Definitions / Glossaries Definitions / Glossaries CEPTOAR Capability for Engineering of Protection, Technical Operation, Analysis and Response; Functions which provide information sharing and analysis at CI operators, and organizations which serve as these functions The council composed of representatives of each CEPTOAR which carries out information sharing between CEPTOARs; An independent body, not positioned under other agencies, including government organizations The backbone of people’s living and economic activities formed by businesses providing services that are extremely difficult to be substituted; If the function of the services is suspended, deteriorates or becomes unavailable, it could have a significant impact on the people’s living and economic activities. Operators designated in "Applicable CI operators" in "Annex 1. Scope of CI Operators and Critical Information System Examples " and groups composed of those designated operators Sectors regarding CI designated for each business type; Specifically, as follows: "information and communication services," "financial services," "aviation services," "airport," "railway services," "electric power supply services," "gas supply services," "government and administrative services (including local government)," "medical services," "water services," "logistics services," "chemical industries," "credit card services" and "petroleum industries" Services and/or a set of procedures provided by CI operators necessary to utilize those services that are designated as those to be protected in particular for each CI sector, taking into account the extent of their impact on people’s living and economic activities Situation where system failures hinder safe and continuous provision of CI services CEPTOAR council CI CI operators CI sectors CI services (CISs) CISs outages Consequences of an event Critical information systems Crisis management ministries Cyberattack risk Cyberspace-related operators Disaster prevention ministries related *With regard to the causes that could give rise to CISs outages, or in other words, threats that should be subjected to Safety Principles, concrete examples are provided in the Annex 2: Examples of Events That Give Rise to Consequences (Threats) from NISC’s Risk Assessment Guide based on the Concept of Mission Assurance in Critical Infrastructure The end of an event that has an impact on the objective Information systems required to provide CI services, designated for each CI operator, taking into account of the degree of impact on its CI services The National Police Agency (NPA); Fire and Disaster Management Agency (FDMA); Japan Coast Guard (JCG); Ministry of Defense (MOD) Risks that can arise in the business as a result of cyberattacks System vendors, which are engaged in the design, construction, operation and maintenance of information systems required for providing CI services; security vendors, which provide information security measures such as antivirus software of those information systems; and platform vendors, which provide the platforms which serve as foundations, including hardware and software of those information systems The government organizations and ministries stipulated in Article 2, item (iii) of the Basic Act on Disaster Control Measures (Act No. 223 of 1961) which engage in information collection in the event of a disaster 50

Select target paragraph3