III. Policies for CIP 4. Risk Management and Preparation of Incident Readiness Table 3 Standard Risk Management Process (example) Risk management Establishing the context of organization Risk assessment Risk identification Risk analysis Risk assessment Risk treatment Risk acceptance Risk communication and consultation Monitoring and review 4.2 Promotion of risk management Risk management should basically be optimized by each CI operator individually to suit their organization. The significance of risk assessment seems to have been widely recognized by many CI operators as suggested by the fact that an increasing number of CI operators mention the implementation of risk assessment in cybersecurity basic policies they voluntarily establish. On the other hand, some CI operators, despite being aware of the significance, have yet to conduct risk assessment due to such reasons as the lack of knowledge on concrete measures. The concept and implementation methods of risk assessment have not been necessarily disseminated sufficiently. It is also true that some activities, such as cross-sectoral study/analysis and opinion exchanges, are not easily carried out solely within individual CI operators. Therefore, the Cabinet Secretariat takes the following measures to promote risk management of CI operators. 4.2.1 Dissemination of risk assessment It is necessary to maintain safe and continuous provision of CI services, which are fulfilling indispensable roles and functions in socioeconomic systems. Accordingly, what should be prioritized is the concept of mission assurance, under which CI operators fulfill expected roles and functions and conduct risk assessment for the purpose of ensuring safety of CI services they provide and continue providing services by preventing suspension or quality loss unacceptable for themselves and other stakeholders to the extent possible, and promote risk countermeasures under top management's comprehensive judgement based on the results of risk assessment, thereby aiming to achieve their goals. Given these, the Cabinet Secretariat endeavors to encourage more and more CI operators to conduct risk assessment based on the concept of mission assurance. Concrete activities are as follows. (i) Disseminate the purpose and methods of risk assessment based on the concept of mission assurance widely among relevant entities by encouraging them to refer to the Risk Assessment Guidelines for Mission Assurance7 in risk assessment looking toward the Olympic and Paralympic games, and also promote such risk assessment at related briefing sessions and lectures 7 Guidelines established by the Cabinet Secretariat in September 2016, targeting providers of CI services that may exert significant influence on the operation of the Olympic and Paralympic games 22

Select target paragraph3