ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC 3. Information Sharing from NISC 3. Information Sharing from NISC 3.1 Cases requiring information sharing from NISC If it is found that the case falls under any of the following as a result of collecting and analyzing information on system failures provided broadly from responsible ministries for CI, cybersecurity related ministries, crisis management ministries, disaster prevention related ministries, cybersecurity related agencies, cyberspace-related operators, and CI 13 operators, the Cabinet Secretariat provides relevant information positively. (i) Cases where the obtained information is regarding a security hole, program bug, etc. and it is recognized that serious problems related to said information may occur at other CI operators (ii) Cases where there is a cyber-attack or advance notice of such an attack, where there are predicted damages from a disaster, or where it is otherwise recognized that the information poses a risk to the critical information systems of other CI operators (iii) Other cases where information sharing is considered to be effective for CI operators' cybersecurity measures The Cabinet Secretariat provides information after taking appropriate measures, such as anonymizing or otherwise processing information, so as not to cause any disadvantage to data sources. The scope to which the Cabinet Secretariat provides information is limited to CI sectors that are found to have a relevant connection with said information by the Cabinet Secretariat, within the scope permitted in advance by data sources. If the Cabinet Secretariat considers it necessary to share information beyond the scope permitted by data sources, necessary change to the scope is to be discussed and adjusted with data sources. 3.2 Framework for information sharing from NISC The procedures for information sharing from the Cabinet Secretariat to CI operators via responsible ministries for CI are as follows. (i) When the Cabinet Secretariat shares information, such sharing is carried out through liaisons to the Cabinet Secretariat for respective jurisdictional sectors of responsible ministries for CI. At that time, appropriate information identification methods are devised so that information receivers can recognize the classification and scope of handling of the information based on its severity and can utilize the information easily. (ii) Liaisons of responsible ministries for CI convey the information to the relevant CEPTOAR's point of contact (PoC). (iii) CEPTOARs convey the information to CI operators which make up respective CEPTOARs. (iv) In particularly urgent cases, such as the case of early warning information, etc., regardless of procedures (i) 13 For information to be provided, the accuracy thereof should be enhanced through cross-check of data, or otherwise, efforts should be made to improve the quality of information. Concrete measures include studies of CISs outages caused by suspension or deterioration of services in CI sectors, estimates of possible impacts of CISs outages due to common risk sources on other CI sectors, and judgment of severity based on these studies and estimates. 52

Select target paragraph3