IV. Activities Taken by Stakeholders 5. Voluntary Activities by CI Operators 5. Voluntary Activities by CI Operators (1) Maintenance and promotion of the safety principles (i) When the relevant operator has established the safety principles, it should revise them as necessary, in addition to implementing periodic analysis and verification thereof (ii) When the relevant operator has established the safety principles, it should cooperate with the Cabinet Secretariat every year with its efforts to ascertain the conditions of continued improvements of the safety principles, etc. (iii) Consider environmental arrangement for packaging and implementing cybersecurity measures based on the safety principles (iv) Identify issues from operation of cybersecurity measures, internal and external audits, environmental change studies/analysis results related to IT, exercises/training and response to CISs outages, and continually amend the safety principles through risk assessment (v) Cooperate with the Cabinet Secretariat every year with a survey on the dissemination of the safety principles, etc. (2) Enhancement of information sharing system (i) Cooperate with the CEPTOAR council, CEPTOARs, responsible ministries for CI, and the Cabinet Secretariat and operate the information sharing system during normal circumstances and upon a CISs crisis (ii) Carry out information sharing to NISC regarding system failures (iii) Collect information, etc. related to attack methods and recovery methods (iv) Carry out supplemental information sharing based on consensus with the cybersecurity related agencies (v) Carry out activities at the CEPTOAR council (vi) Rating of seriousness of cases involving IT and OT (3) Enhancement of incident response capability (i) Utilize verification of information communication functions (CEPTOAR training) provided by the Cabinet Secretariat and enhance own information sharing systems (ii) Cooperate with planning of cross-sectoral exercise scenarios, implementation methods and verification issues, etc. and implementation of cross-sectoral exercises (iii) Participate in cross-sectoral exercises (iv) Cooperate with study of measures for improving cross-sectoral exercises (v) Utilize the results of cross-sectoral exercises for own procedures for early recovery in the event of ICSs outages and IT-BCP etc. as necessary (4) Risk management and preparation of incident readiness (i) When the relevant operator conducts risk assessment for the Olympic and Paralympic games, conduct said risk assessment and implement required responses based on the results thereof; Make necessary collaboration with the Cabinet Secretariat and other stakeholders, such as information sharing and opinion exchanges, in this process (ii) Promote and strengthen risk assessment based on the concept of mission assurance; Ensure allocation of resources and develop own organizational structure required therefor 36

Select target paragraph3