Introduction (Executive Summary of This Guideline) Positioning and Structure of This Guideline Critical infrastructure (CI) operators have the social responsibilities of providing CI services (CISs) safely and continuously, and it is important to put in place the necessary measures based on the “Concept of Mission Assurance” set out in the Cybersecurity Policy for Critical Infrastructure Protection (4th Edition). Specifically, this involves making the necessary preparations for risks related to information security and implementing the appropriate countermeasures in the event of an emergency. The matters that should be taken into consideration in such situations should ideally be set out in Safety Principles, which provide the standard for the operation of businesses by CI operators. This guideline organizes and sets out the items that should ideally be provided for in such safety principles. The items set out in this guideline are information security measures that follow the PDCA cycle. The formulation of these items takes into consideration the Information security Management System (ISMS), an international standard for information security, as well as information security standards related to CI sectors, such as NIST’s Framework for Improving Critical Infrastructure Cybersecurity and CSMS Certification Criteria. This guideline is structured in a way that allows it to comprehensively cover all the main standards related to CI. Matters of Importance when Implementing the PDCA Cycle for Information security Measures  Actions required of the management The management needs to recognize that information security risks have an impact on business operations that are based on the “Concept of Mission Assurance,” adding a level of uncertainty to such operations; hence, the management has to provide instructions on the implementation of the necessary information security risk assessments in order to decide on the approach for dealing with such risks. Furthermore, in promoting the PDCA cycle for information security measures, it should strive to continuously secure and appropriately allocate the necessary resources (budget, systems, human resources, etc.). In addition, the management needs to periodically verify the effects and impact that the results of addressing information security risks have on the business, and to make decisions on the necessity of reviewing the strategy for addressing information security risks. With regard to these initiatives, it should refer to materials such as the Approaches to Cybersecurity for Corporate Management and the Cybersecurity Management Guidelines.  Periodic implementation of information security risk assessment Information security risks are constantly changing as a result of factors such as the occurrence of new threats and the new discovery of technological vulnerabilities, and changes in the business environment surrounding CI operators and new demands from interested parties. In view of that, there is a need to periodically implement risk assessments while taking reference from materials such as the Risk Assessment Guide Based on the Concept of Mission Assurance in Critical Infrastructure, and to reassess the impact that changes in information security risk have on the safe and sustainable provision of CISs.  Formulation of response plans based on the characteristics of cyberattacks During the occurrence of a cyberattack, which is one of the events that give rise to CISs outages, formulate a contingency plan beforehand, which sets out concrete policies and procedures of initial response among other details, in order to realize swiftly and appropriate initial response. At the same time, formulate a business continuity plan, which sets out the policies and procedures, among other details, of measures for recovery from the CISs outages that result from the cyberattack. In the formulation of these response plans, take into consideration the Characteristics of Cyberattack Risks as well as Considerations for Response and Countermeasures provided in this guideline.  Making provisions for swiftly and flexible incident readiness In addition to addressing information security risks from a medium- to long-term perspective based on the PDCA cycle, there is also a need to ensure readiness, which enables timely and flexible response to any indications of a cyberattack that are detected on a daily basis through monitoring mechanisms built by CI operators.

Select target paragraph3