Table of Contents I. Introduction .......................................................................................................................................... 1 1. Direction for Establishing the Cybersecurity Policy ............................................................................... 1 2. Structure of This Cybersecurity Policy ................................................................................................. 3 3. Assessment of the Third Policy ............................................................................................................ 3 4. Outcome of the Review for the Revision of this Cybersecurity Policy ..................................................... 6 4.1 Purpose of CIP .............................................................................................................................. 6 4.2 Concept of Mission Assurance ....................................................................................................... 7 4.3 Priorities in This Cybersecurity Policy ............................................................................................ 7 4.4 Policy Groups and Direction of Reinforcing and Refining the Components of the Cybersecurity Policy8 II. Executive Summary of This Cybersecurity Policy ............................................................................. 10 III. Policies for CIP ................................................................................................................................ 12 1. Maintenance and Promotion of the Safety Principles ........................................................................... 12 1.1 Continual improvement of the Guidelines for Safety Principles....................................................... 12 1.2 Continual improvement of the safety principles ............................................................................. 13 1.3 Promotion of the safety principles................................................................................................. 13 2. Enhancement of Information Sharing System ..................................................................................... 14 2.1 Information sharing system during the term of this Cybersecurity Policy ......................................... 14 2.2 Further promotion of information sharing...................................................................................... 15 2.3 Promotion of CI operators' activities ............................................................................................. 16 3. Enhancement of Incident Response Capability .................................................................................... 18 3.1 Improvement of cross-sectoral exercises ....................................................................................... 18 3.2 CEPTOAR communication training ............................................................................................. 19 4. Risk Management and Preparation of Incident Readiness .................................................................... 21 4.1 Basic view of risk management .................................................................................................... 21 4.2 Promotion of risk management..................................................................................................... 22 4.3 Establishment of a process of synergizing the relevant policies ....................................................... 25 5. Enhancement of the Basis for CIP ...................................................................................................... 26 5.1 Review of the protection scope of CI ............................................................................................ 26 5.2 Promotion of public relations activities ......................................................................................... 27 5.3 Promotion of international cooperation ......................................................................................... 27 5.4 Promotion of security by design ................................................................................................... 28 5.5 Appeal to top management ........................................................................................................... 28 5.6 Promotion of the development of human resources ........................................................................ 29 5.7 Ensuring Security in relation to the My Number System ................................................................ 29 5.8 Maintenance of reference of standards and guides.......................................................................... 29 IV. Activities Taken by Stakeholders....................................................................................................... 31 i

Select target paragraph3