III. Policies for CIP
4. Risk Management and Preparation of Incident Readiness
The Cabinet Secretariat promotes risk communication and consultation implemented by stakeholders related to CI
protection with the aim of encouraging information and opinion exchanges among internal stakeholders and also
contributing to the development of cross-sectoral information and opinion exchanges. Concrete activities are as follows.
(i) Promote risk communication and consultation among top management, cybersecurity departments, departments
responsible for information systems and control systems, user departments, and other internal stakeholders
(ii) Utilize the CEPTOAR council and cross-sectoral exercises and promote enhancement of information and opinion
exchanges in cooperation with diverse stakeholders, and collect information necessary for studies and analyses of
new risk sources and risks
4.2.5 Promotion of monitoring and review
The status ascertained as a result of risk assessment is expected to change over time. In order to identify any
circumstances or other factors that may change or invalidate risk assessment results and properly respond to fluctuations
in risks, it is necessary to create a mechanism to manage risks in an appropriate manner such as constantly monitoring
and revising risk assessment results as needed or otherwise, and maintain risk management functions continuously and
effectively.
Therefore, the Cabinet Secretariat promotes CI operators' monitoring and review of their risk management and
incident readiness. More specifically, the Cabinet Secretariat provides key points for audits compiled based on the
viewpoint of mission assurance to assist CI operators' voluntary internal audits, etc., thereby promoting their monitoring
and review.
4.3 Establishment of a process of synergizing the relevant policies
The Cabinet Secretariat utilizes the results of studies and analyses of the abovementioned measures in activities under
other key policies as reference data for the purpose of contributing to other policies in this Cybersecurity Policy.
In addition, the Cabinet Secretariat conducts studies and analyses as necessary regarding new risk sources and risks
requiring cross-sectoral measures that are revealed as a result of implementing other policies.
25