III. Policies for CIP 1. Maintenance and Promotion of the Safety Principles III. Policies for CIP 1. Maintenance and Promotion of the Safety Principles Cybersecurity measures commonly required in all sectors were compiled as the Guidelines for Safety Principles for Ensuring CI Security and revisions have been made as necessary. In line with the Guidelines, all CI sector guidelines and internal policies, etc. of respective CI operators are now being reviewed, and the safety principles as a whole are being developed in this manner. The safety principles have been disseminating among CI operators as the rules on cybersecurity measures, which further encourages efforts necessary for ensuring safe and continuous provision of CI services. During the term of this Cybersecurity Policy, the Cabinet Secretariat carries out the review of the Guidelines and continual improvement of the safety principles, and surveys their promotion status in order to maintain and enhance CIP capability. Also, CI operators continuously and steadily work on cybersecurity measures in accordance with their PDCA cycle, in view of the importance thereof. 1.1 Continual improvement of the Guidelines for Safety Principles The Cabinet Secretariat carries out the review of the main section and measures section of the Guidelines for safety principles as well as the manual (the "Manual for Prioritization of Information Security Measures") with the aim of maintaining and enhancing CIP capability, especially measures related to top management, development of incident readiness including formulation of contingency plans, and measures integrating not only IT but also OT. Specifically, responsibility of top management is clarified to require them to take the initiative in the formation of cybersecurity culture and the implementation of the PDCA cycle in carrying out cybersecurity measures by the use of the "Cybersecurity Management Guidelines," etc. The reviewed Guidelines additionally describe the necessity of preparation of incident readiness through the establishment of BCPs and contingency plans based on the concept of mission assurance and efforts for ensuring cybersecurity, which is indispensable for properly responding to IT, as a basic factor for internal control (such as internal audits and penetration tests). The significance of developing a cross-sectoral organization consisting of a unit responsible for IT and a unit responsible for OT and nurturing personnel required therefor is also emphasized for the purpose of promptly responding to threats of cyberattacks to control systems of plants and factories, in addition to the need to formulate a Computer Security Incident Response Team (CSIRT3). Furthermore, as a part of the efforts for information sharing, the implementation of case studies concerning past incident responses is presented as a recommendation so that respective CI operators surely reflect other operators' experience of response to CISs outages in their future cybersecurity measures. 3 Computer Security Incident Response Team: A mechanism to monitor information systems for information security problems, and analyze the causes and investigate affected areas, etc. if any problem is detected 12

Select target paragraph3