I. Introduction
4. Outcome of the Review for the Revision of this Cybersecurity Policy
disseminated to other CI operators within these sectors and those in other CI sectors. Therefore, this point is reflected in
activities under this Cybersecurity Policy.
4.3.2 Enhancement of information sharing structure toward the Olympic and Paralympic games
Looking ahead to big international events, such as the Olympic and Paralympic games, Japan is attracting the attention
of the international community but at the same time may also be subject to malicious attacks, posing a possibility that
risks of cyberattacks, etc. may increase. In order to surely protect these international events and CI from heightened
threats of cyberattacks, stakeholders need to detect threats early and take prompt and appropriate countermeasures based
on helpful and practical information. Therefore, this point is reflected in the activities for the enhancement of information
sharing structure under this Cybersecurity Policy.
Assuming that these activities are to be handed down as a legacy after the Olympic and Paralympic games, modeling
of know-how and other knowledge concerning the formulation of relevant systems will be discussed.
4.3.3. Promotion of incident readiness based on risk management
Considering the fact that cyberattacks targeting CI are becoming more and more serious and in light of background
changes in the social and technological environment, CI operators are required to develop appropriate incident readiness
against cyberattacks, etc. so that they can continue the provision of CI services while ensuring safety of their services
and preventing suspension or quality loss unacceptable for themselves and other stakeholders to the extent possible.
Additionally, it is necessary to enhance and promote efforts for risk assessment, risk communication and consultation,
monitoring and review in the process of risk management in order to develop appropriate incident readiness from the
viewpoint of mission assurance. Therefore, this point is reflected in the activities for the risk management and
development of incident readiness under this Cybersecurity Policy.
4.4 Policy Groups and Direction of Reinforcing and Refining the Components of the Cybersecurity Policy
Policy groups and direction of reinforcing and refining the components of the Cybersecurity Policy are as shown in
the following table.
Table 2 Policy Groups and Direction of Reinforcing and Refining the Components of the Cybersecurity Policy
Policy groups in
this
Cybersecurity
Policy
1. Maintenance
and promotion
of the safety
principles
Relation with policy
groups in the Third Policy
Direction of reinforcing and refining the components of the
Cybersecurity Policy
Basically keep the element
of "[1] Maintenance and
promotion of the safety
principles" in the Third
Policy
○ Improve the safety principles prioritizing the importance of
the preparation of incident readiness, including awareness
and behavior required for top management and the
formulation of contingency plans, and the development of
organizations and human resources while keeping OT in
mind
8