Decision making bodies(Primary responsible office) and person, as well as scope of responsibility Responsible officer in each organization (eg. Cyber executive or Chief Information Security Officer (CISO)) Participants in decision making Decision making process and related matters including the name of the meeting, the procedure of holding a meeting, and others 2-4-2 Roles and Responsibilities of stakeholders a) Stakeholders shall be specified in the CII industries as defined above. Clarification of stakeholders Examples of stakeholders to be specified are as follows: CII owners Service provider operating CII The roles of each stakeholder Information sharing Roles in CIIP, including cyber risk recognition, implementation of measures, participation in exercises and so forth 2-5 Establishment of an information sharing scheme between the governments and/or regulators and private sector -It is preferable to consider a two-way communication system between the governments and/or regulators and private sector; a) As for information sharing from private sector to the governments and/or regulators, there are two possible approaches (i) Laws and regulations basis and (ii) voluntary basis. b) With (i) laws and regulations basis, the private sector should share information with the governments and/or regulators according to legal and regulatory requirements. The benefit to the governments and/or regulators is that necessary information is received at the right time, but it also has the disadvantage in that the private sector may protest against the government regulations. It may be necessary for the governments and/or regulators to carefully consider the cyber risks they are facing, effectiveness of the information to be gathered, and accountability. c) With (ii) voluntary basis, the benefits and disadvantages are reversed. The

Select target paragraph3