Introduction
(Executive Summary of This Guideline)
Positioning and Structure of This Guideline
Critical infrastructure (CI) operators have the social responsibilities of providing CI services (CISs)
safely and continuously, and it is important to put in place the necessary measures based on the “Concept
of Mission Assurance” set out in the Cybersecurity Policy for Critical Infrastructure Protection (4th
Edition). Specifically, this involves making the necessary preparations for risks related to information
security and implementing the appropriate countermeasures in the event of an emergency. The matters
that should be taken into consideration in such situations should ideally be set out in Safety Principles,
which provide the standard for the operation of businesses by CI operators. This guideline organizes and
sets out the items that should ideally be provided for in such safety principles.
The items set out in this guideline are information security measures that follow the PDCA cycle. The
formulation of these items takes into consideration the Information security Management System
(ISMS), an international standard for information security, as well as information security standards
related to CI sectors, such as NIST’s Framework for Improving Critical Infrastructure Cybersecurity and
CSMS Certification Criteria. This guideline is structured in a way that allows it to comprehensively cover
all the main standards related to CI.
Matters of Importance when Implementing the PDCA Cycle for Information security Measures
Actions required of the management
The management needs to recognize that information security risks have an impact on business
operations that are based on the “Concept of Mission Assurance,” adding a level of uncertainty to such
operations; hence, the management has to provide instructions on the implementation of the necessary
information security risk assessments in order to decide on the approach for dealing with such risks.
Furthermore, in promoting the PDCA cycle for information security measures, it should strive to
continuously secure and appropriately allocate the necessary resources (budget, systems, human
resources, etc.). In addition, the management needs to periodically verify the effects and impact that the
results of addressing information security risks have on the business, and to make decisions on the
necessity of reviewing the strategy for addressing information security risks. With regard to these
initiatives, it should refer to materials such as the Approaches to Cybersecurity for Corporate
Management and the Cybersecurity Management Guidelines.
Periodic implementation of information security risk assessment
Information security risks are constantly changing as a result of factors such as the occurrence of new
threats and the new discovery of technological vulnerabilities, and changes in the business environment
surrounding CI operators and new demands from interested parties. In view of that, there is a need to
periodically implement risk assessments while taking reference from materials such as the Risk
Assessment Guide Based on the Concept of Mission Assurance in Critical Infrastructure, and to reassess
the impact that changes in information security risk have on the safe and sustainable provision of CISs.
Formulation of response plans based on the characteristics of cyberattacks
During the occurrence of a cyberattack, which is one of the events that give rise to CISs outages,
formulate a contingency plan beforehand, which sets out concrete policies and procedures of initial
response among other details, in order to realize swiftly and appropriate initial response. At the same
time, formulate a business continuity plan, which sets out the policies and procedures, among other
details, of measures for recovery from the CISs outages that result from the cyberattack. In the
formulation of these response plans, take into consideration the Characteristics of Cyberattack Risks as
well as Considerations for Response and Countermeasures provided in this guideline.
Making provisions for swiftly and flexible incident readiness
In addition to addressing information security risks from a medium- to long-term perspective based on
the PDCA cycle, there is also a need to ensure readiness, which enables timely and flexible response to
any indications of a cyberattack that are detected on a daily basis through monitoring mechanisms built
by CI operators.