I. Introduction
4. Outcome of the Review for the Revision of this Cybersecurity Policy
steadily based on the five key policies. Therefore, it can be said that the Cybersecurity Policy and activities thereunder
have been properly reviewed through regular assessments.
The basic framework for CIP should be maintained as the Cybersecurity Policy and efforts need to be continued into
the future based thereon.
< Envisaged Future >
These efforts being made by stakeholders have become steadily rooted as measures contributing to the
sustainable development of society.
< Assessment >
Efforts based on the Cybersecurity Policy are found to have been progressed steadily as mentioned above.
Therefore, the basic structure consisting of the five key policies in the Third Policy, which have deeply taken root
among stakeholders, should be maintained and activities under each policy should be strengthened. In light of the status
of cyberattacks targeting CI and background changes in the social and technological environment, and based on the
concept of mission assurance, due consideration should be given to [i] further promotion of leading activities by some
operators for protecting CI as a whole, [ii] enhancement of information sharing structure toward the Olympic and
Paralympic games, and [iii] promotion of incident readiness based on risk management. These points should be
positioned as policy priorities in this Cybersecurity Policy and concrete activities under each of the five key policies
need to be enhanced and improved while keeping them in mind.
4. Outcome of the Review for the Revision of this Cybersecurity Policy
As explained above, the basic structure consisting of the five key policies in the Third Policy, which have taken deep
root among stakeholders, are maintained in this Cybersecurity Policy, in light of the issues extracted through the
assessment of the Third Policy and the Cybersecurity Strategy. It was decided to first clarify the purpose of CIP and
decide policy priorities, in light of the status of cyberattacks targeting CI and background changes in the social and
technological environment and also based on the concept of mission assurance, and then consider enhancement and
improvement of activities under this Cybersecurity Policy.
4.1 Purpose of CIP
This Cybersecurity Policy maintains the purpose of CIP under the Third Policy but clearly states "ensuring safe and
continuous provision of CI services" as the top priority based on the concept of mission assurance.
6