I. Introduction 4. Outcome of the Review for the Revision of this Cybersecurity Policy steadily based on the five key policies. Therefore, it can be said that the Cybersecurity Policy and activities thereunder have been properly reviewed through regular assessments. The basic framework for CIP should be maintained as the Cybersecurity Policy and efforts need to be continued into the future based thereon. < Envisaged Future > These efforts being made by stakeholders have become steadily rooted as measures contributing to the sustainable development of society. < Assessment > Efforts based on the Cybersecurity Policy are found to have been progressed steadily as mentioned above. Therefore, the basic structure consisting of the five key policies in the Third Policy, which have deeply taken root among stakeholders, should be maintained and activities under each policy should be strengthened. In light of the status of cyberattacks targeting CI and background changes in the social and technological environment, and based on the concept of mission assurance, due consideration should be given to [i] further promotion of leading activities by some operators for protecting CI as a whole, [ii] enhancement of information sharing structure toward the Olympic and Paralympic games, and [iii] promotion of incident readiness based on risk management. These points should be positioned as policy priorities in this Cybersecurity Policy and concrete activities under each of the five key policies need to be enhanced and improved while keeping them in mind. 4. Outcome of the Review for the Revision of this Cybersecurity Policy As explained above, the basic structure consisting of the five key policies in the Third Policy, which have taken deep root among stakeholders, are maintained in this Cybersecurity Policy, in light of the issues extracted through the assessment of the Third Policy and the Cybersecurity Strategy. It was decided to first clarify the purpose of CIP and decide policy priorities, in light of the status of cyberattacks targeting CI and background changes in the social and technological environment and also based on the concept of mission assurance, and then consider enhancement and improvement of activities under this Cybersecurity Policy. 4.1 Purpose of CIP This Cybersecurity Policy maintains the purpose of CIP under the Third Policy but clearly states "ensuring safe and continuous provision of CI services" as the top priority based on the concept of mission assurance. 6

Select target paragraph3