1. Activities by the Cabinet Secretariat ................................................................................................... 31 2. Activities by Responsible Ministries for CI ......................................................................................... 33 3. Activities by Cybersecurity Related Ministries .................................................................................... 35 4. Activities by Crisis Management Ministries and Disaster Prevention Related Ministries......................... 35 5. Voluntary Activities by CI Operators .................................................................................................. 36 6. Voluntary Activities by CEPTOARs and the CEPTOAR Secretariat ..................................................... 37 7. Voluntary Activities by the CEPTOAR Council .................................................................................. 38 8. Voluntary Activities by Cybersecurity Related Agencies ...................................................................... 38 9. Voluntary Activities by Cyberspace-related Operators.......................................................................... 39 V. Assessment and Verification ............................................................................................................... 40 1. Assessment of This Cybersecurity Policy............................................................................................ 40 1.1 Assessment ................................................................................................................................. 40 1.2 Envisaged future ......................................................................................................................... 40 1.3 Goals of this Cybersecurity Policy ................................................................................................ 42 1.4 Supplementary studies ................................................................................................................. 43 2. Verification of This Cybersecurity Policy............................................................................................ 44 2.1 Verification ................................................................................................................................. 44 2.2 Verification of measures taken by CI operators .............................................................................. 44 2.3 Verification of policies by government organizations...................................................................... 45 VI. Revision of This Cybersecurity Policy .............................................................................................. 47 ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC ...................................................................................................................................................... 48 1. Information Related to System Failures .............................................................................................. 48 2. Information Sharing to NISC from CI Operators ................................................................................. 50 2.1 Cases requiring information sharing to NISC................................................................................. 50 2.2 Framework for information sharing to NISC ................................................................................. 50 2.3 Handling of information shared to NISC ....................................................................................... 51 3. Information Sharing from NISC......................................................................................................... 52 3.1 Cases requiring information sharing from NISC ............................................................................ 52 3.2 Framework for information sharing from NISC ............................................................................. 52 3.3 Cooperation for information sharing from NISC ............................................................................ 53 ANNEX 1. SCOPE OF CI OPERATORS AND CRITICAL INFORMATION SYSTEM EXAMPLES ......... 54 ANNEX 2. EXPLANATION OF CI SERVICES AND CI SERVICE OUTAGE EXAMPLES ...................... 55 ANNEX 3. CATEGORIES OF EVENTS AND CAUSES FOR INFORMATION SHARING TO NISC........ 61 ANNEX 4-1. INFORMATION SHARING SYSTEM ................................................................................ 62 ANNEX 4-2. RESPONSIBILITIES OF EACH STAKEHOLDER IN INFORMATION SHARING SYSTEM ............................................................................................................................................................... 63 ANNEX 5. DEFINITIONS / GLOSSARIES ............................................................................................. 64 ii

Select target paragraph3