III. Policies for CIP 2. Enhancement of Information Sharing System awareness sharing among stakeholders and ensuring prompt and effective information sharing. Through these efforts, the Cabinet Secretariat works on promoting effective information sharing among stakeholders based on concrete criteria with regard to information on cyberattacks, etc. that are highly likely to have an expansive influence within and outside the relevant sector. In addition, considering the recent trend that cyberattacks have come to target control systems, which used to be considered closed and safe, this Cybersecurity Policy clearly states that attacks to control systems, including IoT systems that are expected to be further disseminated in the future, are also included in the information to be shared. During the term of this Cybersecurity Policy, stakeholders are requested to conduct information sharing to and from NISC and thus promote information sharing in line with the ATTACHMENT under the reviewed information sharing system. When any change occurs in the environment, the system is to be reviewed as needed. Review of the protection scope of CI is also continued in order to achieve "protection as plane" covering a broader area for the purpose of ensuring safe and continuous provision of CI services (refer to 5.1(1) below for details). 2.3 Promotion of CI operators' activities Enrichment of information sharing within and between CEPTOARs is expected for further activating activities of CI operators, in addition to individual efforts by CI operators themselves. In particular, CI operators should proactively work towards their own information sharing activities, in addition to constructing and enhancing CISs outage response structure, such as CSIRT. CEPTOARs are also expected to continue sharing information provided by the Cabinet Secretariat as during the term of the Third Policy, while applying rules decided upon by constituent members regarding agreements on the handling of such provided information, maintenance of confidentiality and provision of information to parties outside the constituent members, under a situation where a PoC4 is established to allow contact between constituent members and with non-members in case of emergency. It is also expected that efforts for further activating sharing activities are made such as through appointing coordinators who will carry out information collection and decision making within CEPTOARs, sharing predictive information and CISs outage examples during ordinary situations, and enhancing functions required for information sharing between CEPTOARs and with the CEPTOAR council. ISACs have already been organized in some sectors that are carrying out leading activities, and sharing, examination and analysis of information within respective ISACs and information sharing with foreign ISACs are now being promoted. Promoting participation in ISACs and information sharing among different ISACs will contribute to further activating information sharing among CI operators and their further positive activities for cybersecurity measures. Additionally, expansion of internal and external information sharing should be maintained through the expansion of constituent members of respective CEPTOARs and establishment of new CEPTOARs. Qualitative and quantitative improvements are expected for sharing information handled by CI operators, covering not only IT but also OT, for the purpose of ensuring collaboration with domestic and foreign diverse entities, and safe and continuous provision of CI services. 4 PoC: Point of Contact 16

Select target paragraph3