III. Policies for CIP
5. Enhancement of the Basis for CIP
Therefore, the Cabinet Secretariat cooperates with responsible ministries for CI and the cybersecurity related agencies
and continues to enhance international cooperation by communicating Japan's initiatives through active utilization of
bilateral, inter-regional and multilateral frameworks.
Specifically, the Cabinet Secretariat actively introduces Japan's unique initiatives such as cross-sectoral exercises
through talks and speeches using frameworks with the US and Europe, ASEAN and Meridian, thereby strengthening
international cooperation. Such cooperative relationships serve as the basis for information sharing concerning foreign
threats, incident responses, and best practices, and also contribute to enhancing international CIP capability. The
information thus obtained from foreign countries that will contribute to enhancing Japan's CIP capability is to be
positively provided to domestic stakeholders.
In addition, CI operators are also expected to make efforts for diversified and multilateral international cooperation
by ascertaining overseas trends through participation in international conferences and expansion of their initiatives
related to cybersecurity measures to foreign companies in the same industry and sharing information with foreign ISACs,
etc.
5.4 Promotion of security by design
The Cabinet Secretariat promotes the concept of security by design, which means to prioritize security from the stage
of system planning and designing, as a common value among stakeholders. CI operators should promote use of products
certified under a third-party certification system in compliance with international standards when procuring and
operating control systems and related equipment based on the concept of security by design.
5.5 Appeal to top management
As observed in the Cybersecurity Management Guidelines and the Basic Approach to Cybersecurity for Corporate
Management, cybersecurity measures have come to be emphasized as significant managerial issues. Top management
of CI operators is expected to properly recognize the necessity and implement the following actions.
(i) Recognize top management's responsibility for ensuring cybersecurity and exert their leadership in cybersecurity
measures from the viewpoint of mission assurance
(ii) With the awareness that their individual efforts also contribute to the development of society as a whole, take
cybersecurity measures while involving their supply chains (business partners, subsidiaries and affiliated
companies, etc.)
(iii) Develop incident readiness even in normal times and disclose information on responses properly in the event of
an incident from the perspective of gaining trust and nurturing a sense of security among stakeholders
(iv) Constantly secure management resources, such as budgets, systems and personnel, necessary for the
abovementioned measures and devise risk-based allocation thereof; For CI, whose systems are large in scale and
28