I. Introduction
4. Outcome of the Review for the Revision of this Cybersecurity Policy
4.2 Concept of Mission Assurance
CI services are the very basis of national life and socioeconomic activities and suspension thereof may have a direct
and serious negative effect on the safety and ease of the general public. Therefore, stakeholders are required to make
efforts to ensure safe and continuous provision of CI services (mission assurance).
Mission assurance in this Cybersecurity Policy does not mean to oblige stakeholders to make a firm commitment to
ensuring CIP or maintaining CI functions, but to have them assume their responsibilities in the process of protecting CI
services and maintaining the functions thereof. This is the concept to require each stakeholder to properly make efforts
for necessary cybersecurity measures.
(1) Efforts required for CI operators
The top management of CI operators must be actively involved in deciding business strategies incorporating
preparedness for cybersecurity risks and taking measures to reduce such risks strategically based on the results of risk
assessment. They need to put in place an appropriate incident readiness to continue CI services even in the case of
receiving a cyberattack, etc., ensuring safety of their CI services and preventing suspension or quality loss unacceptable
for themselves and other stakeholders to the extent possible. Top management should develop internal control systems
concerning cybersecurity measures and must fulfill accountability to their own stakeholders concerning the fact that
they are properly taking measures for mission assurance.
(2) Efforts required for government organizations
Government organizations are required to set or review the scopes of CI and CI services to be protected as the basis
to support national life and socioeconomic activities, in collaboration with diverse stakeholders, and to offer necessary
support to CI operators for their abovementioned efforts. Government organizations must also fulfill accountability to
the general public concerning the fact that efforts are being made properly through the assessment of this Cybersecurity
Policy and PR activities.
4.3 Priorities in This Cybersecurity Policy
The following three priorities are to be reflected in activities under each policy.
4.3.1 Promotion of leading activities by CI operators (classification of CI operators in light of interdependency)
The utilization of ICT is increasingly spreading among CI operators and interdependency among sectors has become
deeper. In some sectors that are highly depended upon by other CISs and may cause a big impact in the case of outages
even for a relatively short period of time (such as electric power supply services, information and communication
services, and financial services), CI operators have voluntarily promoted highly advanced cybersecurity measures,
centered on major operators belonging to the relevant sectors. In order to protect CI as a whole from increasingly
sophisticated cyberattacks, etc., such leading activities need to be further enhanced and promoted and should also be
7