V. Assessment and Verification
2. Verification of This Cybersecurity Policy
through individual outputs and the outcomes of policy groups. For this reason, in order to collect the supplementary
information required for assessment, supplementary studies are to be carried out every fiscal year in principle.
Supplementary studies aim to obtain materials for checking the validity of CI operators' initiatives based on this
Cybersecurity Policy, such as issues of their cybersecurity measures and good practices, by way of following up samples
of their concrete responses to CISs outages.
Study results are to be publicized to the extent possible.
2. Verification of This Cybersecurity Policy
2.1 Verification
Verification from the perspective of measuring output (verification of the progress in each fiscal year) is conducted
for policy groups indicated in "III. Policies for CIP." Because all of the cybersecurity measures based on this
Cybersecurity Policy are multilayered among multiple stakeholders, a wide variety of items can be imagined as indexes
for use in verification. However, verification is to be conducted analytically after roughly classifying and setting both
indexes to be used for verification of measures under this Cybersecurity Policy taken by CI operators and indexes to be
used for verification of policies by government organizations. For the indexes for each measure for CIP policies under
this Cybersecurity Policy, it is important to appropriately interpret the meaning of the values rather than to be overlyfocused on the quantity or any fluctuations.
Verification of this Cybersecurity Policy is conducted by the Cabinet Secretariat every fiscal year under the initiative
of the Cybersecurity Strategic Headquarters with cooperation of CI operators and responsible ministries for CI. The
results are referred to the Cybersecurity Strategic Headquarters after deliberations at the CI Expert Committee.
2.2 Verification of measures taken by CI operators
As the party with the most fundamental responsibility for the safe and continuous provision of CI services, CI
operators implement cybersecurity measures on a daily basis. In order to continually and steadily improve such
initiatives and in order to make government's support for CI operators' initiatives more effective, it is important to
objectively verify the outcome of the implemented cybersecurity measures.
Based on the purpose of CIP, i.e., ensuring safe and continuous provision of CI services, the conditions of the
countermeasures and responses to CISs outages in each CI sector is to be verified.
Measures of individual CI operators include independent initiatives based on the management decisions of each
operator, and it is therefore inappropriate to assess measures through comparison of CISs outage conditions for each CI
operator or each sector. For this reason, it is reasonable to carry out assessment of measures based on self-assessment
by CI operators, and each CI operator should work towards their own improvement. CI operators should also verify
44