I. Introduction 1. Direction for Establishing the Cybersecurity Policy I. Introduction 1. Direction for Establishing the Cybersecurity Policy National life and socioeconomic activities fully depend on diverse social infrastructures, and information systems are being broadly utilized to enable infrastructures to properly fulfill their functions. Under such circumstances, there is a need for the public and private sectors to make all-out efforts to intensively protect critical infrastructure (CI) services, such as information and communication services, electric power supply services and financial services, whose suspension or deterioration is highly likely to have tremendous impact. The private sector should not completely count on the government, nor should the government leave everything to the private sector. Close public-private collaboration is indispensable. As safe and continuous provision of CI services is required due to their nature, Critical Infrastructure Services (CISs) outage risks due to cyberattacks on indispensable information systems must be reduced to the extent possible, and at the same time, efforts for early detection of and swift recovery from outages are of great importance in protecting them. Therefore, the government established the Cybersecurity Policy for Critical Infrastructures Protection (the "Cybersecurity Policy"), a shared policy between the government, which bears responsibility for protection, and CI operators, which independently carry out relevant protective measures, as a basic framework for CI protection, and has promoted this initiative. This framework was originally formulated with the establishment of the "Special Action Plan on Cyber-terrorism Countermeasures for Critical Infrastructure" (concluded in the December 2000 Information Security Measure Promotion Meeting; the "Special Action Plan") and had served as the basis for the policy related to cybersecurity measures for Japan's critical infrastructure for over 16 years, up until the establishment of the preceding Basic Policy of Critical Information Infrastructure Protection (3rd Edition) (concluded by the Information Security Policy Council in May 2014 and revised by the Cybersecurity Strategic Headquarters in May 2015; the "Third Policy"). Certain achievements have been made, while reflecting the lessons learned from the experience of dealing with system outages and data loss during the Great East Japan Earthquake and appropriate responses having been made to an ever-changing social and technological environment and the increasingly sophisticated and complex cyberattacks in recent years, and through necessary reviews based on assessment of measures implemented under this framework. Considering these backgrounds, the Cybersecurity Policy of Critical Infrastructure Protection (4th Edition) ("this Cybersecurity Policy") was established while maintaining the basic framework for CIP. Based on the basic concept of the Basic Act on Cybersecurity (Act No. 104 of 2014), assessment of the Third Policy described later, and the Cybersecurity Strategy (Cabinet resolution in September 2015), this Cybersecurity Policy maintains the basic structure consisting of the five key policies in the Third Policy which have become deeply rooted among stakeholders. In the meantime, changes in cyberattacks targeting CI and in the background social and technological environment are significant, and information technology (IT) has come to be increasingly incorporated in socioeconomic systems integrally with operational technology (OT)1 such as control systems. Additionally, IoT systems, which may be targeted 1 Hereinafter, operational technology for control systems using IT is simply indicated as OT. 1

Select target paragraph3