achievement of the goals of the measures. In addition, it is recommended that
all stakeholders take the effort to understand the progress of similar efforts
by other parties and to establish cooperation with them.
d)
In addition to the aforementioned measures, it is important that the
governments and/or regulators and the CII owners/operators recognize the
need for the following measures to ensure effective implementation of the
measures:
Identify information infrastructure that is required by critical public
services. Specifically, determine which function is categorized as CII and
the CII owners/operators, and specify the cyber risk sources which may
affect the CII.
Conduct assessments of the cyber risk sources and set forth measures and
their priorities to address those risks.
Specifically, evaluate each cyber
risk source stated above based on the level of impact and the feasibility of
establishing mitigation measures, prioritized according to the severity of
impact.
Establish the plan for implementation of measures, in line with the CIIP
policies, and monitor the implementation of the measures.
Evaluate the effectiveness of the measures, including the incident response
capability, incident management plans and the information sharing scheme
amongst relevant stakeholders through exercises and training.
1-5 Definition of terms
The definition of terms in these guidelines is based on international standards such
as ISO 27001:2013, ISO 31000:2009, and ISO 22301 unless otherwise explicitly
defined in the guideline.
2. Role of Governments and/or Regulators in CIIP
2-1 Preparation for development of CIIP policies
a)
It is preferable for countries developing CIIP policies to conduct necessary
preparation before starting the development process.
b)
The preparation should, at least, include the following activities:
To research current status of CIIP measures in the country