III. Policies for CIP 4. Risk Management and Preparation of Incident Readiness 4. Risk Management and Preparation of Incident Readiness Cases of personal information leakage caused by cyberattacks or information system failures and economic loss due to suspension of CI services have come to be frequently reported along with the increase in ICT utilization. Damage to the real world is becoming more and more serious. It is necessary to note that highly sophisticated cyberattacks, such as zero-day attacks targeting undisclosed vulnerability, and internal fraud "can no longer be prevented completely in advance." Under such circumstances, CI operators should inevitably position preparedness for cybersecurity risks in their business strategy and strategically take risk response measures based on the results of risk assessment. From the viewpoint of mission assurance, they need to put in place appropriate risk assessment-based incident readiness to ensure safe and continuous provision of CI services even in the event of a cyberattack, etc. It is also important for them to build a mechanism under which these activities as a whole (risk management) function sustainably and effectively.6 In order to prioritize measures to be taken by CI operators based on the concept of mission assurance, this Cybersecurity Policy expansively positions the key policy "risk management" under the Third Policy as "risk management and preparation of incident readiness," and newly introduces measures for supporting CI operators' initiatives for strengthening internal control to enable proper decision making based on risk assessment and their voluntary and autonomous efforts for preparing incident readiness for business continuity, while maintaining measures for risk management under the Third Policy. 4.1 Basic view of risk management Risk management should be independently implemented by each CI operator. However, in circumstances where information sharing and discussions based on common risk management views or terms are not observed among stakeholders, there is a possibility that the activities in this Cybersecurity Policy will not be effectively utilized in the risk management of each CI operator. For this reason, it is preferable for each stakeholder to utilize the internationally standard views of risk management and related terminology definitions for cybersecurity etc. In details, views based on the framework shown in Table 3 below and the terminology definitions used therein should be adopted to the extent possible in concrete activities and related materials. 6 From the viewpoint of mission assurance, CI operators should conduct risk assessment to comprehensively ascertain impacts on the provision of CI services, taking into account not only the influence of system failures directly relating to CI services but also spillover effects of indirectly related system failures. 21

Select target paragraph3