Table of Contents
I. Introduction .......................................................................................................................................... 1
1. Direction for Establishing the Cybersecurity Policy ............................................................................... 1
2. Structure of This Cybersecurity Policy ................................................................................................. 3
3. Assessment of the Third Policy ............................................................................................................ 3
4. Outcome of the Review for the Revision of this Cybersecurity Policy ..................................................... 6
4.1 Purpose of CIP .............................................................................................................................. 6
4.2 Concept of Mission Assurance ....................................................................................................... 7
4.3 Priorities in This Cybersecurity Policy ............................................................................................ 7
4.4 Policy Groups and Direction of Reinforcing and Refining the Components of the Cybersecurity Policy8
II. Executive Summary of This Cybersecurity Policy ............................................................................. 10
III. Policies for CIP ................................................................................................................................ 12
1. Maintenance and Promotion of the Safety Principles ........................................................................... 12
1.1 Continual improvement of the Guidelines for Safety Principles....................................................... 12
1.2 Continual improvement of the safety principles ............................................................................. 13
1.3 Promotion of the safety principles................................................................................................. 13
2. Enhancement of Information Sharing System ..................................................................................... 14
2.1 Information sharing system during the term of this Cybersecurity Policy ......................................... 14
2.2 Further promotion of information sharing...................................................................................... 15
2.3 Promotion of CI operators' activities ............................................................................................. 16
3. Enhancement of Incident Response Capability .................................................................................... 18
3.1 Improvement of cross-sectoral exercises ....................................................................................... 18
3.2 CEPTOAR communication training ............................................................................................. 19
4. Risk Management and Preparation of Incident Readiness .................................................................... 21
4.1 Basic view of risk management .................................................................................................... 21
4.2 Promotion of risk management..................................................................................................... 22
4.3 Establishment of a process of synergizing the relevant policies ....................................................... 25
5. Enhancement of the Basis for CIP ...................................................................................................... 26
5.1 Review of the protection scope of CI ............................................................................................ 26
5.2 Promotion of public relations activities ......................................................................................... 27
5.3 Promotion of international cooperation ......................................................................................... 27
5.4 Promotion of security by design ................................................................................................... 28
5.5 Appeal to top management ........................................................................................................... 28
5.6 Promotion of the development of human resources ........................................................................ 29
5.7 Ensuring Security in relation to the My Number System ................................................................ 29
5.8 Maintenance of reference of standards and guides.......................................................................... 29
IV. Activities Taken by Stakeholders....................................................................................................... 31
i