II. Items that Should Ideally be Prescribed in the Safety Principles the adoption of each measure item, where necessary. 4.1. The “Plan” Perspective 4.1.1. Perspective of the Organization’s Situation (1) Understanding the External and Internal Environments Organize information about the condition of the external environment surrounding CI operators (politics, economy, society, etc.) to which the impact on the necessary capacity for the safe and continuous provision of CISs is assumed, and the internal environment of CI operators (organizational structure, strategy, capabilities, etc.), including the situation in the near future. When doing so, it is particularly important to get an accurate grasp of the dependency between the supply-chain (suppliers, contractors, etc.) and one’s own organization, by extracting and analyzing the various tasks associated with the provision of CISs. (2) Understanding the Requirements of Stakeholders Organize the requirements of stakeholders, customers, suppliers, contractors, etc. in relation to the information security measures put in place by CI operators (including initial response and recovery treatment during the occurrence of CISs outages). The requirements include tasks stipulated by contracts or the relevant laws of the respective business domains, and restrictions prescribed by suppliers or contractors. The organized information, including the aforementioned status of the external and internal environments, is an element that should be taken into consideration when formulating information security policies and implementing information security risk assessments. From the perspective of raising awareness of the information security measures among employees (including staff of administrative organizations), the organized contents should be shared across the entire organization. 4.1.2. The “Leadership” Perspective (1) Commitment of the Management The management of CI operators evaluates information security risks1 and declares, within and outside the organization, the appropriate response to these risks, in order to realize business management based on the “Concept of Mission Assurance,” which is required of CI operators. In making the declaration, the information security policies set out in item (2) on the following page should be utilized. 1 Refers to the risks identified by CI operators based on CISs outages caused by cyberattacks or other causes, that is, the consequences of events related to information assets (such as information, information systems, and control systems that make use of IT) that are owned, used or managed for the purpose of executing the businesses necessary for the provision of their services. 7

Select target paragraph3