II. Executive Summary of This Cybersecurity Policy
II. Executive Summary of This Cybersecurity Policy
The key points for this Cybersecurity Policy ([i] Purpose of CIP, [ii] Basic principles, [iii] Responsibility of
stakeholders, such as CI operators, government organizations, and cybersecurity related agencies, and in particular, [iv]
Responsibility of top management) are as follows.
[i] Purpose of CIP
The purpose of CIP is to maintain safe and continuous provision of CI services, based on the concept of
mission assurance, by preventing serious impact on national life and socioeconomic activities caused by any
CISs outages resulting from cyberattacks, natural disasters or other causes to the extent possible and ensuring
prompt recovery from outages.
[ii] Basic concept
In the first place, CI operators should implement cybersecurity measures on their own responsibility, but
collaborative efforts among stakeholders are indispensable on the basis of mission assurance for all CIs.
Therefore, the purpose of CIP should be achieved through all-out efforts by diverse stakeholders, thereby
nurturing a sense of security among the general public, promoting social growth and resilience, and
strengthening international competitiveness.
・ CI operators should respectively take measures and make efforts for continuous improvement of those
measures as entities providing services and bearing social responsibilities.
・ Government organizations should provide necessary support for cybersecurity measures of CI operators.
・ Each CI operator should cooperate and coordinate with other stakeholders due to the limit of each operator's
individual cybersecurity measures to address various threats.
[iii] Responsibility of stakeholders
・ All stakeholders should periodically check the progress of their own measures and policies as part of
relevant efforts and accurately recognize the current circumstances, and proactively determine the goals of
relevant activities. In addition, stakeholders should enhance their cooperation with each other, taking into
account the status of other stakeholders' relevant activities.
・ All stakeholders should understand the 5W1H (when, where, who, why, what and how) of responses to
CISs outages depending on the scale thereof and should be able to calmly address signs or occurrence of
any CISs outages. They should also be capable to cooperate with other stakeholders and respond in a
cooperative and concerted manner in addition to ensuring robust communication among various
stakeholders and taking proactive measures.
[iv] Responsibility of top management
In addition to the above, top management should understand the necessity of the following matters and take
relevant measures.
・Recognize their responsibility for ensuring cybersecurity and exert their leadership in cybersecurity measures
from the viewpoint of mission assurance
・With the awareness that their individual efforts also contribute to the development of society as a whole, take
cybersecurity measures while involving their supply chains (business partners, subsidiaries and affiliated
companies, etc.)
・Develop incident readiness even in normal times and disclose information on responses properly in the event
of an incident from the perspective of gaining trust and nurturing a sense of security among stakeholders
・Constantly secure management resources, such as budgets, structure and personnel, necessary for the
abovementioned measures and appropriately allocate them from a risk-based perspective
10