III. Policies for CIP
1. Maintenance and Promotion of the Safety Principles
III. Policies for CIP
1. Maintenance and Promotion of the Safety Principles
Cybersecurity measures commonly required in all sectors were compiled as the Guidelines for Safety Principles for
Ensuring CI Security and revisions have been made as necessary. In line with the Guidelines, all CI sector guidelines
and internal policies, etc. of respective CI operators are now being reviewed, and the safety principles as a whole are
being developed in this manner.
The safety principles have been disseminating among CI operators as the rules on cybersecurity measures, which
further encourages efforts necessary for ensuring safe and continuous provision of CI services.
During the term of this Cybersecurity Policy, the Cabinet Secretariat carries out the review of the Guidelines and
continual improvement of the safety principles, and surveys their promotion status in order to maintain and enhance CIP
capability.
Also, CI operators continuously and steadily work on cybersecurity measures in accordance with their PDCA cycle,
in view of the importance thereof.
1.1 Continual improvement of the Guidelines for Safety Principles
The Cabinet Secretariat carries out the review of the main section and measures section of the Guidelines for safety
principles as well as the manual (the "Manual for Prioritization of Information Security Measures") with the aim of
maintaining and enhancing CIP capability, especially measures related to top management, development of incident
readiness including formulation of contingency plans, and measures integrating not only IT but also OT.
Specifically, responsibility of top management is clarified to require them to take the initiative in the formation of
cybersecurity culture and the implementation of the PDCA cycle in carrying out cybersecurity measures by the use of
the "Cybersecurity Management Guidelines," etc. The reviewed Guidelines additionally describe the necessity of
preparation of incident readiness through the establishment of BCPs and contingency plans based on the concept of
mission assurance and efforts for ensuring cybersecurity, which is indispensable for properly responding to IT, as a basic
factor for internal control (such as internal audits and penetration tests).
The significance of developing a cross-sectoral organization consisting of a unit responsible for IT and a unit
responsible for OT and nurturing personnel required therefor is also emphasized for the purpose of promptly responding
to threats of cyberattacks to control systems of plants and factories, in addition to the need to formulate a Computer
Security Incident Response Team (CSIRT3).
Furthermore, as a part of the efforts for information sharing, the implementation of case studies concerning past
incident responses is presented as a recommendation so that respective CI operators surely reflect other operators'
experience of response to CISs outages in their future cybersecurity measures.
3
Computer Security Incident Response Team: A mechanism to monitor information systems for information security problems, and
analyze the causes and investigate affected areas, etc. if any problem is detected
12