II. Items that Should Ideally be Prescribed in the Safety Principles 4.1.3. The “Plan” Perspective (1) Information Security Risk Assessment In order to appropriately manage the information security risks that have an impact on the safe and continuous provision of CISs, conduct information security risk assessments by following the procedures set out below. (i) Taking into account the constantly changing situation surrounding the organization and the needs of stakeholders, clearly define the scope and standards of the business that are necessary for providing CISs. At the same time, identify the management resources, such as information systems, that are necessary for the execution of these business. As a part of this process, analyze the organization’s risk attitude 5 and risk tolerance.6 (ii) Identify the information security risks for management resources such as information systems (risk identification). (iii) While giving consideration to the risk attitude and risk tolerance, utilize the risk criteria that have been formulated with evaluating the degree of impact that the consequences of an event has on services and the business and the probability for the occurrence of an event being the axis, and verify the magnitude of the risks identified (risk analysis). (iv) In addition to identifying risks of a magnitude that is larger than the risk criteria, identify risks that are subjected to risk treatment in consideration of individual factors (risk evaluation). * The Risk Assessment Guide based on the Concept of Mission Assurance in Critical Infrastructure issued by the National center of Incident readiness and Strategy for Cybersecurity (NISC) sets out the perspective of risk assessment based on the concept of mission assurance as well as details on the abovementioned procedures. Please refer to the Guide alongside with this guideline. * Depending on the business characteristics and environment of the organization, there may also be cases where applying methods from other guidebooks, etc. is more effective. For example, the Security Risk Assessment Guide for Industrial Control Systems published by the Information-Technology Promotion Agency (IPA) sets out the concrete work procedures for effective security measures as well as risk analysis methods that combine asset-based risk assessment and business risk-based (scenario-based) risk assessment methods. 5 Refers to an organization's efforts to conduct risk assessments, and ultimately retain, take, or avoid the risks. To clarify risk attitude, clarify the degree to which CI operators take risks in the operation of their businesses. For example, "The occurrence of CISs outages accompanying the decline of service levels below 20% is to be three times or less per year." 6 Refers to the degree of residual risk (a risk that remains after the risk treatment) that the organization or stakeholder is prepared to take on in order to achieve their objectives. Specified, for example, as, "The occurrence of CISs outages accompanying the decline of service levels above 50% is to be once a year or less." 11

Select target paragraph3