III. Policies for CIP
4. Risk Management and Preparation of Incident Readiness
(ii) Generalize the Risk Assessment Guidelines for Mission Assurance so that they can be utilized by CI operators in
their risk assessment also in normal times and improve the Manual for Prioritization of Information Security
Measures, thereby further disseminating the purpose and methods of risk assessment based on the concept of
mission assurance widely among CI operators
Through these activities, it is expected that individual CI operators' risk assessment will achieve a certain standard
and a certain level of accuracy in the future.
4.2.2 Investigation and analysis of new risk sources and risks, etc.
In light of changes in the environment surrounding CI sectors, the Cabinet Secretariat conducts surveys on the current
status and trends of major facilities and technologies from the perspective of cybersecurity, and analyses new risk
sources inherent to such facilities and technologies and risks arising therefrom (hereinafter referred to as "new risk
sources and risks").
Additionally, the Cabinet Secretariat continues analysis of spillover effects of CISs outages. In detail, the following
activities are carried out, also taking into account viewpoints of the efficiency of each study/analysis and mutual
reflection with other policies, and the results of the studies/analyses are provided to CI operators and are also utilized
for improving measures under this Cybersecurity Policy.
(1) Environmental change studies
The Cabinet Secretariat carries out current status studies on environmental changes including analyses of new risk
sources and risks, targeting IoT, FinTech, and other new technologies and systems expected to spread in CI sectors in
the medium- and long-term, as well as institutions related thereto. As these studies and analyses produce better results
when conducted over time in accordance with environmental changes, the Cabinet Secretariat conducts them
continuously by flexibly changing the targets and scopes. New risk sources and risks that are common only across
specific sectors, such as control systems or information systems, but could have a significant influence if not on all
sectors will also be targeted.
When any new risk sources and risks are identified through these studies and analyses or any new CI sectors are
newly targeted, analysis of commonality across these sectors are to be carried out as a detailed investigation, as necessary.
(2) Interdependency analysis
As utilization of ICT continues to develop in each CI sector and interdependent relationships among CI sectors and
with other sectors continue to grow, the understanding of interdependency in CI sectors becomes more and more
important for conducting risk assessment and taking effective recovery measures in the event of CISs outages.
For this reason, in this Cybersecurity Policy, the Cabinet Secretariat continuously carries out interdependency analysis,
and also conducts restudy or reanalysis based on the results of the analyses under preceding Cybersecurity Policies if
there are any changes in interdependency due to environmental changes or addition of new CI sectors.
In addition, as the degree of IT dependency in CI sectors is closely related to interdependency analysis, detailed IT
dependency studies are also periodically implemented.
23