or agencies that regulate CII industries in each ASEAN Member State. 1-3 Fundamental ideas of CII a) In these guidelines, CII is defined as follows: “Information infrastructures whose failure or limited operation due to natural or man-made disasters would surely cause tremendous impact on the vast majority of citizens” b) “Tremendous impact on the vast majority of citizens” means not only direct damage due to CII failure but also indirect damage caused by the effect of CII’s failure on other information infrastructures which are highly dependent on the CII based on formal impact assessment. c) ‘CII owner/operator’ in this guideline refers to the owner of the CII as well as the service provider operating the CII. 1-4 Significance of CIIP 1-4-1 Purpose of CIIP a) In order to continuously provide services using CII and to avoid serious effects on public welfare and socioeconomic activities caused by outages of the information technology (IT) supporting the CII resulting from cyber-attacks or other causes, all stakeholders concerned should protect CII by taking proactive actions to minimize the risk of the IT outages and by ensuring prompt recovery from the outage should one occur. 1-4-2 Fundamental issues and concerns of CIIP a) When providing necessary guidelines and support with regards to information security measures, the relevant governments and/or regulators for the CII sector should take into consideration the situation in each country, as well as the size and capability of each CII owner/operator. b) If the governments and/or regulators request the same level of implementation of measures regardless of the size of the CII owners/operators, it may overburden SME operators and negatively affect their business viability. c) It is preferable that all stakeholders concerned, including the governments and/or regulators and each CII owner/operator, periodically check the progress of their own measures and policies as a part of the initiative to accurately recognize the current CIIP circumstances, and assess the

Select target paragraph3