Index I. Purposes and Positioning .................................................................................................................. 1 1. The Importance of Information Security Measures for Critical Infrastructure (CI) ............................ 1 2. What Are “Safety Principles?”...................................................................................................... 2 3. Positioning of the Guideline ......................................................................................................... 2 4. Expectations Toward the Continual Improvements and Dissemination of Safety Principles based on This Guideline ................................................................................................................................ 5 II. Items That Should Ideally Be Prescribed in the Safety Principles........................................................ 6 1. Purpose of Formulating the Safety Principles................................................................................. 6 2. Applicable Scope ........................................................................................................................ 6 3. Roles of Stakeholders .................................................................................................................. 6 4. Measures .................................................................................................................................... 6 4.1. The “Plan” Perspective ............................................................................................................ 7 4.1.1. Perspective of the Organization’s Situation ........................................................................... 7 (1) Understanding the External and Internal Environments ............................................................ 7 (2) Understanding the Requirements of Stakeholders .................................................................... 7 4.1.2. The “Leadership” Perspective .............................................................................................. 7 (1) Commitment of the Management ........................................................................................... 7 (2) Formulation of Information security Policies .......................................................................... 8 (3) Assignment of Responsibilities and Authority for the Roles in the Organization ........................ 9 4.1.3. The “Plan” Perspective.......................................................................................................11 (1) Information Security Risk Assessment...................................................................................11 (2) Decision on Information Security Risk Treatment ................................................................. 12 (3) Formulation of Individual Policies for Security Management Measures .................................. 19 (4) Formulation of Plans for Addressing Information Security Risks ............................................ 19 4.1.4. The “Support” Perspective ................................................................................................ 19 (1) Securing Resources ............................................................................................................. 19 (2) Human Resource Development and Awareness-Raising ......................................................... 20 (3) Communication .................................................................................................................. 20 4.2. The “Do” Perspective ............................................................................................................ 21 4.2.1. The Operational Perspective .............................................................................................. 21 (1) Introduction and Operation of Information Security Measures ................................................ 21 (2) Addressing CISs Outages .................................................................................................... 22 (3) Conducting Exercises and Training ...................................................................................... 23 4.3. The “Check” Perspective ....................................................................................................... 24 4.3.1. The Evaluation Perspective ............................................................................................... 24 (1) Monitoring and Auditing ..................................................................................................... 24 (2) Review by the Management................................................................................................. 24 4.4. The “Act” Perspective ........................................................................................................... 25 4.4.1. The Improvement Perspective ............................................................................................ 25 (1) Corrective Measures and Continual Improvements ................................................................ 25 Annex 1: Scope of CI Operators and Critical Information System Examples.......................................... 26 Annex 2: Explanation of CI Services and CI Service Outage Examples ................................................. 27 Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness ............................................................. 33 Annex 4: References for Concrete Examples of Measures .................................................................... 46 Definitions / Glossaries ..................................................................................................................... 50 References........................................................................................................................................ 52

Select target paragraph3