CIIP guidelines Introduction The Critical Information Infrastructure Protection (CIIP) guideline is drafted by the CIIP expert panel established as part of the ASEAN-Japan cooperation on CIIP that was adopted in the ministerial statement at the ASEAN-Japan Ministerial Policy Meeting on Cyber Security Cooperation on September 12th and September 13th, 2013. The first edition of the CIIP guidelines reflects the discussions at the CIIP expert panel meetings in Kuala Lumpur (February, 2014) and in Bangkok (May, 2014) and the 6th Government Network Security Workshop in Singapore on August 27th and 28th, 2014. The second edition is a reflection of continuous discussions in the ASEAN-Japan CIIP Working Group (formerly the CIIP expert panel) in Jakarta (February, 2015), in Hanoi (April, 2015) and at the 1st ASEAN-Japan Information Security Joint Working Group Meeting in Tokyo (June, 2015), and the revised part is especially focused on the preparation stage of the development of CIIP policies. The third edition reflects the discussion in the ASEAN-Japan CIIP Working Group in Bandar Seri Begawan (February, 2016), in Hanoi (May, 2016) and at the 2nd ASEANJapan Information Security Joint Working Group Meeting in Bangkok (July, 2016) 1. Outline/Overview 1-1 Purpose of the guidelines a) These guidelines are intended to be used as a reference or checklist for the relevant governments and/or regulators of ASEAN Member States to develop basic CIIP policies for their various critical sectors. b) These guidelines explain the fundamental ideas of CIIP with regards to the minimum protection requirements of and roles of the governments and/or regulators. It also provides basic ideas and processes with which the relevant governments and/or regulators for the CII sector can assist CII operators to understand the significance of CIIP, as well as to help with the implementation of measures for CIIP. c) The outlines of cyber exercises and the CIIP best practices of leading ASEAN Member States are attached in the appendix for reference. 1-2 Intended users a) The intended users of these guidelines are mainly policy makers in ministries

Select target paragraph3