V. Assessment and Verification
1. Assessment of This Cybersecurity Policy
- The attitude to share information as much as possible for enhancing the levels of cybersecurity measures is
positively evaluated as a common value.
- CI operators share an awareness that the occurrence of CISs outages is not something to be hidden but something
that should instead be shared among internal stakeholders involved in cybersecurity measures.
○ The following matters related to issue identification, risk assessment and improvement of measures are fully
disseminated among CI operators.
- Based on this Cybersecurity Policy, stakeholders cooperate to carry out cybersecurity measures and are aware
of remaining risks in their own measures and the extent of cybersecurity measures.
- Properly detecting changes in risk sources resulting from the development of various measures and
environmental changes and changes in risks in relation to CISs outages, CI operators are voluntarily carrying
out independent measures and making adjustments as necessary.
- CI operators have become able to take appropriate measures in preparation for CISs outages, and as a result, the
risk of their serious impact on the national life and socioeconomic activities is minimized to the greatest degree
possible.
- These initiatives serve as a driving force for the continued improvements of the measures.
○ The following matters related to information sharing are fully disseminated among CI operators.
- CI operators have information on conditions of the occurrence of CISs outages, and relevant information is
shared with external stakeholders through each sector's CEPTOARs and CEPTOAR council as necessary.
Official or unofficial cooperation is thus carried out.
(3) Cabinet Secretariat
Detailed future visions for the Cabinet Secretariat are as follows.
○ The Cabinet Secretariat fulfills a comprehensive coordination function for advancing more effective measures.
Diverse information which contributes to cybersecurity measures has come to be accumulated at the Cabinet
Secretariat through the key policies under this Cybersecurity Policy and cooperation with stakeholders based on
relevant information is being mobilized.
○ The Cabinet Secretariat has obtained an understanding of risks related to serious risk sources and CISs outages, in
particular. When it is difficult for CI operators alone to address such risks, organic cooperation and coordination
for studying and implementing resolutions can promptly be organized.
1.3 Goals of this Cybersecurity Policy
Goals to be achieved during the term of this Cybersecurity Policy for realizing the envisaged future are as follows.
(1) Goals under the key policy "maintenance and promotion of the safety principles"
42