4-2 Establishment of information security policy or strategy Expectation for To establish basic idea of CIIP to be included in information Governments security policy. To decide items to be included in the policy (examples are described in the CIIP guidelines 2-2). To periodically review policy/strategy to make sure it is not outdated. Possible Issues Lack of examples/templates. and Obstacles Lack of human resources/information. Conflict among stakeholders (Ministries/Agencies, CII owners/operators, etc.). Possible If you cannot establish information security policy: Countermeasures Refer to the information security policy of the other to Overcome countries listed on the CIIP guidelines. Issues and If there is conflict of the interest between stakeholders, Obstacles following are the examples to solve the problem. Establish an organization that has enough authority to coordinate conflicts among stakeholders. Conduct series of intensive discussions in which every stakeholders can freely discuss their opinions to compromise. Give enough authorities to certain regulatory ministries/agencies to solve the conflicts. It is desirable to put periodical review as a responsibility of the government in the information security policy so that you can have enough human resources or organizations within the government. 6

Select target paragraph3