I. Purposes and Positioning I. Purposes and Positioning 1. The Importance of Information Security Measures for Critical Infrastructure (CI) The people’s living and socioeconomic activities of the country are underpinned by various CI services (CISs), and information systems are widely used to realize this function. In this context, critical infrastructure, by its very nature, calls for the provision of safe and sustainable services. Hence, based on the “Concept of Mission Assurance” set out in the Cybersecurity Policy for Critical Infrastructure Protection (4th Edition) (hereinafter referred to as “4th Cybersecurity Policy”), in the protection of CI, it is important to ensure the security of the information systems necessary for the provision of services, and to reduce the possibility of the occurrence of CISs outages due to cyberattacks or other factors as far as possible. At the same time, it is also important to ensure early detection of the occurrence of outages and recovery from these outages swiftly. Furthermore, as CISs can have a severe impact in the case of a suspension or deterioration of their functions. For this reason, there is a need to provide focused protection through close cooperation between the public and private sectors. Concept of Mission Assurance CI services are the very basis of national life and socioeconomic activities and suspension thereof may have a direct and serious negative effect on the safety and ease of the general public. Therefore, stakeholders are required to make efforts to ensure safe and continuous provision of CI services (mission assurance). Mission assurance in this Cybersecurity Policy does not mean to oblige stakeholders to make a firm commitment to ensuring CIP or maintaining CI functions, but to have them assume their responsibilities in the process of protecting CI services and maintaining the functions thereof. This is the concept to require each stakeholder to properly make efforts for necessary cybersecurity measures. (Excerpt from the Cybersecurity Policy for Critical Infrastructure Protection (4th Edition)) For CI operators, with the necessary support from government organizations, it is desirable for the management to be actively involved, position readiness against risks related to information security as a part of their management strategy, and put in place strategic measures such as risk reduction based on the results of risk assessments (implementation of risk management for information security). In addition, through the prompt detection of cyberattacks and other risks and appropriate responses to these problems, CI operators should also develop the appropriate incident readiness, so that they can continue to ensure the safety of CISs and, as far as possible, provide CISs without any deterioration in quality or suspension of services that are unacceptable to themselves and their stakeholders. In promoting these measures, it is particularly important for CI operators to recognize that while they are business entities, they are also socially responsible entities. In addition to the steady 1

Select target paragraph3