the owners of the CII. In the case that the CII owners/operators are private entities, the governments and/or regulators are expected to establish basic guidelines on which each industry can base their own safety standards, while adhering to international standards. d) Examples of items to be included in these guidelines for the CII owners/operators are as follows: Purpose of the security standards Scope of the security standards Recommended items to be included in the security standards, and so forth. Practical/appropriate methods for satisfying security standards such as using a certification scheme. e) In addition to the policy or strategy, items included in the security standards may also be changed according to variations in the internal or external environment such as emergence of new technology and changes in trends in certification systems based on international standards. Therefore, it is preferable for the governments and/or regulators to periodically (preferably, at least, annually) monitor these changes by conducting interviews with CII owners/operators about the situation and issues they are facing, and revise the guideline as necessary in the case there are significant changes in circumstances. 2-4 Establishment of governance structure and identifying stakeholders 2-4-1 Establishment of governance a) To establish a governance system necessary to implement the strategy set forth in 2-2, the following items should be considered: Clarification of the roles and scope of responsibilities of government agencies involved. For example it is preferable to clarify following points: Coordinating Ministry/Agency and the Chief Executive Officer Ministry/Agency responsible for establishing strategies Ministry/Agency controlling or regulating major CII industries. Ministry/Agency which monitors the implementation status of the strategies, and so forth. Clarification of the decision making process For example it is desirable to clarify the following points:

Select target paragraph3