ANNEX 5. DEFINITIONS / GLOSSARIES Cyberspace-related operators Disaster prevention related ministries Guidelines for Safety Principles Information sharing Information from NISC sharing Information sharing to NISC Information systems IT-BCP Responsible ministries for CI Safety principles Service maintenance level Signs/Hiyari-Hatto events Stakeholders System failures System vendors, which are engaged in the design, construction, operation and maintenance of information systems required for providing CI services; security vendors, which provide cybersecurity measures such as antivirus software of those information systems; and platform vendors, which provide the platforms which serve as foundations, including hardware and software of those information systems The government organizations and ministries stipulated in Article 2, item (iii) of the Basic Act on Disaster Control Measures (Act No. 223 of 1961) which engage in information collection in the event of a disaster Cybersecurity measures, which contain high-priority items and/or advanced items which should serve as a reference, collected with an overlook on all the CI sectors, in order to contribute to preparation and revision of safety principles Main section is approved by the Cybersecurity Strategic Headquarters. Measures section contains detail measures as an example. The mutual provision and sharing among relevant entities of information on system failures (information including that on CISs outages and any signs of possible system failures and HiyariHatto events) and information that will contribute to ensuring cybersecurity This includes both information sharing to NISC and information sharing from NISC. The provision of information for contributing to cybersecurity measures from the Cabinet Secretariat to CI operators The provision of information on system failures (information including that on CISs outages and any signs of possible system failures and Hiyari-Hatto events) at CI operators from the CI operators to the Cabinet Secretariat All systems based on IT such as systems for business processing, control field equipment, monitoring and control systems Business continuity plan (including relevant manuals) related to the information systems to provide CI services, and other business continuity plan Financial Services Agency (FSA); Ministry of Internal Affairs and Communications (MIC); Ministry of Health, Labour and Welfare (MHLW); Ministry of Economy, Trade and Industry (METI); Ministry of Land, Infrastructure, Transport and Tourism (MLIT) Collective term for "regulations" stipulated by the government in compliance with relevant laws, "recommendations" and "guidelines" developed by the government according to relevant laws, "standards" and "guidelines" in the whole-sector developed by sector-specific groups to respond to relevant laws and public expectations, and "internal policies" prepared by CI operators themselves to respond to relevant laws and expectations of public and customs; However, safety principles do not include the "Guidelines for Safety Principles." Based on the concept of mission assurance, the level at which CI services are judged to be provided safely and continuously Events that may cause or may have caused system failures although there are not or have not been any failures in reality The Cabinet Secretariat; responsible ministries for CI; cybersecurity related ministries; crisis management ministries; disaster prevention related ministries; CI operators; CEPTOARs; CEPTOAR council; cybersecurity related agencies; cyberspace-related operators Events that information systems of CI operators do not or cannot perform as expected at the time of their design 65

Select target paragraph3