III. Policies for CIP
3. Enhancement of Incident Response Capability
of participants who assessed the exercises as meaningful exceeded 80%. This Cybersecurity Policy continuously aims
to disseminate exercise results in CI sectors through encouraging participation of individuals who had not yet
participated in the exercises. However, as there is a certain limitation on participation increase, it is necessary, in addition
to encouraging new participation, to nurture human resources so that exercise participants can voluntarily hold
individual exercises in their companies or in the relevant sector that are carried out based on know-how of cross-sectoral
exercises, in order to further propagate and promote exercise results to overall CI.
For this activity, the Cabinet Secretariat creates and releases explanation materials regarding the merits of exercises,
thereby increasing understanding and encouraging active participation of top management in overall CI sectors to
promote implementation of exercises in each CI sector and at each CI operator.
In addition, the Cabinet Secretariat works to provide a virtual exercise environment with the aim of developing and
sharing implementation, assessment and advising methods accumulated from past exercises in order to contribute to the
support of exercise implementation by individual CI operators.
3.1.3 Cooperation with responsible ministries for CI
Although expected effects differ between exercises and training for CIP conducted by responsible ministries and
cross-sectoral exercises conducted by the Cabinet Secretariat, carrying out these exercises in a manner to cooperate with
and complement each other is expected to contribute to efficient and effective maintenance and enhancement of CIP
capability.
For this reason, the Cabinet Secretariat and responsible ministries for CI positively work on materializing ideal mutual
cooperation and clarifying verification purposes and the main targets for each exercise in order to surely improve CI
operators' incident response capability.
Additionally, in collaboration with private organizations, such as ISACs, that have already been established in some
CI sectors, the Cabinet Secretariat will make it clear what exercises are truly effective for participating operators and
ideal means for information cooperation.
Various factors including physical obstruction need to be considered in responding to CISs outages and there is a
possibility that information may need to be shared not only among responsible ministries for CI and CI operators'
cybersecurity departments but also with disaster prevention and risk management departments. Therefore, collaboration
with such other departments should also be sought as necessary, based on stakeholders' needs.
3.2 CEPTOAR communication training
The Cabinet Secretariat continues CEPTOAR training based on the procedures for information sharing to and from
NISC for the purpose of maintenance and improvement of protective capability of the "vertical-directional information
sharing" systems in each sector between CEPTOAR and responsible ministries for CI.
Considering that many CI operators have already participated in CEPTOAR training, and from the perspective of
effectively utilizing these training opportunities, the Cabinet Secretariat further enhances the content of the training,
19