I. Introduction 2. Structure of This Cybersecurity Policy 2. Structure of This Cybersecurity Policy The structure of this Cybersecurity Policy and outlines of each Chapter are as indicated in Table 1. For responsible entities for respective initiatives based on this Cybersecurity Policy, please refer to Chapter IV. Table 1 Structure of This Cybersecurity Policy Chapter I. Introduction II. Executive Summary of This Cybersecurity Policy III. Policies for CIP IV. Activities Taken by Stakeholders V. Assessment and Verification VI. Revision of This Policy Outlines Directions for establishing this Cybersecurity Policy based on the results of the assessment of the Third Policy, and principles and ideas for implementing this Cybersecurity Policy [i] Purpose of CIP, [ii] Basic principles, [iii] Responsibility of stakeholders, and [iv] Responsibility of CI operators' executives and senior managers in promoting this Cybersecurity Policy Policies for carrying out cybersecurity measures and details of concrete measures for each of the five key policies of this Cybersecurity Policy Regarding cybersecurity measures (III. above), concrete measures that each stakeholder takes or is expected to take Policies and methods for the assessment and verification of this Cybersecurity Policy Policies for the revision of this Cybersecurity Policy based on the results of the assessment (V. above) 3. Assessment of the Third Policy The Third Policy is composed of the following five key policies. [1] Maintenance and promotion of the safety principles [2] Enhancement of information sharing system [3] Enhancement of incident response capability [4] Risk management [5] Enhancement of the basis for CIP After analytical assessment for each key policy (assessment of the results and clarification of issues), comprehensive assessment was conducted for the entirety of the Third Policy (assessment of the achievement and clarification of issues in light of the purpose (envisaged future) during the term). The comprehensive assessment is outlined as follows. < Envisaged Future > Voluntary activities based on each stakeholder's awareness of their responsibilities are disseminated as their respective code of conduct and such behavior contributes to forming cybersecurity culture. < Assessment > The Third Policy clearly indicates the basic principle, stating that cybersecurity measures should be taken by CI operators on their own responsibility, and then presents this envisaged future. 3

Select target paragraph3