To research current status of CIIP measures in foreign countries To research generally accepted International standards (e.g. ISO standards) To gather stakeholders’ opinions To evaluate possible cyber risks regarding CII in their own country To identify critical business functions and their supporting critical IT resources that should be protectedi To prioritize available resources to deal with the possible cyber risks 2-2 Establishment of information security policy or strategy a) It is preferable for the governments to establish a national policy or strategy in which the basic ideas of CIIP are systematically organized. b) It is preferable to perform Plan-Do-Check-Act (PDCA) cycle and regular periodical review (preferably, at least, annually) on this policy or strategy to ensure that the policy or strategy is not outdated due to changes to the internal or external environment such as emerging new cyber risks and technologies. If there are issues, the governments are expected to revise the policy or strategy in response to such changes. Examples of items to be included in the policy or strategy are as follows: Purpose of CIIP Goals of the CIIP strategy Definitions of designated CII Items concerning governance Prioritized areas of measures to improve CIIP Outlines of CIIP measures 2-3 Establishment of guidelines for security standards a) To achieve the goals described in the policy or strategy, it is desirable for each CII owner/operator to establish CIIP security standards according to the features of each industry. b) In this context “security standards” means a document(s) which describes the necessary or preferable level of information security measures for the industries according to the features of each industry.ii c) It is preferable for the governments and/or regulators to establish security standards or guidelines if the governments and/or regulators themselves are

Select target paragraph3