Contents 1. Introduction ............................................................................................................... 3 2. Purpose of this document and intended users .......................................................... 3 3. Structure of this document........................................................................................ 3 4. Check lists to develop CIIP policies utilizing CIIP guidelines.................................. 4 4-1 Preparation for development of CIIP policies ........................................................................ 4 4-2 Establishment of information security policy or strategy ...................................................... 6 4-3 Establishment of guidelines for security standards ............................................................... 8 4-4 Establishment of governance structure and identifying stakeholders ................................. 10 4-5 Establishment of an information sharing scheme between the governments and/or regulators and private sector ............................................................................................................................ 12 4-6 IT security crisis management ............................................................................................ 14 4-7 Cyber exercise ..................................................................................................................... 16 4-8 Awareness-raising activities for CII owners/operators ........................................................ 18 4-9 ASEAN regional partnership............................................................................................... 20 2

Select target paragraph3