CIIP guidelines
Introduction
The Critical Information Infrastructure Protection (CIIP) guideline is drafted by the
CIIP expert panel established as part of the ASEAN-Japan cooperation on CIIP that was
adopted in the ministerial statement at the ASEAN-Japan Ministerial Policy Meeting
on Cyber Security Cooperation on September 12th and September 13th, 2013. The first
edition of the CIIP guidelines reflects the discussions at the CIIP expert panel meetings
in Kuala Lumpur (February, 2014) and in Bangkok (May, 2014) and the 6th Government
Network Security Workshop in Singapore on August 27th and 28th, 2014.
The second edition is a reflection of continuous discussions in the ASEAN-Japan CIIP
Working Group (formerly the CIIP expert panel) in Jakarta (February, 2015), in Hanoi
(April, 2015) and at the 1st ASEAN-Japan Information Security Joint Working Group
Meeting in Tokyo (June, 2015), and the revised part is especially focused on the
preparation stage of the development of CIIP policies.
The third edition reflects the discussion in the ASEAN-Japan CIIP Working Group in
Bandar Seri Begawan (February, 2016), in Hanoi (May, 2016) and at the 2nd ASEANJapan Information Security Joint Working Group Meeting in Bangkok (July, 2016)
1. Outline/Overview
1-1 Purpose of the guidelines
a)
These guidelines are intended to be used as a reference or checklist for the
relevant governments and/or regulators of ASEAN Member States to develop
basic CIIP policies for their various critical sectors.
b)
These guidelines explain the fundamental ideas of CIIP with regards to the
minimum protection requirements of and roles of the governments and/or
regulators. It also provides basic ideas and processes with which the relevant
governments and/or regulators for the CII sector can assist CII operators to
understand the significance of CIIP, as well as to help with the
implementation of measures for CIIP.
c)
The outlines of cyber exercises and the CIIP best practices of leading ASEAN
Member States are attached in the appendix for reference.
1-2 Intended users
a)
The intended users of these guidelines are mainly policy makers in ministries