Contents
Introduction ........................................................................................................................... 4
1.
Outline/Overview ........................................................................................................... 4
1-1 Purpose of the guidelines............................................................................................ 4
1-2 Intended users ............................................................................................................. 4
1-3 Fundamental ideas of CII ........................................................................................... 5
1-4 Significance of CIIP .................................................................................................... 5
1-4-1 Purpose of CIIP ........................................................................................................ 5
1-4-2 Fundamental issues and concerns of CIIP............................................................. 5
1-5 Definition of terms ...................................................................................................... 6
2.
Role of Governments and/or Regulators in CIIP ......................................................... 6
2-1 Preparation for development of CIIP policies ........................................................... 6
2-2 Establishment of information security policy or strategy........................................ 7
2-3 Establishment of guidelines for security standards ................................................. 7
2-4 Establishment of governance structure and identifying stakeholders ................... 8
2-4-1 Establishment of governance .............................................................................. 8
2-4-2 Roles and Responsibilities of stakeholders ........................................................ 9
2-5 Establishment of an information sharing scheme between the governments and/or
regulators and private sector............................................................................................ 9
2-6 IT Security Crisis Management ............................................................................... 10
2-6-1 Incident handling ............................................................................................... 10
2-6-2 Disaster recovery and Business Continuity Planning (BCP) ..........................11
2-7 Cyber exercise ............................................................................................................11
2-7-1 Significance of cyber exercise .............................................................................11
2-7-2 Government support for industry-level exercises in the private sector ..........11
2-7-3 Government support for cross-industry exercises in the private sector ........ 12
2-8 Awareness-raising activities for CII owners/operators .......................................... 12
2-9 ASEAN regional partnership ................................................................................... 12