I. Introduction
1. Direction for Establishing the Cybersecurity Policy
I. Introduction
1. Direction for Establishing the Cybersecurity Policy
National life and socioeconomic activities fully depend on diverse social infrastructures, and information systems are
being broadly utilized to enable infrastructures to properly fulfill their functions. Under such circumstances, there is a
need for the public and private sectors to make all-out efforts to intensively protect critical infrastructure (CI) services,
such as information and communication services, electric power supply services and financial services, whose
suspension or deterioration is highly likely to have tremendous impact. The private sector should not completely count
on the government, nor should the government leave everything to the private sector. Close public-private collaboration
is indispensable. As safe and continuous provision of CI services is required due to their nature, Critical Infrastructure
Services (CISs) outage risks due to cyberattacks on indispensable information systems must be reduced to the extent
possible, and at the same time, efforts for early detection of and swift recovery from outages are of great importance in
protecting them.
Therefore, the government established the Cybersecurity Policy for Critical Infrastructures Protection (the
"Cybersecurity Policy"), a shared policy between the government, which bears responsibility for protection, and CI
operators, which independently carry out relevant protective measures, as a basic framework for CI protection, and has
promoted this initiative.
This framework was originally formulated with the establishment of the "Special Action Plan on Cyber-terrorism
Countermeasures for Critical Infrastructure" (concluded in the December 2000 Information Security Measure
Promotion Meeting; the "Special Action Plan") and had served as the basis for the policy related to cybersecurity
measures for Japan's critical infrastructure for over 16 years, up until the establishment of the preceding Basic Policy of
Critical Information Infrastructure Protection (3rd Edition) (concluded by the Information Security Policy Council in
May 2014 and revised by the Cybersecurity Strategic Headquarters in May 2015; the "Third Policy"). Certain
achievements have been made, while reflecting the lessons learned from the experience of dealing with system outages
and data loss during the Great East Japan Earthquake and appropriate responses having been made to an ever-changing
social and technological environment and the increasingly sophisticated and complex cyberattacks in recent years, and
through necessary reviews based on assessment of measures implemented under this framework.
Considering these backgrounds, the Cybersecurity Policy of Critical Infrastructure Protection (4th Edition) ("this
Cybersecurity Policy") was established while maintaining the basic framework for CIP. Based on the basic concept of
the Basic Act on Cybersecurity (Act No. 104 of 2014), assessment of the Third
Policy described later, and the
Cybersecurity Strategy (Cabinet resolution in September 2015), this Cybersecurity Policy maintains the basic structure
consisting of the five key policies in the Third Policy which have become deeply rooted among stakeholders. In the
meantime, changes in cyberattacks targeting CI and in the background social and technological environment are
significant, and information technology (IT) has come to be increasingly incorporated in socioeconomic systems
integrally with operational technology (OT)1 such as control systems. Additionally, IoT systems, which may be targeted
1
Hereinafter, operational technology for control systems using IT is simply indicated as OT.
1