V. Assessment and Verification
1. Assessment of This Cybersecurity Policy
The outcome expected under this key policy is that stakeholders involved in cybersecurity measures understand what
they themselves should do in accordance with the safety principles and steadily carry out required activities while
periodically self-checking the achievements, and such behavior has been established as their code of conduct.
(2) Goals under the key policy "enhancement of information sharing system"
The outcome expected under this key policy is that CI operators can receive and utilize necessary information through
enhancement of information sharing based on the latest information sharing system and information sharing to and from
NISC, and strengthening of autonomous activities of each CEPTOAR.
(3) Goals under the key policy "enhancement of incident response capability"
The outcome expected under this key policy is that CI operators' incident response capability is enhanced through the
participation in cross-sectoral exercises and other exercises and training, and resulting verification of the CISs outage
early recovery process and IT-BCP, verification of the effectiveness of information sharing among stakeholders required
therefor, and technological improvement of response capability.
(4) Goals under the key policy "risk management and preparation of incident readiness"
The outcome expected under this key policy is that CI operators have come to conduct risk assessment based on the
concept of mission assurance in light of new risk sources and risks and have developed their incident readiness through
promoting and enhancing their risk management measures, and the overall risk management including these processes
functions sustainably and effectively.
(5) Goals under the key policy "enhancement of the basis for CIP"
The outcome expected under this key policy is as follows.
○ Efforts for reviewing the scope of protection are continued in light of the environmental changes and interdependence
of sectors inside and outside CI, and activities are promoted in accordance with the conditions of respective operators.
○ PR activities aim to broaden the understanding of the general public and people other than stakeholders concerning
the framework of the Cybersecurity Policy and are properly carried out in line with technological trends.
○ International cooperation, such as information exchanges and assistance and awareness-raising activities, is enhanced
through active utilization of bilateral, inter-regional and multilateral frameworks.
○ Developed reference of standards and guides has disseminated and been fully utilized by CI operators.
1.4 Supplementary studies
When carrying out assessment of the framework of this Cybersecurity Policy, it is important to carry out
comprehensive assessment after appropriately ascertaining the conditions which cannot be completely identified only
43