “Annex 2: Explanation
of CISs and Examples of CISs Outages,” the applicable scope for the items to be prescribed in
the safety principles shall be listed.
3. Roles of Stakeholders
With regard to the stakeholders of the CI sectors within the scope of the safety principles (*refer
to the Definitions and Glossary), provide a comprehensive and specific list, and clearly define
the roles of each stakeholder in relation to the respective information security measures. In
particular, with regard to the role of CI operators, the efforts of the management should also be
included, taking reference from the section “Responsibility of Top Management” in the 4th
Cybersecurity Policy and other materials.
4. Measures
In light of the fact that CI operators have the social responsibility of realizing the safe and
continuous provision of CISs, review the adoption or rejection of the measure items listed in
items 4.1 to 4.4, in accordance with the PDCA cycle for information security measures.
The PDCA cycle for information security measures typically follows the flow of: Plan, which
involves identifying the measures based on the results of analysis; Do, which involves moving
to the implementation phase, and after a certain period of time; Check, which involves
evaluating the need to review the measures, and; Act, which involves putting in place
improvements. However, in actual operations, depending on the results of the monitoring and
detection carried out in the “Do” phase, it is necessary to be aware of the possible need to
respond actively, such as by reviewing the contents of the measures urgently.
In addition, list the references that set out concrete examples of each measure in Annex 4:
References for Concrete Examples of Measure Items. This provides a source of reference during
6