I. Introduction 4. Outcome of the Review for the Revision of this Cybersecurity Policy 4.2 Concept of Mission Assurance CI services are the very basis of national life and socioeconomic activities and suspension thereof may have a direct and serious negative effect on the safety and ease of the general public. Therefore, stakeholders are required to make efforts to ensure safe and continuous provision of CI services (mission assurance). Mission assurance in this Cybersecurity Policy does not mean to oblige stakeholders to make a firm commitment to ensuring CIP or maintaining CI functions, but to have them assume their responsibilities in the process of protecting CI services and maintaining the functions thereof. This is the concept to require each stakeholder to properly make efforts for necessary cybersecurity measures. (1) Efforts required for CI operators The top management of CI operators must be actively involved in deciding business strategies incorporating preparedness for cybersecurity risks and taking measures to reduce such risks strategically based on the results of risk assessment. They need to put in place an appropriate incident readiness to continue CI services even in the case of receiving a cyberattack, etc., ensuring safety of their CI services and preventing suspension or quality loss unacceptable for themselves and other stakeholders to the extent possible. Top management should develop internal control systems concerning cybersecurity measures and must fulfill accountability to their own stakeholders concerning the fact that they are properly taking measures for mission assurance. (2) Efforts required for government organizations Government organizations are required to set or review the scopes of CI and CI services to be protected as the basis to support national life and socioeconomic activities, in collaboration with diverse stakeholders, and to offer necessary support to CI operators for their abovementioned efforts. Government organizations must also fulfill accountability to the general public concerning the fact that efforts are being made properly through the assessment of this Cybersecurity Policy and PR activities. 4.3 Priorities in This Cybersecurity Policy The following three priorities are to be reflected in activities under each policy. 4.3.1 Promotion of leading activities by CI operators (classification of CI operators in light of interdependency) The utilization of ICT is increasingly spreading among CI operators and interdependency among sectors has become deeper. In some sectors that are highly depended upon by other CISs and may cause a big impact in the case of outages even for a relatively short period of time (such as electric power supply services, information and communication services, and financial services), CI operators have voluntarily promoted highly advanced cybersecurity measures, centered on major operators belonging to the relevant sectors. In order to protect CI as a whole from increasingly sophisticated cyberattacks, etc., such leading activities need to be further enhanced and promoted and should also be 7

Select target paragraph3