I. Introduction 3. Assessment of the Third Policy With the aim of promoting voluntary efforts by CI operators, the Guidelines for Establishing Safety Principles for Ensuring CI Security and Attachment thereof (the "Guidelines for Safety Principles") were revised in line with the PDCA (Plan-Do-Check-Act) cycle. Each CI sector guideline and codes of conduct of respective CI operators such as internal policies are now being reviewed on a voluntary basis in response to the revision of the Guidelines for Safety Principles. Given these, it is considered that the PDCA cycle itself, which allows CI operators to judge the necessity of review and make improvements independently, is prevailing as their code of conduct. However, the activities of "Check" and "Act" in the PDCA cycle are not sufficiently established, nor can be recognized to have been disseminated to the degree that they are accepted as the code of conduct, as shown in the results of the survey concerning the dissemination of safety principles, which was conducted by the Cabinet Secretariat with the aim of ascertaining the current status of cybersecurity measures. The establishment of these activities is one of the remaining challenges. In the future, it is hoped that such behavior based on the abovementioned code of conduct is disseminated among all stakeholders, encouraging them to continue efforts in line with this, and cybersecurity culture is thus formed among them. < Envisaged Future > Stakeholders communicate with each other on a regular basis with the aim of strengthening measures in preparation for any CISs outages and are making improvements to their measures constantly in order to reflect experience concerning incident responses in their future efforts. < Assessment > Active information sharing between the public sector and the private sector is steadily progressing, with an increasing number of reports being made from CI operators to responsible ministries and the National Center of Incident Readiness and Strategy for Cybersecurity (NISC). Regarding information sharing in the private sector, the secretariat of the CEPTOAR council was transferred to the private sector, thereby enhancing their independence and positive attitude in information sharing among CEPTOARs. Additionally, members of each CEPTOAR have increased and broader information exchanges have been contributing to enriching knowledge on cybersecurity and creating ties among responsible personnel. The development of a better environment for communication among stakeholders has thus been steadily advancing. Furthermore, ISACs2 have been organized in some sectors and information sharing and countermeasures against cyberattacks are progressing. Cross-sectoral exercises and training by CEPTOARs are also being conducted continuously to enhance incident response capability. Participants are increasing significantly and response scenarios are made more and more sophisticated. These activities are found to have contributed to enhancing response capability in line with the needs of CI operators. In the meantime, as threats are becoming increasingly serious, it is required to continue to improve communication methods qualitatively and quantitatively through their classification and specification in light of respective purposes in 2 ISAC: Information Sharing and Analysis Center 4

Select target paragraph3