II. Items that Should Ideally be Prescribed in the Safety Principles direction of information security measures, as well as present the commitment of the management toward fulfilling the requirements of stakeholders related to the information security measures and continual improvements on the information security measures. The information security policies are communicated within the organization, and can also be obtained by external stakeholders where necessary. In addition to checking, at regular intervals, that the information security policies are relevant and effective, it is also necessary to check the policies in the event of any significant changes to the situation surrounding the organization. (3) Assignment of Responsibilities and Authority for the Roles in the Organization In order to ensure the firm implementation of information security measures, the management of CI operators decide on the departments and employees that will take on the role of promoting information security measures. At the same time, the management also assigns the corresponding responsibilities and authority within the appropriate scope, communicates the assignment to all members of the organization, and ensures that all employees have the same recognition of these responsibilities and authority. In doing so, it is particularly important to clearly identify the risk owners from among the personnel who have the role of promoting information security measures. These risk owners have the responsibility of monitoring and addressing the risks identified through risk assessments, and are required to provide clear explanations and take responsibility for the contents of their explanations. Besides, it is also expected to secure human resources who are able to connect the management with the practitioners, plan the information security measures based on the business strategy, and lead and direct the practitioners (CISO, etc.). Furthermore, in cases where the organization has an environment in which control systems are operated, they are expected to consider the need for human resources for departments related to OT4 to prevent and recover from CISs outages caused by cyberattacks or other reasons. In addition to the abovementioned, the following roles are also possible:  Responsible for the collection of threat information, etc. and the sharing of information with stakeholders  Responsible for the management of security incidents (CSIRT, etc.)  Responsible for the execution of contingency plans and business continuity plans 4 In this guideline, it refers to operation technology such as control systems that make use of information and communication technology (IT). 9

Select target paragraph3