III. Policies for CIP 2. Enhancement of Information Sharing System Furthermore, the information sharing system will be developed to allow the opening of a hotline between the Cabinet Secretariat and CI operators in an emergency to achieve prompt and efficient information sharing on cyberattacks, 24 hours a day, 365 days a year. Cybersecurity related agencies offer support for the collection and analysis of information on domestic and foreign incidents and incident responses from a neutral standpoint apart from individual companies, and therefore, it is effective and preferable that the Cabinet Secretariat, CI operators and cybersecurity related agencies, which have abundant knowledge on cybersecurity, closely collaborate with each other. Cybersecurity related agencies are expected to play a major role in Japan's information sharing system through anonymizing information based on consent of data sources and sharing such anonymized information positively with stakeholders. In the event of a CISs crisis due to a disaster or terror attack, etc., stakeholders should closely collaborate with each other in accordance with "Regarding the Government Initial Response System for Emergencies" (November 21, 2003, Cabinet resolution), while properly sharing information based on this Cybersecurity Policy. Given these, the information sharing system during the term of this Cybersecurity Policy is represented in "ANNEX 4-1. INFORMATION SHARING SYSTEM" and the roles of individual stakeholders are in "ANNEX 4-2. RESPONSIBILITIES OF EACH STAKEHOLDER". Diversification of reporting routes will be promoted on a trial basis even before the introduction of the new information sharing system. Examples of critical information systems and CISs outages are indicated in "ANNEX 1. SCOPE OF CI OPERATORS AND CRITICAL INFORMATION SYSTEM EXAMPLES" and "ANNEX 2. EXPLANATION OF CI SERVICES AND CI SERVICE OUTAGE EXAMPLES." The abovementioned measures are steadily promoted and construction of a system to share information with stakeholders will be developed while CISs outages and threat information is aggregated in the Cabinet Secretariat in a cross-sectoral manner and analyzed using the information sharing system mentioned above, in order to make it possible to promptly and properly respond to any threat to cybersecurity covering multiple sectors, such as IoT. 2.2 Further promotion of information sharing The Cabinet Secretariat continuously reviews the protection scope of CI (including the expansion of the scope of information sharing) in light of changes in the social and technological environment and interdependency among CI sectors, while clarifying information to be shared among CI operators, in order to further activate information sharing during the term of this Cybersecurity Policy. Information to be shared is defined, as in the Third Policy, to be "information concerning system failures, including CISs outages, signs and Hiyari-Hatto events (hereinafter, referred to as "information on system failures")" based on the idea indicated in "ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC" and "ANNEX 3. CATEGORIES OF EVENTS AND CAUSES FOR INFORMATION SHARING TO NISC". However, as affected areas and concrete actions differ depending on the seriousness of CISs outages and the significance of related information, this Cybersecurity Policy cites examples of the severity schema on CISs outages in the ATTACHMENT and the Cabinet Secretariat considers materialization of such criteria for the purpose of promoting 15

Select target paragraph3