the owners of the CII. In the case that the CII owners/operators are private
entities, the governments and/or regulators are expected to establish basic
guidelines on which each industry can base their own safety standards, while
adhering to international standards.
d)
Examples of items to be included in these guidelines for the CII
owners/operators are as follows:
Purpose of the security standards
Scope of the security standards
Recommended items to be included in the security standards, and so forth.
Practical/appropriate methods for satisfying security standards such as
using a certification scheme.
e)
In addition to the policy or strategy, items included in the security standards
may also be changed according to variations in the internal or external
environment such as emergence of new technology and changes in trends in
certification systems based on international standards. Therefore, it is
preferable for the governments and/or regulators to periodically (preferably, at
least, annually) monitor these changes by conducting interviews with CII
owners/operators about the situation and issues they are facing, and revise
the guideline as necessary in the case there are significant changes in
circumstances.
2-4 Establishment of governance structure and identifying stakeholders
2-4-1 Establishment of governance
a)
To establish a governance system necessary to implement the strategy set
forth in 2-2, the following items should be considered:
Clarification of the roles and scope of responsibilities of government
agencies involved.
For example it is preferable to clarify following points:
Coordinating Ministry/Agency and the Chief Executive Officer
Ministry/Agency responsible for establishing strategies
Ministry/Agency controlling or regulating major CII industries.
Ministry/Agency which monitors the implementation status of the
strategies, and so forth.
Clarification of the decision making process
For example it is desirable to clarify the following points: