I. Purposes and Positioning
I. Purposes and Positioning
1. The Importance of Information Security Measures for Critical Infrastructure (CI)
The people’s living and socioeconomic activities of the country are underpinned by various CI
services (CISs), and information systems are widely used to realize this function.
In this context, critical infrastructure, by its very nature, calls for the provision of safe and
sustainable services. Hence, based on the “Concept of Mission Assurance” set out in the
Cybersecurity Policy for Critical Infrastructure Protection (4th Edition) (hereinafter referred to
as “4th Cybersecurity Policy”), in the protection of CI, it is important to ensure the security of
the information systems necessary for the provision of services, and to reduce the possibility of
the occurrence of CISs outages due to cyberattacks or other factors as far as possible. At the
same time, it is also important to ensure early detection of the occurrence of outages and
recovery from these outages swiftly. Furthermore, as CISs can have a severe impact in the case
of a suspension or deterioration of their functions. For this reason, there is a need to provide
focused protection through close cooperation between the public and private sectors.
Concept of Mission Assurance
CI services are the very basis of national life and socioeconomic activities and suspension thereof may
have a direct and serious negative effect on the safety and ease of the general public. Therefore,
stakeholders are required to make efforts to ensure safe and continuous provision of CI services (mission
assurance).
Mission assurance in this Cybersecurity Policy does not mean to oblige stakeholders to make a firm
commitment to ensuring CIP or maintaining CI functions, but to have them assume their responsibilities
in the process of protecting CI services and maintaining the functions thereof. This is the concept to require
each stakeholder to properly make efforts for necessary cybersecurity measures.
(Excerpt from the Cybersecurity Policy for Critical Infrastructure Protection (4th Edition))
For CI operators, with the necessary support from government organizations, it is desirable for
the management to be actively involved, position readiness against risks related to information
security as a part of their management strategy, and put in place strategic measures such as risk
reduction based on the results of risk assessments (implementation of risk management for
information security). In addition, through the prompt detection of cyberattacks and other risks
and appropriate responses to these problems, CI operators should also develop the appropriate
incident readiness, so that they can continue to ensure the safety of CISs and, as far as possible,
provide CISs without any deterioration in quality or suspension of services that are
unacceptable to themselves and their stakeholders.
In promoting these measures, it is particularly important for CI operators to recognize that while
they are business entities, they are also socially responsible entities. In addition to the steady
1