II. Items that Should Ideally be Prescribed in the Safety Principles
4.1.3. The “Plan” Perspective
(1) Information Security Risk Assessment
In order to appropriately manage the information security risks that have an impact on the safe
and continuous provision of CISs, conduct information security risk assessments by following
the procedures set out below.
(i) Taking into account the constantly changing situation surrounding the organization
and the needs of stakeholders, clearly define the scope and standards of the business
that are necessary for providing CISs. At the same time, identify the management
resources, such as information systems, that are necessary for the execution of these
business. As a part of this process, analyze the organization’s risk attitude 5 and risk
tolerance.6
(ii) Identify the information security risks for management resources such as information
systems (risk identification).
(iii) While giving consideration to the risk attitude and risk tolerance, utilize the risk
criteria that have been formulated with evaluating the degree of impact that the
consequences of an event has on services and the business and the probability for the
occurrence of an event being the axis, and verify the magnitude of the risks identified
(risk analysis).
(iv) In addition to identifying risks of a magnitude that is larger than the risk criteria,
identify risks that are subjected to risk treatment in consideration of individual factors
(risk evaluation).
* The Risk Assessment Guide based on the Concept of Mission Assurance in Critical Infrastructure issued
by the National center of Incident readiness and Strategy for Cybersecurity (NISC) sets out the perspective
of risk assessment based on the concept of mission assurance as well as details on the abovementioned
procedures. Please refer to the Guide alongside with this guideline.
* Depending on the business characteristics and environment of the organization, there may also be cases
where applying methods from other guidebooks, etc. is more effective. For example, the Security Risk
Assessment Guide for Industrial Control Systems published by the Information-Technology Promotion
Agency (IPA) sets out the concrete work procedures for effective security measures as well as risk
analysis methods that combine asset-based risk assessment and business risk-based (scenario-based) risk
assessment methods.
5
Refers to an organization's efforts to conduct risk assessments, and ultimately retain, take, or avoid the risks. To clarify risk attitude, clarify
the degree to which CI operators take risks in the operation of their businesses. For example, "The occurrence of CISs outages accompanying
the decline of service levels below 20% is to be three times or less per year."
6
Refers to the degree of residual risk (a risk that remains after the risk treatment) that the organization or stakeholder is prepared to take on in
order to achieve their objectives. Specified, for example, as, "The occurrence of CISs outages accompanying the decline of service levels above
50% is to be once a year or less."
11