V. Assessment and Verification 1. Assessment of This Cybersecurity Policy V. Assessment and Verification Assessment and verification of this Cybersecurity Policy are conducted from the following two perspectives. ○ Assessment from the perspective of measuring the outcome Assessment is conducted from the perspective of measuring to what extent society has come closer to the envisaged future through activities based on this Cybersecurity Policy. Assessment here means to check the validity of activities based on this Cybersecurity Policy in light of the achievements during the term of this Cybersecurity Policy (goals of this Cybersecurity Policy) in the process of reaching the envisaged future (ultimate purpose of the Cybersecurity Policy) and extract issues to be addressed for the purpose of improving individual policies. ○ Verification from the perspective of measuring the output Verification is conducted from the perspective of measuring the results brought about by individual activities based on this Cybersecurity Policy with the aim of ensuring their steady progress and continued improvements. Verification here means to check the progress of individual activities during each fiscal year objectively using prescribed indicators and decide basic policies from the following fiscal year onward. 1. Assessment of This Cybersecurity Policy 1.1 Assessment Assessment from the perspective of measuring the outcome (assessment of this Cybersecurity Policy) is conducted in light of the goals of this Cybersecurity Policy. Considering that the outcome is brought about as a result of mutually related various initiatives based on this Cybersecurity Policy, assessment should be conducted not for each policy separately but for the entirety of measures contributing to CIP, in other words, comprehensively for the overall framework of this Cybersecurity Policy. Assessment of this Cybersecurity Policy is conducted by the Cybersecurity Strategic Headquarters, and surveys and reviews necessary therefor are conducted by the CI Expert Committee with cooperation of responsible ministries for CI. Assessment of the Cybersecurity Policy is generally conducted once every three years, in principle, because assessment of annual changes cannot easily lead to improvements due to the nature of the Cybersecurity Policy. However, as the Olympic and Paralympic games are scheduled in 2020, this Cybersecurity Policy should be assessed on a timely basis. This principle of conducting assessment once every three years does not apply when any significant changes beyond expectations occur in social trends, etc. 1.2 Envisaged future 1.2.1 Outline of the envisaged future The future images expected to be realized through the initiatives based on this Cybersecurity Policy are as follows. 40

Select target paragraph3