Table of Contents I. Introduction ····································································································· 1 1. Purpose of CI Protection ····················································································1 2. Envisaged Future ·····························································································2 3. Consistency with the Basic Act on Cybersecurity ······················································· 4 3.1 Positioning of the Cybersecurity Policy in the Basic Act on Cybersecurity ·················· 4 3.2 Definition of cybersecurity in the Basic Act on Cybersecurity ································· 4 3.3 Responsibilities of stakeholders under the Basic Act on Cybersecurity ······················ 4 4. Policy Groups and Direction of Reinforcing and Refining the Components in this Cybersecurity Policy ·················································································································5 II. Executive Summary of This Cybersecurity Policy ······················································ 7 III. Basic Concept Relating to Environmental Changes Surrounding CI and Cybersecurity Policy 9 1. Changes in the Cybersecurity Environment Surrounding CI ·········································· 9 2. Scope of CIP ································································································ 10 3. Cybersecurity as part of organizational governance ·················································· 10 4. Realization of CIP policies optimized to individual organizations ································· 11 IV. 1. 2. 3. 4. 5. Activities During the Term of This Cybersecurity Policy ··········································· 12 Enhancement of Incident Response Capability ························································ 12 1.1 Incident response capability as part of organizational governance ·························· 12 1.2 Activities to enhance incident response capability ············································· 14 1.3 Integrated public-private efforts to enhance incident response capability ·················· 16 1.4 Review of the protection scope of CI ···························································· 17 Maintenance and Promotion of the Safety Principles ················································· 19 2.1 Continual improvement of the Guidelines for Safety Principles ····························· 20 2.2 Continual improvement of the safety principles ················································ 21 2.3 Promotion of the safety principles ································································ 22 2.4 Clarification of documentation relating to the safety principles······························ 22 Enhancement of Information Sharing System ························································· 23 3.1 Information sharing system during the term of this Cybersecurity Policy ·················· 23 3.2 Further promotion of information sharing ······················································· 25 3.3 Promotion of CI operators’ activities ···························································· 25 3.4 CEPTOAR communication training ····························································· 26 Utilization of Risk Management ········································································· 27 4.1 Promotion of risk management ··································································· 27 4.2 Understanding risks arising from environmental change ······································ 29 Enhancement of the Basis for CIP ······································································· 31 5.1 Verification of the effectiveness of incident response capability ···························· 31 5.2 Promotion of the development of human resources ············································ 33 i

Select target paragraph3