II. Executive Summary of This Cybersecurity Policy II. Executive Summary of This Cybersecurity Policy The key points for this Cybersecurity Policy ([i] Purpose of CIP, [ii] Basic principles, [iii] Responsibility of stakeholders, such as CI operators, government organizations, and cybersecurity related agencies, and in particular, [iv] Responsibility of top management) are as follows. [i] Purpose of CIP The purpose of CIP is to maintain safe and continuous provision of CI services, based on the concept of mission assurance, by preventing serious impact on national life and socioeconomic activities caused by any CISs outages resulting from cyberattacks, natural disasters or other causes to the extent possible and ensuring prompt recovery from outages. [ii] Basic concept In the first place, CI operators should implement cybersecurity measures on their own responsibility, but collaborative efforts among stakeholders are indispensable on the basis of mission assurance for all CIs. Therefore, the purpose of CIP should be achieved through all-out efforts by diverse stakeholders, thereby nurturing a sense of security among the general public, promoting social growth and resilience, and strengthening international competitiveness. ・ CI operators should respectively take measures and make efforts for continuous improvement of those measures as entities providing services and bearing social responsibilities. ・ Government organizations should provide necessary support for cybersecurity measures of CI operators. ・ Each CI operator should cooperate and coordinate with other stakeholders due to the limit of each operator's individual cybersecurity measures to address various threats. [iii] Responsibility of stakeholders ・ All stakeholders should periodically check the progress of their own measures and policies as part of relevant efforts and accurately recognize the current circumstances, and proactively determine the goals of relevant activities. In addition, stakeholders should enhance their cooperation with each other, taking into account the status of other stakeholders' relevant activities. ・ All stakeholders should understand the 5W1H (when, where, who, why, what and how) of responses to CISs outages depending on the scale thereof and should be able to calmly address signs or occurrence of any CISs outages. They should also be capable to cooperate with other stakeholders and respond in a cooperative and concerted manner in addition to ensuring robust communication among various stakeholders and taking proactive measures. [iv] Responsibility of top management In addition to the above, top management should understand the necessity of the following matters and take relevant measures. ・Recognize their responsibility for ensuring cybersecurity and exert their leadership in cybersecurity measures from the viewpoint of mission assurance ・With the awareness that their individual efforts also contribute to the development of society as a whole, take cybersecurity measures while involving their supply chains (business partners, subsidiaries and affiliated companies, etc.) ・Develop incident readiness even in normal times and disclose information on responses properly in the event of an incident from the perspective of gaining trust and nurturing a sense of security among stakeholders ・Constantly secure management resources, such as budgets, structure and personnel, necessary for the abovementioned measures and appropriately allocate them from a risk-based perspective 10

Select target paragraph3