III. Policies for CIP 5. Enhancement of the Basis for CIP Therefore, the Cabinet Secretariat cooperates with responsible ministries for CI and the cybersecurity related agencies and continues to enhance international cooperation by communicating Japan's initiatives through active utilization of bilateral, inter-regional and multilateral frameworks. Specifically, the Cabinet Secretariat actively introduces Japan's unique initiatives such as cross-sectoral exercises through talks and speeches using frameworks with the US and Europe, ASEAN and Meridian, thereby strengthening international cooperation. Such cooperative relationships serve as the basis for information sharing concerning foreign threats, incident responses, and best practices, and also contribute to enhancing international CIP capability. The information thus obtained from foreign countries that will contribute to enhancing Japan's CIP capability is to be positively provided to domestic stakeholders. In addition, CI operators are also expected to make efforts for diversified and multilateral international cooperation by ascertaining overseas trends through participation in international conferences and expansion of their initiatives related to cybersecurity measures to foreign companies in the same industry and sharing information with foreign ISACs, etc. 5.4 Promotion of security by design The Cabinet Secretariat promotes the concept of security by design, which means to prioritize security from the stage of system planning and designing, as a common value among stakeholders. CI operators should promote use of products certified under a third-party certification system in compliance with international standards when procuring and operating control systems and related equipment based on the concept of security by design. 5.5 Appeal to top management As observed in the Cybersecurity Management Guidelines and the Basic Approach to Cybersecurity for Corporate Management, cybersecurity measures have come to be emphasized as significant managerial issues. Top management of CI operators is expected to properly recognize the necessity and implement the following actions. (i) Recognize top management's responsibility for ensuring cybersecurity and exert their leadership in cybersecurity measures from the viewpoint of mission assurance (ii) With the awareness that their individual efforts also contribute to the development of society as a whole, take cybersecurity measures while involving their supply chains (business partners, subsidiaries and affiliated companies, etc.) (iii) Develop incident readiness even in normal times and disclose information on responses properly in the event of an incident from the perspective of gaining trust and nurturing a sense of security among stakeholders (iv) Constantly secure management resources, such as budgets, systems and personnel, necessary for the abovementioned measures and devise risk-based allocation thereof; For CI, whose systems are large in scale and 28

Select target paragraph3