To research current status of CIIP measures in foreign countries
To research generally accepted International standards (e.g. ISO
standards)
To gather stakeholders’ opinions
To evaluate possible cyber risks regarding CII in their own country
To identify critical business functions and their supporting critical IT
resources that should be protectedi
To prioritize available resources to deal with the possible cyber risks
2-2 Establishment of information security policy or strategy
a)
It is preferable for the governments to establish a national policy or strategy
in which the basic ideas of CIIP are systematically organized.
b)
It is preferable to perform Plan-Do-Check-Act (PDCA) cycle and regular
periodical review (preferably, at least, annually) on this policy or strategy to
ensure that the policy or strategy is not outdated due to changes to the
internal or external environment such as emerging new cyber risks and
technologies. If there are issues, the governments are expected to revise the
policy or strategy in response to such changes.
Examples of items to be included in the policy or strategy are as follows:
Purpose of CIIP
Goals of the CIIP strategy
Definitions of designated CII
Items concerning governance
Prioritized areas of measures to improve CIIP
Outlines of CIIP measures
2-3 Establishment of guidelines for security standards
a)
To achieve the goals described in the policy or strategy, it is desirable for each
CII owner/operator to establish CIIP security standards according to the
features of each industry.
b)
In this context “security standards” means a document(s) which describes the
necessary or preferable level of information security measures for the
industries according to the features of each industry.ii
c)
It is preferable for the governments and/or regulators to establish security
standards or guidelines if the governments and/or regulators themselves are