Decision making bodies(Primary responsible office) and person, as well
as scope of responsibility
Responsible officer in each organization (eg. Cyber executive or Chief
Information Security Officer (CISO))
Participants in decision making
Decision making process and related matters including the name of the
meeting, the procedure of holding a meeting, and others
2-4-2 Roles and Responsibilities of stakeholders
a)
Stakeholders shall be specified in the CII industries as defined above.
Clarification of stakeholders
Examples of stakeholders to be specified are as follows:
CII owners
Service provider operating CII
The roles of each stakeholder
Information sharing
Roles in CIIP, including cyber risk recognition, implementation of
measures, participation in exercises and so forth
2-5 Establishment of an information sharing scheme between the governments
and/or regulators and private sector
-It is preferable to consider a two-way communication system between the
governments and/or regulators and private sector;
a)
As for information sharing from private sector to the governments and/or
regulators, there are two possible approaches (i) Laws and regulations basis
and (ii) voluntary basis.
b)
With (i) laws and regulations basis, the private sector should share
information with the governments and/or regulators according to legal and
regulatory requirements. The benefit to the governments and/or regulators is
that necessary information is received at the right time, but it also has the
disadvantage in that the private sector may protest against the government
regulations. It may be necessary for the governments and/or regulators to
carefully consider the cyber risks they are facing, effectiveness of the
information to be gathered, and accountability.
c)
With (ii) voluntary basis, the benefits and disadvantages are reversed. The